CareerPlanSign in

Risk Analyst - Vendor Risk Assessment (VRA)

Costa Rica💼 Full-time🗓 2026-07-31 → 2026-09-26

Core

Conduct technical vendor risk assessments by reviewing security controls, technical documentation, and compliance reports to identify gaps and support remediation for a global cybersecurity company.

Role type

Senior IC Risk Analyst (Vendor Risk Assessment)

Builds

Risk-prioritized remediation plans and validated technical evidence of fixes for third-party vendors.

Domain

Cybersecurity, GRC, Third-Party Risk Management

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Vendor risk assessment, technical control evaluation, SOC 2/ISO 27001/NIST compliance mapping, risk remediation tracking, technical documentation review, scripting (Python/PowerShell/Bash), API automation, data processing (JSON/CSV), Git

Preferred skills

CISA, CISM, CISSP, CompTIA Security+, ISO 27001 Lead Auditor/Implementer, CCSK, AWS/Azure Security Specialty

Technologies

Python, PowerShell, Bash, Git, JSON, CSV, AWS, Azure, GCP

Responsibilities

Conduct vendor assessments by reviewing questionnaire responses, SOC 2 reports, and technical documentation including penetration test findings and encryption practices; Review and interpret vendor-provided technical documentation including system architecture diagrams, data flow maps, and incident response capabilities; Map vendor technical controls to ISO 27001, SOC 2, SOX ITGC, GDPR, and NIST CSF/SP 800-53 to identify gaps; Support Vendor Risk Assessment workstreams by tracking remediation activities and validating technical evidence of fixes; Write and maintain scripts to automate tasks, query APIs, and process data; Stay current on evolving threat landscapes including cloud misconfigurations and supply chain attacks.

Seniority

Mid-Senior, hands-on IC

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.