Risk Analyst - Vendor Risk Assessment (VRA)
Core
Conduct technical vendor risk assessments by reviewing security controls, technical documentation, and compliance reports to identify gaps and support remediation for a global cybersecurity company.
Role type
Senior IC Risk Analyst (Vendor Risk Assessment)
Builds
Risk-prioritized remediation plans and validated technical evidence of fixes for third-party vendors.
Domain
Cybersecurity, GRC, Third-Party Risk Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vendor risk assessment, technical control evaluation, SOC 2/ISO 27001/NIST compliance mapping, risk remediation tracking, technical documentation review, scripting (Python/PowerShell/Bash), API automation, data processing (JSON/CSV), Git
Preferred skills
CISA, CISM, CISSP, CompTIA Security+, ISO 27001 Lead Auditor/Implementer, CCSK, AWS/Azure Security Specialty
Technologies
Python, PowerShell, Bash, Git, JSON, CSV, AWS, Azure, GCP
Responsibilities
Conduct vendor assessments by reviewing questionnaire responses, SOC 2 reports, and technical documentation including penetration test findings and encryption practices; Review and interpret vendor-provided technical documentation including system architecture diagrams, data flow maps, and incident response capabilities; Map vendor technical controls to ISO 27001, SOC 2, SOX ITGC, GDPR, and NIST CSF/SP 800-53 to identify gaps; Support Vendor Risk Assessment workstreams by tracking remediation activities and validating technical evidence of fixes; Write and maintain scripts to automate tasks, query APIs, and process data; Stay current on evolving threat landscapes including cloud misconfigurations and supply chain attacks.
Seniority
Mid-Senior, hands-on IC