CareerPlanGet AI match score →

Security Risk and Compliance Lead

Warsaw💼 Full-time💰 $273,000–$327,000🗓 2026-07-07 → 2026-07-31

Core

Building and running Asana's Third Party Risk Management (TPRM) program to assess, track, and manage vendor security risks.

Role type

Third Party Risk Management Lead

Builds

A risk-based framework for assessing and managing third-party vendors and service providers

Domain

B2B SaaS security and compliance

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Third-party risk management, vendor risk assessment, TPRM frameworks (SIG, CAIQ, NIST SP 800-161, ISO 27001, SOC 2), security due diligence, risk tiering, remediation tracking, contract security review, global coordination

Preferred skills

Experience with cloud environments, data privacy, emerging technologies (AI tools)

Technologies

SIG, CAIQ, NIST SP 800-161, ISO 27001, SOC 2

Responsibilities

Design and scale TPRM program frameworks, conduct vendor security assessments, drive remediation and risk acceptance, manage ongoing third-party monitoring, review security provisions in vendor contracts, report on TPRM program health

Seniority

Mid-Senior, hands-on IC

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Greenhouse ↗