Senior Security Third Party Risk (TPRM) Analyst
Core
Senior Information Security GRC Analyst supporting IT and InfoSec by performing governance, risk, and compliance activities, specifically within the Third Party Risk Management (TPRM) process.
Role type
Senior IC Information Security GRC Analyst (TPRM)
Builds
Matured compliance processes and vendor risk assessments for customers and vendors
Domain
Information Security, Governance, Risk, and Compliance (GRC), Third Party Risk Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Reviewing SOC 1/2 reports and ISO 27001 certifications, evaluating supplier control environments against risk frameworks, executing risk assessments of third-party vendors, documenting risk findings, generating KPIs and metrics, mentoring junior analysts, understanding GDPR/CCPA/PCI-DSS/SOC 2/ISO/FedRAMP regulations, cloud experience
Preferred skills
CRISC, Security+, CISSP, CISM, CCSP, CISA certifications, knowledge of OneTrust security/GRC products
Technologies
SOC 1, SOC 2, ISO 27001, GDPR, CCPA, PCI-DSS, FedRAMP, cloud providers
Responsibilities
Collaborate with IT, InfoSec, and GRC team to mature compliance process; Review vendor due diligence documentation including SOC reports, ISO certifications, penetration testing reports, policies, and security questionnaires; Evaluate supplier control environments against established risk management standards and frameworks; Document risk findings and communicate recommendations to business stakeholders; Execute risk assessments of third-party vendors; Mentor Junior Security Analysts; Responsible for generation and continued delivery of relevant KPIs and metrics; Provide feedback on solutions and processes to mature overall capabilities
Seniority
Senior, hands-on IC