Third-Party Risk Management Analyst
Core
Own security risk assessments for critical Samsara vendors and partners, overseeing the complete lifecycle from tiering and onboarding to ongoing reassessments and remediation.
Role type
Third-Party Risk Management Analyst
Builds
Vendor risk management program and security posture for the vendor ecosystem
Domain
Information Security / GRC / Vendor Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Third-party/vendor risk management, GRC, information security compliance, automation/scripting/low-code workflows, vendor security assessments, vendor tiering program management, contract security and privacy terms review
Preferred skills
Risk assessment frameworks (NIST CSF, ISO 27001, SOC 2), GRC or vendor risk management platforms (Vanta, ServiceNow, OneTrust, Archer), CTPRP/CISA/CRISC/CISSP certification
Technologies
Vanta, ServiceNow, OneTrust, Archer, Zip
Responsibilities
Lead end-to-end third-party security risk assessments using qualitative and quantitative methods; Own the vendor reassessment cadence and track remediation of security gaps; Partner with Legal, Procurement, and system owners to review vendor contracts and onboarding requests; Escalate unresolved vendor risk to leadership; Support internal and external audits (ISO, SOC, FedRAMP); Build and maintain metrics, dashboards, and reporting for vendor risk posture; Support automation and AI-enabled tools in vendor risk workflows; Mentor junior TPRM resources
Seniority
Mid-Senior, hands-on IC