Remote Jobs RockRemote Jobs Rock

Third-Party Risk Analyst

🕒 24 days ago
Third-party RiskSecurity AssessmentSOC 2ISO 27001

📜 Description

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck.
  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion.
  • Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells.
  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.
  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

🛠️ Requirements

  • 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration.
  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.
  • Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up.
  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.
  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.
  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Trusted by Remote Workers