Remote Jobs RockRemote Jobs Rock

Risk Analyst - Vendor Risk Assessment (VRA)

๐Ÿ“… Jul 31
Vendor Risk AssessmentInformation SecurityTechnical Documentation ReviewCompliance Frameworks

๐Ÿ“œ Description

  • Conduct vendor assessments by reviewing questionnaire responses, evaluating SOC 2 reports, and examining supporting technical documentation.
  • Review and interpret vendor-provided technical documentation including system architecture diagrams and incident response capabilities.
  • Map vendor technical controls to various compliance frameworks and identify gaps in technical implementation.
  • Support Vendor Risk Assessment workstreams and track remediation activities to completion.
  • Communicate findings clearly to both technical teams and non-technical stakeholders.

๐Ÿ› ๏ธ Requirements

  • Working knowledge of ISO 27001, SOC 2 (SSAE 18), NIST CSF/SP 800-53, SOX ITGC, GDPR, and CCPA.
  • Bachelor's degree in Computer Science, Information Technology, Information Security, Cybersecurity, or a related technical field, or equivalent demonstrated experience.
  • Preferred certifications include CISA, CISM, CISSP, CompTIA Security+, ISO 27001 Lead Auditor/Implementer, CCSK, AWS/Azure Security Specialty, or equivalent.

โœจ Benefits

  • Competitive leave benefits
  • Gender-neutral parental leave
  • Global home office allowance
  • Internet or mobile phone allowance
  • Hybrid work model with flexible hours
Full job description

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

Weโ€™re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

As a Risk Analyst, Vendor Risk Assessment (VRA), you will be tasked with bringing technically grounded expertise to SentinelOne's Information Security GRC team. You will go beyond compliance knowledge to understand how systems work, how threats materialize, and how to evaluate vendor security controls with a critical technical eye. You will operate with moderate guidance on assigned workstreams and apply hands-on IT and cybersecurity knowledge to assess risk accurately and credibly across a diverse vendor portfolio.

What Will You Do?

Primary responsibilities include:

  • Conduct vendor assessments by reviewing questionnaire responses, evaluating SOC 2 reports, and examining supporting technical documentation including penetration test findings, vulnerability disclosures, encryption practices, and access control configurations; identify technical control gaps and contribute to risk-prioritized remediation plans.
  • Review and interpret vendor-provided technical documentation including system architecture diagrams, data flow maps, hardening standards, patch management practices, and incident response capabilities with moderate oversight; apply growing knowledge of common IT environments (cloud, SaaS, on-prem, hybrid) to contextualize vendor risk.
  • Map vendor technical controls to ISO 27001, SSAE 18/SOC 2, SOX ITGC, GDPR, NIST CSF/SP 800-53, and SentinelOne's internal security policies; deduce general gaps where technical implementation falls short of framework requirements and support closure efforts with vendors.
  • Support Vendor Risk Assessment workstreams and project objectives; track remediation activities to completion, validate technical evidence of fixes, and escalate unresolved risk to senior analysts or management with clear business impact framing, with moderate oversight.
  • Communicate with IT, Engineering, Legal, and Procurement teams to gather technical context and align on risk tolerance; communicate findings clearly to both technical teams using precise IT and security language and to non-technical stakeholders by translating risk into business impact.
  • Stay current on the evolving threat landscape including cloud misconfigurations, supply chain attacks, and third-party data exposure risks, and apply this awareness to refine assessment criteria.
  • Write and maintain scripts (Python, PowerShell, or Bash) to automate tasks, query APIs, process data (JSON/CSV), and manage code using Git; apply AI tools enthusiastically to automate workflows and be prepared to share concrete examples of how you have used scripting and AI to automate tasks.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

  • 3 to 5 years of experience in information security, IT risk, vendor/third-party risk management, or GRC, with hands-on experience assessing vendors across a range of technical environments and approximately 75 to 100 vendor assessments completed; prior experience in an IT, systems, or security engineering role is a strong plus.
  • Solid and developing understanding of core IT and security domains including network security (firewalls, segmentation, VPNs, DNS), cloud platforms and shared responsibility models (AWS, Azure, GCP), Identity and Access Management (SSO, MFA, privileged access), endpoint security and patch and vulnerability management, data protection and encryption (at rest and in transit) and DLP, logging and monitoring and SIEM concepts, and secure SDLC and application security fundamentals.
  • Working knowledge of ISO 27001, SOC 2 (SSAE 18), NIST CSF/SP 800-53, SOX ITGC, GDPR, and CCPA.
  • Bachelor's degree in Computer Science, Information Technology, Information Security, Cybersecurity, or a related technical field, or equivalent demonstrated experience.
  • Preferred certifications include CISA, CISM, CISSP, CompTIA Security+, ISO 27001 Lead Auditor/Implementer, CCSK, AWS/Azure Security Specialty, or equivalent.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

  • Competitive leave benefits
  • Gender-neutral parental leave

Insurance & Financial Security

  • Private medical, dental, and vision insurance

Work Perks & Flexibility

  • Global home office allowance
  • Internet or mobile phone allowance
  • Hybrid work model with flexible hours

Wellness & Lifestyle

  • Wellness programs

Growth & Community

  • In-office lunch program

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Thinkahead

Risk Analyst

๐Ÿ“… Aug 21
Thinkahead๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Information Technology And Services

The Risk Analyst is responsible for developing and maintaining the IT risk management and compliance program, ensuring alignment with business objectives and regulatory requirements.

IT Risk ManagementCompliance FrameworksRisk AssessmentVendor Risk Assessment
Thehartford

Associate Risk Analyst, Economic Capital

๐Ÿ•’ 5 days ago
Thehartford๐Ÿ‘ฅ 10,000+ employees๐Ÿข Financial Services

The Associate Risk Analyst will support ERM's Economic Capital initiatives, focusing on modeling, analysis, and collaboration to assess capital adequacy and risk profile.

Risk ManagementFinanceActuarialFinancial Modeling
Xtb

Operational Risk Analyst

๐Ÿ“… Aug 28
Xtb๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Financial Services

The Enterprise Risk Analyst will enhance risk management frameworks, support risk assessments, and improve reporting processes across the organization.

Enterprise Risk ManagementOperational RiskRisk AssessmentRisk Appetite Framework
Lyft

Fraud & Risk Analyst

๐Ÿ“… Aug 12
Lyft๐Ÿ‘ฅ 10,000+ employees๐Ÿข Transportation

Join a dynamic team as a Fraud & Risk Analyst, where you'll investigate and develop strategies to prevent third-party fraud while ensuring a seamless user experience.

Fraud DetectionData AnalysisSQLPython
Toast

Risk Analyst - Strategy & Capabilities

๐Ÿ“… Jul 23
Toast๐Ÿ‘ฅ 5001 - 10,000 employees๐Ÿข Computer Software

As a Risk Analyst - Strategy & Capabilities, you will enhance operational processes and implement risk strategies to optimize financial products at Toast.

Risk AnalysisOperational Risk ManagementSQLPython

Trusted by Remote Workers