This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Third-Party Risk Management Analyst based in United States.
This role is responsible for strengthening security and risk management across a broad vendor and partner ecosystem.
You will lead end-to-end third-party security assessments, from initial tiering and onboarding through reassessments and remediation.
The position combines information security, governance, risk management, compliance, and cross-functional collaboration.
You will work closely with Legal, Procurement, Security leadership, and business stakeholders to ensure vendor relationships meet established security standards.
Your work will provide leadership with clear visibility into third-party risk through meaningful metrics, dashboards, and reporting.
You will also help modernize vendor risk processes through automation and AI-enabled workflows.
This is an opportunity to make a measurable impact within a fast-growing, high-performance environment while helping scale a mature TPRM program.
Accountabilities:
- Lead end-to-end third-party security risk assessments using qualitative and quantitative methodologies, including vendor risk ratings and tiering in accordance with established Vendor Risk Management policies.
- Own the vendor reassessment cadence and monitor remediation of security gaps throughout the full vendor lifecycle.
- Partner with Legal, Procurement, and system or relationship owners to review vendor onboarding requests and contracts, ensuring appropriate security and privacy requirements are established before vendors go live.
- Evaluate and support requirements related to incident notification, data security and training, compliance obligations, security addenda, and other relevant contractual protections.
- Escalate unresolved or significant vendor risks to Security leadership, Legal, Procurement, and appropriate business owners.
- Support internal and external audits of the third-party risk management program, including assessments aligned with ISO, SOC, FedRAMP, and similar standards.
- Build and maintain metrics, dashboards, and reporting that provide leadership with visibility into the organization’s third-party risk posture and program performance.
- Support the implementation of automation and AI-enabled capabilities within vendor risk workflows, including security questionnaire triage, identification of high-risk contract terms, and integration of relevant industry intelligence.
- Mentor junior third-party risk team members and help ensure the program evolves effectively alongside organizational growth and innovation.
- Promote a strong culture of security, collaboration, continuous improvement, customer focus, long-term thinking, inclusion, and team success.
- 5+ years of experience in third-party or vendor risk management, Governance, Risk, and Compliance (GRC), or information security compliance.
- Hands-on experience conducting vendor security assessments and administering vendor risk tiering programs.
- Experience using automation, scripting, or low-code workflows to improve and scale vendor risk processes.
- Demonstrated experience partnering with Legal and Procurement on vendor security and privacy requirements, including security addenda and Data Processing Agreements (DPAs).
- Familiarity with risk assessment frameworks such as NIST CSF, ISO 27001, or SOC 2.
- Experience using GRC or vendor risk management platforms such as Vanta, ServiceNow, OneTrust, Archer, or similar technologies.
- Strong analytical and problem-solving skills, with the ability to evaluate complex risks and translate findings into clear recommendations.
- Excellent communication and collaboration skills, with the ability to work effectively across Security, Legal, Procurement, and business teams.
- Strong organizational skills and the ability to manage multiple assessments, remediation activities, stakeholders, and deadlines in a fast-paced environment.
- Ability to work independently while exercising sound judgment around risk escalation and prioritization.
- A relevant professional certification such as CTPRP, CISA, CRISC, or CISSP is preferred.
- Must reside in the United States, excluding the San Francisco Bay Area, New York City, and Washington, D.C. metropolitan areas.
- Annual base salary of $110,670-$167,400 USD, with actual compensation varying based on factors such as location, knowledge, skills, and experience.
- Eligibility for an initial RSU grant with no vesting cliff, subject to applicable plan terms and conditions.
- Ongoing equity refresh opportunities tied to performance, subject to plan terms and conditions.
- Potential performance-based bonus and variable compensation as part of a broader total rewards program.
- Flexible, employee-led remote work model.
- Comprehensive health and parental leave plans.
- Professional development stipend to support continued learning and career growth.
- Opportunity to work in a high-growth environment with significant ownership and career development opportunities.
- Inclusive and collaborative culture focused on long-term impact, innovation, and team success.
- Fully remote U.S. position, with geographic restrictions excluding the San Francisco Bay Area, New York City, and Washington, D.C. metro areas.

