387,918open jobs
10,238companies
47,936added this week
Browse all
Salary
$111k – $167k per year
Location
Remote (United States)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Third-Party Risk Management Analyst based in United States.

This role is responsible for strengthening security and risk management across a broad vendor and partner ecosystem.

You will lead end-to-end third-party security assessments, from initial tiering and onboarding through reassessments and remediation.

The position combines information security, governance, risk management, compliance, and cross-functional collaboration.

You will work closely with Legal, Procurement, Security leadership, and business stakeholders to ensure vendor relationships meet established security standards.

Your work will provide leadership with clear visibility into third-party risk through meaningful metrics, dashboards, and reporting.

You will also help modernize vendor risk processes through automation and AI-enabled workflows.

This is an opportunity to make a measurable impact within a fast-growing, high-performance environment while helping scale a mature TPRM program.

Accountabilities:

    • Lead end-to-end third-party security risk assessments using qualitative and quantitative methodologies, including vendor risk ratings and tiering in accordance with established Vendor Risk Management policies.
    • Own the vendor reassessment cadence and monitor remediation of security gaps throughout the full vendor lifecycle.
    • Partner with Legal, Procurement, and system or relationship owners to review vendor onboarding requests and contracts, ensuring appropriate security and privacy requirements are established before vendors go live.
    • Evaluate and support requirements related to incident notification, data security and training, compliance obligations, security addenda, and other relevant contractual protections.
    • Escalate unresolved or significant vendor risks to Security leadership, Legal, Procurement, and appropriate business owners.
    • Support internal and external audits of the third-party risk management program, including assessments aligned with ISO, SOC, FedRAMP, and similar standards.
    • Build and maintain metrics, dashboards, and reporting that provide leadership with visibility into the organization’s third-party risk posture and program performance.
    • Support the implementation of automation and AI-enabled capabilities within vendor risk workflows, including security questionnaire triage, identification of high-risk contract terms, and integration of relevant industry intelligence.
    • Mentor junior third-party risk team members and help ensure the program evolves effectively alongside organizational growth and innovation.
    • Promote a strong culture of security, collaboration, continuous improvement, customer focus, long-term thinking, inclusion, and team success.
    • Requirements

      • 5+ years of experience in third-party or vendor risk management, Governance, Risk, and Compliance (GRC), or information security compliance.
      • Hands-on experience conducting vendor security assessments and administering vendor risk tiering programs.
      • Experience using automation, scripting, or low-code workflows to improve and scale vendor risk processes.
      • Demonstrated experience partnering with Legal and Procurement on vendor security and privacy requirements, including security addenda and Data Processing Agreements (DPAs).
      • Familiarity with risk assessment frameworks such as NIST CSF, ISO 27001, or SOC 2.
      • Experience using GRC or vendor risk management platforms such as Vanta, ServiceNow, OneTrust, Archer, or similar technologies.
      • Strong analytical and problem-solving skills, with the ability to evaluate complex risks and translate findings into clear recommendations.
      • Excellent communication and collaboration skills, with the ability to work effectively across Security, Legal, Procurement, and business teams.
      • Strong organizational skills and the ability to manage multiple assessments, remediation activities, stakeholders, and deadlines in a fast-paced environment.
      • Ability to work independently while exercising sound judgment around risk escalation and prioritization.
      • A relevant professional certification such as CTPRP, CISA, CRISC, or CISSP is preferred.
      • Must reside in the United States, excluding the San Francisco Bay Area, New York City, and Washington, D.C. metropolitan areas.
      • Benefits

        • Annual base salary of $110,670-$167,400 USD, with actual compensation varying based on factors such as location, knowledge, skills, and experience.
        • Eligibility for an initial RSU grant with no vesting cliff, subject to applicable plan terms and conditions.
        • Ongoing equity refresh opportunities tied to performance, subject to plan terms and conditions.
        • Potential performance-based bonus and variable compensation as part of a broader total rewards program.
        • Flexible, employee-led remote work model.
        • Comprehensive health and parental leave plans.
        • Professional development stipend to support continued learning and career growth.
        • Opportunity to work in a high-growth environment with significant ownership and career development opportunities.
        • Inclusive and collaborative culture focused on long-term impact, innovation, and team success.
        • Fully remote U.S. position, with geographic restrictions excluding the San Francisco Bay Area, New York City, and Washington, D.C. metro areas.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
387,918 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$41k – $87k per year (Estimated) • In office • Contractor • 6+ years exp • Noida
JavaScript
Python
TypeScript
Java
Kotlin
Java
Hibernate
Spring Boot
Spring Cloud
Spring Security
Testcontainers
Kotlin
Mockito
Databases
Apache Kafka
InfluxDB
Kafka
PostgreSQL
RabbitMQ
Redis
TimescaleDB
AI/ML
Computer Vision
Feature Store
LLM
Time Series Forecasting
Frontend
Next.js
React.js
Mobile
JUnit
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
GitHub Actions
GitLab
GitLab CI
GitOps
Grafana
gRPC
Jaeger
Jenkins
Kubernetes
Loki
OpenTelemetry
Prometheus
Pulumi
Terraform
Cybersecurity
ISO 27001
SOC 2
SonarQube
IoT
MQTT
OPC UA
QA
Gatling
JMeter
k6
Swagger
Apply
$27k – $72k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
DevOps
Amazon EKS
AWS
Azure
Azure AKS
CI/CD
Crossplane
GCP
GitOps
Google GKE
IAM
Kubernetes
Platform Engineering
Service Mesh
Terraform
Cybersecurity
FedRAMP
Management
ServiceNow
Apply
$77k – $101k per year • Remote • Full-Time • 2+ years exp • Bachelor's Degree
Bash
Python
DevOps
AWS
Azure
GCP
IAM
Cybersecurity
NIST CSF
Nmap
Threat Modeling
Apply
$112k – $212k per year (Estimated) • In office • Full-Time • Leipzig
DevOps
AWS
Azure
VMWare
Cybersecurity
ISO 27001
Marketing
LinkedIn
Apply
Site Support Engineer 3 hours ago
$24k – $66k per year (Estimated) • In office • Full-Time • Piła
Cybersecurity
Microsoft Entra ID
Management
Jira
OneDrive
Outlook
ServiceNow
SharePoint
Apply
$77k – $101k per year • Remote • Full-Time • 2+ years exp • Bachelor's Degree
Bash
Python
DevOps
AWS
Azure
GCP
IAM
Cybersecurity
NIST CSF
Nmap
Threat Modeling
Apply
$111k – $189k per year (Estimated) • Remote • Full-Time • 6+ years exp • Bachelor's Degree
Apply
$125k – $225k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
DevOps
Debian
Ubuntu
Apply
$25k – $60k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
DevOps
Debian
Ubuntu
Apply
$88k – $184k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
DevOps
Debian
Ubuntu
Apply
See all jobs
This is one of many
387,918 more open roles from verified company boards, updated every day.