G
Senior Third-Party Risk Management Analyst
GavinHeath
Location not stated
Remote
Senior
1 month ago
- Risk Management
- SOC2
- ISO 27001
- Penetration Testing
- CIS Controls
- PCI DSS
- CISSP
- CISM
- CISA
- CRISC
1 month ago
GavinHeath is partnering with a client looking to add a Senior Third-Party Risk Management Analyst to their team. The role is a fully remote Contract position.
Responsibilities
- Conduct cybersecurity due diligence and risk assessments for vendors, suppliers, service providers, and other third parties.
- Review vendor security questionnaires, SOC 2 reports, ISO 27001 certifications, penetration testing summaries, security policies, control evidence, and risk attestations.
- Evaluate third-party cybersecurity controls against organizational requirements and established security frameworks.
- Identify security and control gaps, assess risk, recommend remediation requirements, and evaluate compensating controls.
- Perform risk analysis involving critical vendors, third-party and fourth-party relationships, business dependencies, technology dependencies, and supply-chain cybersecurity exposure.
- Lead or support complex vendor risk reviews, escalations, risk acceptance decisions, and remediation activities.
- Monitor identified risks and remediation efforts through resolution and validate appropriate closure.
- Develop vendor risk summaries, risk metrics, Key Risk Indicators (KRIs), and executive-level reporting.
- Maintain risk registers, assessment records, exception documentation, remediation plans, and supporting evidence.
- Collaborate with cybersecurity, procurement, legal, privacy, compliance, IT, and business stakeholders on vendor risk decisions.
- Support audit readiness, evidence collection, control validation, and third-party risk governance activities.
- Develop and maintain procedures, assessment criteria, workflow documentation, and knowledge-transfer materials.
- 7+ years of experience in cybersecurity, risk management, audit, compliance, third-party risk, or supply-chain risk.
- 5+ years of dedicated Third-Party Risk Management (TPRM) or vendor risk management experience.
- Demonstrated experience assessing technology vendors, suppliers, cloud providers, managed service providers, and other critical third parties.
- Experience reviewing SOC 2 reports, ISO 27001 documentation, vendor security questionnaires, control evidence, vulnerability information, and remediation plans.
- Experience identifying cybersecurity control gaps and managing risk findings and remediation activities.
- Strong understanding of cybersecurity risk and its relationship to privacy, procurement, contractual, compliance, and operational risk.
- Ability to develop concise, executive-ready risk assessments, recommendations, and escalation materials.
- Experience with established cybersecurity and risk frameworks such as ISO 27001, SOC 2, NIST CSF, NIST SP 800-161, CIS Controls, PCI DSS, or CSA CCM preferred.
- Experience with TPRM, GRC, or security-rating platforms preferred.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, CTPRP, CTPRA, ISO 27001 Lead Auditor, or Security+ are preferred.
- Ability to support stakeholders across multiple regions across North America.
Senior Third-Party Risk Management Analyst · GavinHeath