G
Third-Party Risk Management Analyst
GavinHeath
Location not stated
Remote
1 month ago
- Risk Management
- SOC2
- ISO 27001
- CIS Controls
- PCI DSS
1 month ago
GavinHeath is partnering with a client looking to add a Third-Party Risk Management Analyst to their team. The role is a fully remote Contract position.
Responsibilities
- Conduct cybersecurity risk assessments and due diligence reviews of vendors, suppliers, service providers, and other third parties.
- Review vendor security questionnaires, SOC 2 reports, ISO 27001 documentation, policies, control evidence, and other security documentation.
- Evaluate vendor cybersecurity controls and document identified risks, control gaps, and remediation requirements.
- Support vendor onboarding, periodic reassessments, renewal reviews, and ongoing third-party risk monitoring.
- Coordinate vendor assessment intake, evidence requests, assessment tracking, remediation follow-up, and assessment closure.
- Maintain accurate vendor risk records, risk classifications, assessment documentation, and remediation status.
- Track identified findings, remediation owners, target dates, exceptions, and closure activities.
- Assist with third-party and supply-chain risk analysis, including vendor criticality, business dependency, access requirements, and operational impact.
- Maintain risk registers, assessment trackers, exception logs, and supporting documentation.
- Support risk reporting, operational metrics, assessment status reporting, and data-quality initiatives.
- Coordinate with cybersecurity, procurement, legal, compliance, IT, and other stakeholders throughout the assessment lifecycle.
- Support audit evidence collection, process documentation, and continuous improvement of third-party risk processes.
- 5+ years of experience in cybersecurity, audit, compliance, risk management, vendor management, or a related discipline.
- 3+ years of experience conducting vendor security assessments or third-party risk reviews.
- Hands-on experience with vendor security questionnaires, evidence requests, control reviews, remediation plans, and risk registers.
- Experience documenting cybersecurity findings, risks, remediation requirements, and assessment outcomes.
- Ability to effectively coordinate with vendors and internal stakeholders to drive assessments and remediation activities through completion.
- Strong written communication, documentation, analytical, and organizational skills.
- Strong attention to detail and data quality.
- Familiarity with cybersecurity and risk frameworks such as ISO 27001, SOC 2, NIST CSF, NIST SP 800-161, CIS Controls, PCI DSS, or CSA CCM preferred.
- Experience with TPRM, GRC, or security-rating platforms preferred.
- Relevant cybersecurity, audit, risk, or TPRM certifications are preferred.
- Ability to support stakeholders across multiple regions across North America.
Third-Party Risk Management Analyst · GavinHeath