Search

GRC - Vendor Risk Assessment Consultant

PublishedPublished: 9/25/2026
Finance

Requisition ID: 110113-1

Title: GRC - Vendor Risk Assessment Consultant

Location: Remote, EST

Duration: 6+ Months

Salary Range: $40/hr - $45 an hour W2

Position Summary

Skills: Cyber Security - GRC - Vendor Risk Assessment, Cyber Security - GRC - Data Security

Experience Required: 8-10 Years

MUST HAVE SKILLS: GRC – Vendor risk assessment/ Third party risk assessment

Role Descriptions:

  • Lead and execute end-to-end third-party vendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies.
  • Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.
  • Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.
  • Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.
  • Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.
  • Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.
  • Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.
  • Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.

    Essential Skills: Lead and execute end-to-end third-partyvendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies.
  • Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.
  • Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.
  • Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.
  • Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.
  • Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.
  • Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.
  • Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.

    Company Benefits & Culture

    •
    Inclusive and diverse work environment

    • Opportunities for professional growth and development

    • Comprehensive health and wellness benefits

Required skills

  • Data Security Experience
  • Cyber Security
  • Security Policies and Procedures
  • GRC (Governance Risk Compliance)
  • ServiceNow
  • Continuous Improvement
  • Best Practices
  • SaaS
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...