Requisition ID: 110113-1
Title: GRC - Vendor Risk Assessment Consultant
Location: Remote, EST
Duration: 6+ Months
Salary Range: $40/hr - $45 an hour W2
Position Summary
Skills: Cyber Security - GRC - Vendor Risk Assessment, Cyber Security - GRC - Data Security
Experience Required: 8-10 Years
MUST HAVE SKILLS: GRC – Vendor risk assessment/ Third party risk assessment
Role Descriptions:
- Lead and execute end-to-end third-party vendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies.
- Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.
- Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.
- Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.
- Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.
- Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.
- Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.
- Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.
Essential Skills: Lead and execute end-to-end third-partyvendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies. - Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.
- Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.
- Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.
- Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.
- Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.
- Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.
- Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.
Company Benefits & Culture
• Inclusive and diverse work environment
• Opportunities for professional growth and development
• Comprehensive health and wellness benefits
Required skills
- Data Security Experience
- Cyber Security
- Security Policies and Procedures
- GRC (Governance Risk Compliance)
- ServiceNow
- Continuous Improvement
- Best Practices
- SaaS