Remote job
Third-Party Risk Management Analyst
Job details
About this role
Role overview A Governance, Risk, and Compliance team within an industrial technology platform is hiring a Third-Party Risk Management Analyst to safeguard the vendor and partner ecosystem. The role owns the full lifecycle of vendor security assessments, from initial tiering through ongoing reassessment and remediation, partnering with Legal, Procurement, and business stakeholders to keep third-party relationships compliant with internal security standards. This is a remote position open to candidates across the United States, with the exception of the San Francisco Bay Area, New York City metro, and Washington DC metro regions.
Responsibilities - Lead end-to-end third-party security risk assessments using qualitative and quantitative methods, and recommend risk ratings and tiering aligned with the Vendor Risk Management Policy - Own the vendor reassessment cadence and track remediation of identified security gaps throughout the entire vendor lifecycle - Partner with Legal, Procurement, and system owners to review vendor contracts and onboarding requests, ensuring security requirements such as incident notification, data handling, and compliance controls are in place before go-live - Escalate unresolved vendor risk to Security leadership, Legal, Procurement, and business owners as needed - Support internal and external audits of the vendor risk program, including frameworks such as ISO, SOC, and FedRAMP - Build and maintain metrics, dashboards, and reporting that give Security leadership visibility into third-party risk posture and program performance - Help bring automation and AI-enabled tools into vendor risk workflows, including AI-assisted triage of security questionnaires and high-risk contract term detection - Mentor junior TPRM team members to keep pace with organizational growth
Requirements - Demonstrated experience running security risk assessments for vendors and partners in a GRC or security function - Familiarity with vendor risk frameworks, contract security requirements, and compliance standards such as ISO, SOC, or FedRAMP - Strong collaboration skills with cross-functional partners including Legal, Procurement, and business system owners - Experience building dashboards, metrics, and reporting for security leadership - Ability to manage multiple vendor assessments concurrently while tracking remediation and reassessment cycles - Comfort working in a fast-paced organization where priorities evolve quickly
Nice to have - Hands-on experience introducing AI or automation tools into risk workflows, such as AI-assisted questionnaire triage - Prior mentoring or team leadership experience within a security or GRC function - Background supporting audits and evidence collection for regulated environments
Benefits and work setup - Fully remote within the eligible US regions - Reports into the Governance, Risk, and Compliance organization - Opportunity to work on cross-functional initiatives spanning security, legal, procurement, and product