Senior TPRM Analyst

1 day, 3 hours ago
Full-time
Senior
Cybersecurity
EVOCS

EVOCS

EVOCS is a global leader in digital transformation, offering end-to-end services including advisory, deployment, implementation support, and post-production optimization. Specializing in Workday and Cloud Services, we provide tailored solutions to driv...

Internet Software & Services
1-10
Founded 2019

Description

  • Own end-to-end risk assessments for critical cloud providers, MSPs, and technology vendors.
  • Analyze SOC 2 Type II reports, ISO 27001 certifications, control evidence, penetration tests, remediation plans, and questionnaires.
  • Set inherent and residual risk ratings, define compensating controls, and track remediation through closure.
  • Assess fourth-party dependencies, vendor concentration, subcontractors, geopolitical exposure, and data residency risks.
  • Use security ratings and continuous monitoring signals to support ongoing vendor risk evaluations.
  • Lead escalations, vendor challenges, and risk acceptance discussions with senior stakeholders.
  • Prepare executive-ready risk summaries, escalation memoranda, and recommendations.
  • Present vendor risk trends, exceptions, and overall posture to governance forums and senior leadership.
  • Improve TPRM standards, tiering criteria, evidence requirements, and playbooks.
  • Mentor junior analysts on evidence review, reporting quality, and stakeholder management.

Requirements

  • 7+ years of experience in cybersecurity, risk, audit, or compliance, including at least 5 years in third-party or vendor risk management.
  • Experience assessing cloud providers, MSPs, and critical technology vendors.
  • Ability to interpret SOC 2 reports and ISO 27001 certifications, including scope carve-outs, qualified opinions, and control exceptions.
  • Experience analyzing fourth-party and supply chain risks, vendor concentration, criticality tiers, geopolitical exposure, and subcontractor dependencies.
  • Proven ability to write executive-ready risk summaries for senior audiences.
  • Experience leading escalations and risk acceptance discussions with senior stakeholders.
  • Working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and CIS frameworks.
  • Strong written, verbal, interpersonal, and stakeholder management skills.
  • TPRP, CTPRA, CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor certification preferred.
  • Experience with ProcessUnity, ServiceNow GRC, Archer, SecurityScorecard, BitSight, RiskRecon, or Black Kite preferred.
  • Exposure to regulated environments and TPRM program design preferred.

Benefits

  • Remote work opportunity.
  • US pay range of $90–$105.
  • Opportunity to work with technology clients on complex third-party risk challenges.
  • Values-driven environment emphasizing customer focus, innovation, integrity, transparency, and data-driven decision-making.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Scientist

Figma 1K-5K Internet Software & Services

Figma is hiring a Security Scientist to use security expertise and data analysis to reduce risks, improve detection and response, and strengthen the safety of its products, platform, and IT systems.

Apache Spark Presto Python R Snowflake SQL
2 hours, 38 minutes ago

Senior Security Assurance Engineer

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Security Compliance professional to operate its technology compliance program across corporate, security, engineering, and third-party systems, unifying controls and evidence for regulatory, contractual, and security assurance needs.

DevSecOps GitLab
2 days, 2 hours ago

Cyber Security Analyst II

RecargaPay 251-1K Capital Markets

RecargaPay is seeking a Cyber Security Analyst II for its Blue Team to defend cloud and internal environments through monitoring, hardening, vulnerability management, and resilient security controls.

AWS CI/CD Cybersecurity Encryption SIEM
2 days, 4 hours ago

Investigator

Stripe 5K-10K Diversified Financial Services

Stripe is hiring an Abuse Operations professional to investigate and lead response to product abuse and fraud incidents, helping protect merchants and strengthen fraud prevention across its financial infrastructure platform.

Apache Spark Databricks Network Security Pandas Python Scikit-learn SQL Trino
3 days, 2 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers