TPRM Analyst

1 day, 3 hours ago
Senior
Cybersecurity
EVOCS

EVOCS

EVOCS is a global leader in digital transformation, offering end-to-end services including advisory, deployment, implementation support, and post-production optimization. Specializing in Workday and Cloud Services, we provide tailored solutions to driv...

Internet Software & Services
1-10
Founded 2019

Description

  • Conduct high-volume vendor security assessments and third-party reviews on schedule.
  • Issue questionnaires, manage evidence requests, and validate submitted materials.
  • Review policies, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and related control evidence.
  • Identify gaps, assign risk ratings, and document findings clearly.
  • Escalate complex, contested, or high-criticality reviews to senior analysts.
  • Build and track remediation plans with vendors and internal stakeholders.
  • Follow up with vendors, business owners, procurement, and legal through remediation closure.
  • Maintain reassessment schedules and identify material changes between review cycles.
  • Ensure risk register and TPRM platform records are complete, accurate, and audit-ready.
  • Produce reporting on assessment volume, aging, findings, and remediation status.

Requirements

  • 5+ years of experience in cybersecurity, audit, compliance, risk, or vendor management.
  • At least 3 years conducting vendor security assessments or third-party reviews.
  • Hands-on experience with security questionnaires, evidence requests, control reviews, remediation plans, and risk registers.
  • Strong written documentation and risk communication skills.
  • High attention to data quality, consistency, and documentation accuracy.
  • Ability to independently manage follow-up and drive items to closure.
  • Working familiarity with NIST CSF, NIST 800-53, ISO 27001/27002, or CIS frameworks.
  • Strong communication skills for working with vendors and internal stakeholders.
  • Security+ or CTPRP certification; CISA, CRISC, CISM, or ISO 27001 Lead Auditor preferred.
  • Experience with ProcessUnity, ServiceNow GRC, Archer, or security ratings tools preferred.
  • Experience assessing cloud providers, MSPs, or technology vendors preferred.
  • Experience managing assessment queues against SLAs in regulated environments preferred.

Benefits

  • Remote work opportunity.
  • US pay range of $75–$90 per hour.
  • Equal opportunity consideration in accordance with applicable law.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Scientist

Figma 1K-5K Internet Software & Services

Figma is hiring a Security Scientist to use security expertise and data analysis to reduce risks, improve detection and response, and strengthen the safety of its products, platform, and IT systems.

Apache Spark Presto Python R Snowflake SQL
2 hours, 38 minutes ago

Senior Security Assurance Engineer

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Security Compliance professional to operate its technology compliance program across corporate, security, engineering, and third-party systems, unifying controls and evidence for regulatory, contractual, and security assurance needs.

DevSecOps GitLab
2 days, 2 hours ago

Cyber Security Analyst II

RecargaPay 251-1K Capital Markets

RecargaPay is seeking a Cyber Security Analyst II for its Blue Team to defend cloud and internal environments through monitoring, hardening, vulnerability management, and resilient security controls.

AWS CI/CD Cybersecurity Encryption SIEM
2 days, 4 hours ago

Investigator

Stripe 5K-10K Diversified Financial Services

Stripe is hiring an Abuse Operations professional to investigate and lead response to product abuse and fraud incidents, helping protect merchants and strengthen fraud prevention across its financial infrastructure platform.

Apache Spark Databricks Network Security Pandas Python Scikit-learn SQL Trino
3 days, 2 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers