
GRC Automation Specialist, Governance, Risk & Compliance, TPRM
Posted Sep 3

Posted Sep 3
This is a fully remote position, open to applicants in United Kingdom.
• Evaluate third-party risks associated with both new and existing systems at Samsara.
• Develop automated workflows to enhance and expand the third-party risk management program.
• Collaborate with Legal and Procurement for ongoing assessments of vendors.
• Create and optimize AI-driven workflows for the vendor risk management initiative.
• Work in partnership with various departments to comprehend and outline vendor use cases and data flows.
• Deliver programmatic updates and communicate information regarding the program, third-party, and technical risks to the Information Security leadership.
• Enhance automation and efficiency within the TPRM program utilizing Zip, Vanta, third-party tools, and native solutions.
• Ensure that security reviews and reassessments evolve in line with the company's growth.
• Collaborate with Procurement, Legal, and Privacy teams to identify, document, and mitigate vendor risks throughout the vendor lifecycle.
• Advocate for and integrate Samsara’s cultural principles as the company scales internationally and opens new offices.
• 2-4 years of experience in governance, risk, and compliance.
• Proven experience in implementing or managing vendor risk programs.
• Background in conducting security and maturity assessments.
• Experience in creating or maintaining risk registers, compliance inventories, and control mappings for both internal and external systems.
• Ability to collaboratively implement security controls across platforms such as Okta, Slack, Salesforce, and internal tools.
• Experience in coordinating with external auditors, internal engineering teams, business stakeholders, senior leadership, and security operations teams on procurement activities, audit controls, and compliance requirements.
• Proven experience in conducting vendor risk assessments, including reviewing security certifications, penetration tests, and policies.
• Strong knowledge of vendor integration risks and permission scoping across SaaS platforms like Slack, Google Workspace, and Salesforce.
• Capability to translate complex technical findings and requirements into understandable business risks and needs for non-technical stakeholders.
• Familiarity with NIST Cybersecurity Framework profiles, SOC 2, ISO 27001, or similar frameworks.
• Experience in creating workflows using automation and AI support.
• Knowledge of GRC and procurement platforms such as Zip and Vanta.
• Ability to manage a high volume of vendor requests and navigate competing priorities.
• Prior experience in assessments within the Software-as-a-Service sector.
• Competitive total compensation package that includes base salary, performance-based bonuses/variable pay, and equity for eligible positions.
• Flexible, employee-driven remote work model.
• Professional development stipend to support continuous learning.
• Comprehensive health insurance options.
• Generous parental leave policies.
• Flexible working arrangements that include both remote and in-person options where operationally feasible.
RTX
EnergyHub
Johnson & Johnson
Johnson & Johnson
Get handpicked remote jobs straight to your inbox weekly.