
Security & Vendor Risk Specialist
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in New York.
• Analyze vendor SOC 2 reports, security questionnaires, and penetration-test evidence.
• Assess vendor documentation against established buyer security standards.
• Determine if the provided evidence supports the stated security controls.
• Spot any missing documentation, control deficiencies, inconsistencies, and unsupported assertions.
• Generate recommendations for approval, remediation, escalation, or denial.
• Review SOC 2 scope, reporting periods, control coverage, exceptions, and auditor conclusions.
• Identify discrepancies between vendor services and the systems evaluated.
• Recognize expired or inadequate bridge letters and gaps in reporting periods.
• Evaluate penetration-test evidence for relevance, currency, and scope.
• Examine supporting compliance documents.
• Analyze vendor practices regarding data collection, access, processing, storage, and transfer.
• Evaluate risks associated with sub-processors, hosting providers, and downstream partners.
• Review considerations related to data residency, retention, deletion, access control, and encryption.
• Identify security issues that necessitate further due diligence or contractual protections.
• Assess vendor responses in the context of procurement and renewal processes.
• Create vendor-security review rubrics at a step level.
• Develop reference responses that reflect seasoned professional judgment.
• Establish criteria for evidence quality, control effectiveness, data risk, and readiness for approval.
• Differentiate between documentation issues and significant security deficiencies.
• Refine scoring standards for consistent assessments by reviewers.
• A minimum of 8 years of professional experience in security review, vendor risk management, third-party risk, or information security.
• Practical experience in evaluating SOC 2 reports, security questionnaires, and compliance documentation.
• Strong grasp of vendor due diligence and third-party security evaluation processes.
• Experience in identifying control deficiencies, evidence limitations, and inconsistencies in scope.
• Familiarity with risks related to data handling, privacy, sub-processors, and supply chain security.
• Exceptional written communication and structured analytical abilities.
• Capability to produce detailed rubric-style feedback and justifiable review conclusions.
• Ability to operate autonomously in a remote and asynchronous setting.
• A degree in cybersecurity, information systems, computer science, risk management, business, or a related field may be advantageous.
• Relevant professional certifications such as CISSP, CISA, CISM, or CRISC may enhance an application.
• Equivalent senior-level professional experience in vendor security or third-party risk may also be considered.
• Experience within a formal third-party risk management program.
• Background in assessments of SaaS, cloud, technology, or enterprise vendors.
• Familiarity with security frameworks such as ISO 27001, NIST, or similar standards.
• Experience in reviewing penetration-test reports and remediation documentation.
• Understanding of procurement, contract renewal, and vendor onboarding processes.
• Previous experience in task writing, rubric creation, quality review, or AI training data development.
• Experience collaborating with procurement, legal, privacy, compliance, and IT teams.
• Flexible scheduling.
• Competitive rates ranging from $85 to $105 per hour based on expertise and project scope.
• Weekly payments through Stripe or Wise.
• Fully remote working environment.
• Project timelines may be extended, shortened, or modified based on scope and performance.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.