Remotery

Third-Party Risk Analyst

atOpenRouterRemoteUS flagUnited StatesFull-timeRiskMid-levelSenior

Posted Aug 12

This is a fully remote position, open to applicants in United States.

📋 Description

• Take charge of comprehensive security assessments for model providers, subprocessors, and SaaS tools.

• Analyze and assess SOC 2 and ISO reports, paying close attention to scope, carve-outs, CUECs, exceptions, testing, penetration tests, DPAs, and lists of subprocessors.

• Transform findings into decisions regarding residual risk and compensating controls.

• Create and implement a third-party risk management program that includes intake processes, tiering, SLAs, escalation procedures, exceptions, and risk acceptance protocols.

• Assess and deploy tools that integrate with the Drata GRC stack and the ticketing system.

• Establish continuous monitoring for key vendors and conduct annual evaluations.

• Align vendor risk with obligations under SOC 2, ISO 27001, HIPAA, GDPR, and the EU AI Act, ensuring flow-down to subprocessors.


⛳️ Requirements

• Minimum of 4 years of experience in third-party/vendor security risk or security assessments.

• Proficient understanding of SOC 2, ISO 27001, HIPAA, and GDPR frameworks.

• Adequate understanding of the EU AI Act to apply its principles effectively.

• Technical knowledge in cloud architecture, access models, encryption, and data flows.

• Familiarity with DPAs, BAAs, and security exhibits.

• Capability to propose solutions and lead their implementation autonomously.

• Strong writing skills and a high tolerance for ambiguity.

• Preferred: experience in assessing AI/ML vendors or inference infrastructure.

• Preferred: familiarity with ISO 42001 or NIST AI RMF.

• Preferred: experience in scripting and automation.

• Preferred: GRC platform administration experience, such as with Drata or Vanta.

• Preferred: experience in early-stage startups building a function.

• Preferred: certifications such as CISSP, CISA, CRISC, or CTPRP.


🏝️ Benefits

• Competitive salary and performance-based bonuses.

• Comprehensive health, dental, and vision insurance.

• Flexible working hours and remote work options.

• Opportunities for professional development and training.

• Supportive and inclusive company culture.

People also viewed

Allianz15 hours ago

Senior Risk Control Surveyor

GB flagUnited Kingdom OnlyFull-timeRisk£60k/year
ApplyView job
ON Partners16 hours ago

Data Governance Lead – Senior Manager

US flagUnited States OnlyFull-timeRisk$190k – $200k/year
ApplyView job
CrowdStrike16 hours ago

Senior Governance, Risk, and Compliance Specialist

US flagUnited States OnlyFull-timeRisk$100k – $155k/year
ApplyView job
CACI International Inc16 hours ago

M365 Governance Analyst

US flagVirginia OnlyFull-timeRisk$98.5k – $206.8k/year
ApplyView job
Stride, Inc.17 hours ago

At-Risk Special Education Instructional Coach

US flagLouisiana, +3 more statesFull-timeRisk$60k/year
ApplyView job
PACIFICSOURCE17 hours ago

Document and Vendor Governance Specialist

US flagMissouri OnlyFull-timeRisk$45k – $72k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers