
Third-Party Risk Management Analyst IV
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
β’ Oversee comprehensive third-party security risk assessments utilizing both qualitative and quantitative approaches.
β’ Propose vendor risk ratings and classifications in accordance with Samsara's Vendor Risk Management Policy.
β’ Manage the vendor reassessment schedule and monitor the resolution of security vulnerabilities throughout the vendor lifecycle.
β’ Collaborate with Legal, Procurement, and system/relationship owners regarding vendor contracts and onboarding requests submitted via Zip.
β’ Ensure that security prerequisites, including incident notification, data training, and compliance, are established before vendors commence operations.
β’ Raise any unresolved vendor risks to Security leadership, Legal, Procurement, and relevant business stakeholders.
β’ Assist in internal and external audits of the vendor risk program, including ISO, SOC, and FedRAMP audits.
β’ Develop and uphold metrics, dashboards, and reporting related to third-party risk status and program effectiveness.
β’ Facilitate automation and AI-driven tools within vendor risk processes.
β’ Provide mentorship to junior TPRM team members.
β’ Advocate for Samsara's cultural principles as the company expands globally and opens new offices.
β’ Minimum of 5 years of experience in third-party/vendor risk management, GRC, or information security compliance.
β’ Proficiency in leveraging automation, scripting, or low-code workflows to enhance a vendor risk program.
β’ Practical experience conducting vendor security assessments and managing a vendor tiering program.
β’ Experience collaborating with Legal and Procurement on security and privacy terms in vendor contracts, including security addendums and Data Processing Agreements (DPAs).
β’ Must be located in the US, excluding the San Francisco Bay Area, New York City, and Washington, D.C. metropolitan areas.
β’ Knowledge of NIST CSF, ISO 27001, or SOC 2 standards.
β’ Familiarity with a GRC or vendor risk management platform such as Vanta, ServiceNow, OneTrust, Archer, or similar tools.
β’ Relevant certifications such as CTPRP, CISA, CRISC, or CISSP are preferred.
β’ Initial RSU grant with no vesting cliff.
β’ Continuous equity refresh opportunities linked to performance.
β’ Performance-based bonus/variable pay.
β’ Above-market total compensation.
β’ Flexible, employee-led remote work model.
β’ Professional development stipend.
β’ Comprehensive health plans.
β’ Parental leave policies.
β’ Offices available for those who prefer in-person work.
PowerSchool
U.S. Financial Technology
Saab
Braun Intertec Corporation
Get handpicked remote jobs straight to your inbox weekly.