Third-Party Risk Management Analyst IV

atSamsaraRemoteUS flagUnited StatesFull-timeBusiness AnalystMid-levelSenior$110.7k – $167.4k/year

Posted 3 days ago

This is a fully remote position, open to applicants in United States.

πŸ“‹ Description

β€’ Oversee comprehensive third-party security risk assessments utilizing both qualitative and quantitative approaches.

β€’ Propose vendor risk ratings and classifications in accordance with Samsara's Vendor Risk Management Policy.

β€’ Manage the vendor reassessment schedule and monitor the resolution of security vulnerabilities throughout the vendor lifecycle.

β€’ Collaborate with Legal, Procurement, and system/relationship owners regarding vendor contracts and onboarding requests submitted via Zip.

β€’ Ensure that security prerequisites, including incident notification, data training, and compliance, are established before vendors commence operations.

β€’ Raise any unresolved vendor risks to Security leadership, Legal, Procurement, and relevant business stakeholders.

β€’ Assist in internal and external audits of the vendor risk program, including ISO, SOC, and FedRAMP audits.

β€’ Develop and uphold metrics, dashboards, and reporting related to third-party risk status and program effectiveness.

β€’ Facilitate automation and AI-driven tools within vendor risk processes.

β€’ Provide mentorship to junior TPRM team members.

β€’ Advocate for Samsara's cultural principles as the company expands globally and opens new offices.


⛳️ Requirements

β€’ Minimum of 5 years of experience in third-party/vendor risk management, GRC, or information security compliance.

β€’ Proficiency in leveraging automation, scripting, or low-code workflows to enhance a vendor risk program.

β€’ Practical experience conducting vendor security assessments and managing a vendor tiering program.

β€’ Experience collaborating with Legal and Procurement on security and privacy terms in vendor contracts, including security addendums and Data Processing Agreements (DPAs).

β€’ Must be located in the US, excluding the San Francisco Bay Area, New York City, and Washington, D.C. metropolitan areas.

β€’ Knowledge of NIST CSF, ISO 27001, or SOC 2 standards.

β€’ Familiarity with a GRC or vendor risk management platform such as Vanta, ServiceNow, OneTrust, Archer, or similar tools.

β€’ Relevant certifications such as CTPRP, CISA, CRISC, or CISSP are preferred.


🏝️ Benefits

β€’ Initial RSU grant with no vesting cliff.

β€’ Continuous equity refresh opportunities linked to performance.

β€’ Performance-based bonus/variable pay.

β€’ Above-market total compensation.

β€’ Flexible, employee-led remote work model.

β€’ Professional development stipend.

β€’ Comprehensive health plans.

β€’ Parental leave policies.

β€’ Offices available for those who prefer in-person work.

People also viewed

PowerSchool1 day ago

Senior Customer Solutions Analyst

US flagTexas OnlyFull-timeBusiness Analyst$42.1k – $76.4k/year
ApplyView job
U.S. Financial Technology1 day ago

Identity & Access Management Analyst

US flagUnited States OnlyFull-timeBusiness Analyst$94.3k – $107.5k/year
ApplyView job
Saab1 day ago

Senior Program Performance Management Analyst

US flagAlabama, +13 more statesFull-timeBusiness Analyst$90k – $135k/year
ApplyView job
Braun Intertec Corporation1 day ago

Senior Business Systems Analyst – D365 Financial Systems Analyst

US flagColorado, +4 more statesFull-timeBusiness Analyst$88k – $131k/year
ApplyView job
General Dynamics Information Technology1 day ago

Senior Business Analyst

US flagUnited States OnlyFull-timeBusiness Analyst$89.7k – $121.3k/year
ApplyView job
CoverGo | Insurtech1 day ago

Senior Business Analyst – Insurance

CO flagColombia, +3 more countriesFull-timeBusiness Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers