
Vendor Risk, GRC Analyst
Posted Jul 20

Posted Jul 20
This is a fully remote position, open to applicants in Bulgaria.
β’ Take charge of the vendor and third-party risk lifecycle within a rapidly growing technology company.
β’ Oversee the supplier register and manage the reassessment schedule based on the significance of suppliers.
β’ Monitor fourth-party dependencies and concentration risks among key suppliers, ensuring alignment with DORA ICT third-party standards and ISO 27001 supplier controls.
β’ Assist in maintaining policies, mapping controls, and collecting evidence to ensure the Statement of Applicability (SoA) is audit-ready.
β’ Perform risk assessments utilizing an ISO 31000-aligned approach and participate in Risk & Control Self-Assessment workshops and follow-up on remediation efforts.
β’ Aid in the upkeep of the RoPA, conduct DPIAs, and handle data subject requests.
β’ Strong foundation in GRC β Demonstrated experience in governance, risk management, compliance, IT audit, vendor risk, or information security, with direct responsibility for third-party/supplier risk.
β’ Expertise in third-party risk β Hands-on experience conducting vendor due diligence, security questionnaires (SIG, CAIQ, or similar), and reviewing contractual risks.
β’ Familiarity with frameworks β Knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, and GDPR processor responsibilities; understanding of DORA third-party requirements is advantageous.
β’ Independent critical thinker β Comprehend the rationale behind controls, identify gaps, and suggest enhancements proactively.
β’ Practical compliance approach β Maintain a balance between thoroughness and efficiency.
β’ Effective communicator β Skillful in drafting questionnaires, risk memos, and responses directed at suppliers with clarity.
β’ Equal Opportunities Statement
β’ Diversity drives innovation and growth.
β’ Appreciates diverse perspectives and skill sets.
Circana
Zero Hash
World Kinect
The Hartford
Get handpicked remote jobs straight to your inbox weekly.