Anthropic9 дней назад
Third Party Risk Analyst, Security GRC
Зарплата не указана
Remote-Friendly (Travel Requ…
Обязанности
- 01Own the Mission Critical vendor portfolio: maintain the tiered list, validate it against business impact analysis findings, support exit and failover planning, and drive risk treatment for single points of failure with Procurement, Business Continuity, and business owners
- 02Manage the Highest-Risk vendor portfolio: keep security, privacy, and compliance assessment depth aligned to active vendor exposure, and drive remediation with the relevant domain teams
- 03Support vendor incident response: vendor-side impact assessment, business-owner coordination, and post-incident risk treatment
- 04Run inherent risk assessments through the intake workflow: review agent-prefilled tiering, evaluate vendor controls and evidence across security, privacy, compliance, and operational risk, determine residual risk, and route to domain reviewers where deeper assessment is warranted
- 05Operate the TPRM issue management workflow: document findings with clear risk statements, assign owners, track treatment to closure
- 06Tune and maintain the TPRM Risk Agent alongside the team through prompt development, backtest calibration, error analysis, and output QA
- 07Contribute to KPI/KRI reporting on portfolio coverage and cycle time
Требования
- 01Experience running third party or vendor risk assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure
- 02Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them when the evidence is incomplete or the answer isn't in a framework
- 03Ability to assess a vendor across security, privacy, compliance, and operational risk domains, and to recognize which findings you can close yourself and which need a domain specialist
- 04Track record of driving risk treatment to closure through influence across teams with competing priorities
- 05Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy
- 06Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls
- 07Hands-on time in a procurement or GRC platform with an understanding of how intake, tiering, and assessment routing fit together
- 08Working knowledge of business continuity, disaster recovery, and concentration risk concepts, with the ability to apply them to a vendor portfolio
- 09Experience assessing cloud infrastructure, data center, or data-pipeline vendors
- 10Experience with vendor financial health or solvency screening (credit models, financial statement review, or tools such as RapidRatings, CreditSafe, or LSEG)
- 11Experience supporting SOX, SOC 2, or ISO 27001 third party or vendor management controls
- 12Exposure to exit planning, contract termination provisions, or supplier failover testing
Условия
- 01Annual Salary: $255,000 — $270,000 USD
- 02Location-based hybrid policy: expected to be in office at least 25% of the time
- 03Visa sponsorship: available; reasonable efforts made to secure visa
- 04Minimum education: Bachelor’s degree or equivalent combination of education, training, and/or experience
- 05Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
- 06Minimum years of experience: commensurate with internal job level requirements for the position