PlaidНовая13 часов назад
Security Analyst, Third-Party Ecosystem Risk Management
Зарплата не указана
Полная занятостьУдалёнка
Навыки
SOC 2ISO 27001NIST CSFAI toolingTPRM platformOneTrustProcessUnityWhisticSecurityScorecar
Обязанности
- 01Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions
- 02Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors
- 03Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate
- 04Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows
- 05Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders
- 06Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting
Требования
- 014+ years of experience in vendor risk management
- 02Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating
- 03Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment
- 04Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR)
- 05Ability to read a control environment and tell a real gap from an acceptable compensating control
- 06Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one
- 07Track record running assessments at volume without dropping rigor
- 08Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow
- 09Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving
- 10Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact
- 11Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput