XTN-A742599 | GRC ANALYST
Remote
Job Summary
Execute day-to-day activities within the Third-Party Risk Management program, ensuring timely processing of supplier risk assessments and conducting thorough reviews of security questionnaires for completeness and accuracy. Support coordination with service team members to deliver high-quality deliverables against established SLAs while maintaining and enhancing process documentation, including SOPs, workflows, and training materials. Manage access controls and data integrity for third-party risk tools like VISO Trust, providing documentation and support for internal and external audits related to vendor due diligence.
Required Qualifications
- Strong understanding of third-party/vendor risk management (TPRM/VRM) practices and assessment methodologies.
- Experience with VISO Trust or similar platforms such as OneTrust, Whistic, SecurityScorecard, or BitSight.
- Knowledge of major information security and privacy frameworks, including ISO 27001, NIST CSF, SOC 2, and GDPR.
- Proficiency with risk management systems, spreadsheets (Excel/Google Sheets), and reporting dashboards.
- Understanding of supplier lifecycle processes and procurement workflows.
- Ability to define, measure, and report on KPIs, SLAs, and operational performance metrics.
- Strong attention to detail and accuracy in data review.
- Excellent written and verbal communication skills.
- Ability to multitask, prioritize, and manage workload in a fast-paced environment.
- Analytical mindset with strong problem-solving capabilities.
- High level of integrity, confidentiality, and professional judgment.
- Effective collaboration with cross-functional and globally distributed teams.
- Strong stakeholder communication and confidence in presenting recommendations.
- Commitment to continuous improvement and operational efficiency.
Desired Qualifications
- Professional certifications such as CISSP, CISA, or CISM are preferred.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.