Third-Party Risk Analyst
Job description
About the role
You own end-to-end security assessments for model providers, subprocessors, and SaaS tooling, interpreting SOC 2 and ISO reports, pen tests, DPAs, and subprocessor lists to turn findings into documented residual risk and compensating controls. You design and stand up a TPRM program with intake, tiering, SLAs, escalation, exceptions, and risk acceptance, pitch and implement tooling to compress time-to-close integrated with GRC and ticketing, build continuous monitoring for critical vendors with annual reviews on a real cadence, and map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations including flow-down to subprocessors.
Key facts
What you'll do
- Conduct risk assessments for model providers, subprocessors, and SaaS tooling, then translate findings into documented residual risk and compensating controls.
- Read SOC 2 and ISO reports critically, evaluating scope, carve-outs, CUECs, exceptions, and whether testing supports the opinion, and use that evaluation to inform risk decisions.
- Review penetration tests, data processing agreements, and subprocessor lists, assessing how findings should change our level of reliance on each third party.
- Turn security findings into decisions by recommending and tracking compensating controls and justifiable risk acceptance where appropriate.
- Design and stand up a TPRM program including standardized intake, tiering, SLAs, escalation paths, exceptions handling, and formal risk acceptance criteria.
- Pitch and implement tooling and workflows that compress time-to-close, integrated with the GRC stack (Drata) and ticketing systems to streamline evidence collection and tracking.
- Build continuous monitoring for critical vendors and run annual reviews on a defined cadence to ensure ongoing alignment with our risk posture.
- Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, and ensure those requirements are correctly flow-down to subprocessors through contracts and controls.
Requirements
- Bring 4 or more years of experience in third-party or vendor security risk or security assessment with real assessment work you have performed.
- Demonstrate working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, and show the ability to reason about obligations under the EU AI Act.
- Show technical literacy in cloud architecture, identity and access models, encryption, and data flows across systems and interfaces.
- Read and interpret DPAs, BAAs, and security exhibits comfortably, with judgment about which clauses materially affect our risk posture.
- Bias toward shipping solutions by independently pitching recommendations and driving implementation to closure.
- Communicate clearly in writing and tolerate high ambiguity, producing memos and guidance when no precedent exists.
Nice to have
- Experience assessing AI or ML vendors or inference infrastructure and familiarity with associated risk patterns.
- Knowledge of ISO 42001 or the NIST AI Risk Management Framework when evaluating AI-specific controls.
- Ability to write scripts and automate repetitive tasks to eliminate manual toil in evidence gathering and tracking.
- Hands-on experience administering GRC platforms such as Drata, Vanta, or similar systems that support continuous compliance.
- Prior time at an early-stage startup where you built the third-party risk function rather than joined it already formed.
- Possession of certifications such as CISSP, CISA, CRISC, or CTPRP that reinforce depth in risk and control management.
Engineering methods
No specific methods or tools are prescribed beyond an expectation of disciplined assessment practices and comfort with cloud and security tooling.
Relevant systems
The role explicitly references the GRC platform Drata and ticketing systems for tracking remediation and exceptions.
Practical notes
You will work remotely from the United States, and the role is full-time. You must be able to independently scope assessments, manage ambiguity, and communicate judgments to technical and non-technical stakeholders. You should expect to handle a portfolio of vendors, maintain continuous monitoring for critical third parties, and iterate on the TPRM program as the company scales.