Haystack
← Back to Jobs
Other
AG

GRC TPRM Assessment and Remediation SME

ASCII Group LLCAustin, TX🇺🇸United StatesPosted 14 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
Yesterday
SOC 2Inventory ManagementJiraOutreachProcurementRisk ManagementServiceNow

Job Description

The following requirement is open with our client. 

Title                                       : GRC TPRM Assessment and Remediation SME

Location                               : Austin, TX/Cupertino, CA (Hybrid)

Duration                              : 12 Months

Relevant Experience      :

 

Detailed Job Description:

We are looking for an experienced GRC Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation from inventory governance through assessment coordination, escalation management, and executive reporting, client-facing environment.

 

Job Responsibilities:       

Supplier Inventory Management:

         Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.

         Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.

         Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).

Assessment Execution:

         Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).

         Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.

         Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.

         Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).

         Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.

Remediation Management

         Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.

         Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.

Stakeholder Communication & Escalation:

         Run a structured outreach cadence with DRIs (kick-off ? 3 follow-ups ? 3 escalations to management).

         Track response/non-response rates for every outreach cycle.

         Escalate unresolved/high-risk findings to client leadership and track to closure.

Weekly Reporting:

         Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.

 

Must Have Skills:

         5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.

         Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.

         Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).

         Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.

         Excellent written communication for remote, client-facing engagement.

         Experience operating in distributed/remote teams. Preferred Qualifications

         Certification: CTPRP, CRISC, CISA, or CISSP.

         Experience with Wrike, AirTable, Jira, or similar tracking tools.

         Prior experience in regulated industries (financial services, healthcare, insurance).

         Track record producing leadership-facing weekly reporting.

 

Thanks and Regards, 

Goutham Eluri

Technical Recruiter 

ASCII Group LLC. 

38345 W. 10 Mile Rd, Ste.#365; Farmington, MI  48335 Office:

Email:  Website:  

 

 

Similar jobs