Quick Overview
Seniority
Mid Senior
Work mode
Remote
Location
Manor, TX, United States
Posted
Yesterday
SOC 2Inventory ManagementJiraOutreachProcurementRisk ManagementServiceNow
Job Description
Job Title : GRC TPRM Assessment & Remediation SME
Location : Austin, TX/Cupertino, CA
Location : Austin, TX/Cupertino, CA
JD :
Hybrid (3 days a week)
Job Title: GRC TPRM Assessment and Remediation SME
Role Descriptions:
• We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation — from inventory governance through assessment coordination, escalation management, and executive reporting — in a fully remote, client-facing environment.
• This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.
Key Responsibilities
1. Supplier Inventory Management:
• Maintain the Supplier Inventory (GRC platform, e.g., Supplier Ninja) as the single source of truth for assessment status.
• Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
• Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., One Trust).
2. Assessment Execution:
• Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
• Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
• Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
• Confirm onsite-assessed suppliers have current-year coverage (e.g., in Air Table).
• Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
3. Remediation Management
• Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
• Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
4. Stakeholder Communication & Escalation:
• Run a structured outreach cadence with DRIs (kick-off → 3 follow-ups → 3 escalations to management).
• Track response/non-response rates for every outreach cycle.
• Escalate unresolved/high-risk findings to client leadership and track to closure.
5. Weekly Reporting.
• Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.
Required Qualifications:
• 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
• Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
• Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
• Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
• Excellent written communication for remote, client-facing engagement.
• Experience operating in distributed/remote teams. Preferred Qualifications
• Certification: CTPRP, CRISC, CISA, or CISSP.
• Experience with Wrike, Air Table, Jira, or similar tracking tools.
• Prior experience in regulated industries (financial services, healthcare, insurance).
• Track record producing leadership-facing weekly reporting.
Experience Required: 8-10
** All submissions must have LinkedIn id of Candidate**
Job Title: GRC TPRM Assessment and Remediation SME
Role Descriptions:
• We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation — from inventory governance through assessment coordination, escalation management, and executive reporting — in a fully remote, client-facing environment.
• This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.
Key Responsibilities
1. Supplier Inventory Management:
• Maintain the Supplier Inventory (GRC platform, e.g., Supplier Ninja) as the single source of truth for assessment status.
• Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
• Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., One Trust).
2. Assessment Execution:
• Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
• Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
• Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
• Confirm onsite-assessed suppliers have current-year coverage (e.g., in Air Table).
• Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
3. Remediation Management
• Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
• Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
4. Stakeholder Communication & Escalation:
• Run a structured outreach cadence with DRIs (kick-off → 3 follow-ups → 3 escalations to management).
• Track response/non-response rates for every outreach cycle.
• Escalate unresolved/high-risk findings to client leadership and track to closure.
5. Weekly Reporting.
• Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.
Required Qualifications:
• 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
• Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
• Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
• Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
• Excellent written communication for remote, client-facing engagement.
• Experience operating in distributed/remote teams. Preferred Qualifications
• Certification: CTPRP, CRISC, CISA, or CISSP.
• Experience with Wrike, Air Table, Jira, or similar tracking tools.
• Prior experience in regulated industries (financial services, healthcare, insurance).
• Track record producing leadership-facing weekly reporting.
Experience Required: 8-10
** All submissions must have LinkedIn id of Candidate**
Similar jobs
- SI
Quantitative Systematic Trading Internship - PhD: Summer 2027 - Susquehanna International Group
Susquehanna International Group
New York, NY🇺🇸$8.6k/hrOn-site4 weeks agoMachine LearningC++Python+1 - SI
Quantitative Systematic Trader - PhD: 2027 - Susquehanna International Group
Susquehanna International Group
Bala-Cynwyd, PA🇺🇸On-site4 weeks agoMachine LearningC++Python+2 - UG
Per Diem Registration Representative
UnitedHealth Group
PORTLAND, ME🇺🇸$16 - $29/hrOn-site1 week ago401kMedical TerminologyMicrosoft Office+1 - RT
Partner BDR Opportunity | AI-Driven Partner Programs
NewRussell, Tobin & Associates
San Francisco, CA🇺🇸$100 - $110/hrHybridYesterdaySalesforceBusiness DevelopmentCRM+5 - OR
Oracle EBS Technical Lead
NewOraapps Inc
United States🇺🇸RemoteYesterdayOracleAccounts PayableAccounts Receivable+4 - KG
Loan IQ (Fulltime - New York City, NY)
NewK&K Global Talent Solutions
New York, NY🇺🇸On-siteYesterdaySQLBusiness AnalysisRequirements Gathering+2