Why This Role Stands Out
This remote role at TechClub Inc. offers a fantastic opportunity to lead critical third-party risk assessments and drive impactful remediation strategies, leveraging your expertise in a high-visibility capacity. You'll thrive here if you are a proactive communicator with a passion for cybersecurity risk management and a desire to grow within a reputable organization. We encourage you to apply and explore this exciting career advancement.
Quick Overview
Job Description
Role: GRC - Third-Party Risk Management (TPRM) Assessment SME
Location: Sunnyvalle, CA
(100% onsite Role)
Job Description:
We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation — from inventory governance through assessment coordination, escalation management, and executive reporting — in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.
Key Responsibilities
1. Supplier Inventory Management
- Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
- Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
- Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).
2. Assessment Execution
- Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
- Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
- Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
- Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
- Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
3. Remediation Management
- Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
- Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
4. Stakeholder Communication & Escalation
- Run a structured outreach cadence with DRIs (kick-off → 3 follow-ups → 3 escalations to management).
- Track response/non-response rates for every outreach cycle.
- Escalate unresolved/high-risk findings to client leadership and track to closure.
5. Weekly Reporting
Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.
Similar jobs
- GT
Senior Data Modeler/Architect
NewGSPANN Technologies
Orlando, FL🇺🇸Hybrid23 hours agoOracleSQLAzure - UT
Senior Network Engineering Coordinator
NewUp2date Technologies
Louisville, KY🇺🇸Hybrid23 hours agoFiberPrismaStakeholder Management+1 - FT
IT Field Service Support
NewFourth Technologies, Inc.
Waltham, MA🇺🇸On-site23 hours agoActive DirectoryAzureTechnical Support - IR
Enterprise Data Governance Consultant
NewIndus River Technologies Inc.
Nashville, TN🇺🇸Hybrid23 hours agoComplianceHIPAAPMP+1 - PB
Cutomer Service Representative - Planner
NewPerformix Business Services, LLC
Foxborough, MA🇺🇸On-site23 hours agoSalesforceMediationMicrosoft Excel+2 - TD
QA AI Lead with Healthcare Domain- Remote
NewThe Dignify Solutions, LLC
United States🇺🇸Remote23 hours agoGenerative AI