Haystack
← Back to Jobs
Remote
Other
VE

W2// Subject Matter Expert

VensIT CorpUnited States🇺🇸United StatesPosted Sep 28, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
2 days ago
SOC 2Inventory ManagementOutreachProcurementRisk Management

Job Description

Subject Matter Expert 

Remote

Long term

 We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation — from inventory governance through assessment coordination, escalation management, and executive reporting — in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.

Key Responsibilities

1. Supplier Inventory Management

  • Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
  • Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
  • Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).

2. Assessment Execution

  • Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
  • Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
  • Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
  • Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
  • Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.

3. Remediation Management

  • Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
  • Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.

4. Stakeholder Communication & Escalation

  • Run a structured outreach cadence with DRIs (kick-off → 3 follow-ups → 3 escalations to management).
  • Track response/non-response rates for every outreach cycle.
  • Escalate unresolved/high-risk findings to client leadership and track to closure.

5. Weekly Reporting

Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.

 

Similar jobs