We are seeking a detail-oriented Third-Party GRC Analyst to support the assessment, monitoring, and governance of third-party risk across the organization. This role is responsible for evaluating vendor security practices, ensuring compliance with internal and regulatory requirements, and supporting the enterprise’s risk management lifecycle.
Conduct third-party risk assessments for new and existing vendors, including security questionnaires, documentation review, and risk scoring.
Collaborate with Legal, Procurement, InfoSec, and Business Units to ensure compliance with vendor governance policies.
Monitor ongoing vendor risks, including SLA adherence, data privacy, financial stability, and regulatory compliance.
Track and escalate vendor risks, issues, and remediation plans using GRC platforms (e.g., Archer, ServiceNow, OneTrust).
Assist in defining and enhancing third-party risk frameworks, processes, and controls.
Maintain vendor inventory and ensure alignment with compliance requirements (e.g., SOC 2, ISO 27001, NIST, GDPR, HIPAA).
Support audits and reporting activities related to third-party and supply chain risk.
Bachelor’s degree in Cybersecurity, Information Technology, Business, or related field.
3–5 years of experience in third-party risk management, GRC, or information security roles.
Knowledge of vendor due diligence processes, risk frameworks, and compliance standards.
Familiarity with GRC platforms (Archer, LogicGate, OneTrust, etc.).
Strong analytical, communication, and documentation skills.
CISA, CISM, CRISC, CISSP, or related certifications.
Experience working in regulated industries (finance, healthcare, pharmaceuticals).
#ThirdPartyRisk, #GRCAnalyst, #RiskAndCompliance, #VendorRisk, #ITCompliance, #CyberRisk, #GRCJobs, #HybridWork, #RiskManagement, #ThirdPartyGovernance, #SecurityAnalyst, #DataPrivacy, #SOC2Compliance, #VendorGovernance, #CyberSecurityJobs, #GovernanceRiskCompliance, #NISTFramework, #InfoSecCareers, #HIPAACompliance, #ISO27001, #SupplyChainRisk, #ComplianceCareers, #RegulatoryCompliance, #OneTrust, #ServiceNowGRC, #EnterpriseRisk, #VendorAssessment, #TechnologyRisk, #ITRiskManagement, #SecurityGovernance