×
Register Here to Apply for Jobs or Post Jobs. X

Technical Risk Management Professional

Job in Auburn, King County, Washington, 98001, USA
Listing for: KellyMitchell Group
Full Time position
Listed on 2026-10-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 52000 - 76000 USD Yearly USD 52000.00 76000.00 YEAR
Job Description & How to Apply Below
Job Summary

Our client is seeking an experienced Third-Party Risk Management / Technical Risk Management professional to join their team. This is a contract opportunity for a hands-on risk professional who can independently manage the vendor risk lifecycle, maintain and analyze an enterprise technical risk register, perform technical and quantitative risk assessments, and translate technical findings into business-relevant risk. The ideal candidate will have strong experience with vendor risk assessments, risk quantification methodologies such as FAIR, security frameworks, and technical risk analysis, while being comfortable operating independently with minimal oversight.

Contract

Details
  • Contract type and duration:
    Contract, approximately 1 year
  • Contract dates: 10/19/2026 – 10/15/2027
  • Work location:

    Remote – US
  • Onsite, hybrid or remote expectations:
    Fully Remote
Core Responsibilities
  • Own and operate the Technical Risk Management program end-to-end, including maintaining the enterprise risk register and driving risk identification, analysis, ownership, and closure
  • Manage the Third-Party Risk Management lifecycle for assigned vendors, including intake, inherent-risk tiering, security questionnaire review, evidence/documentation review, and risk scoring
  • Apply structured risk quantification methods such as FAIR or similar methodologies to assess and prioritize vendor and technical risks in financial or business-impact terms
  • Perform technical risk analysis across infrastructure, applications, and vendor architecture findings
  • Translate technical control gaps and findings into clear, business-relevant risk statements
  • Partner with security engineering and GRC stakeholders to evaluate architecture diagrams, scan results, control configurations, and other technical evidence
  • Track vendor findings and remediation commitments through closure and raise stalled items as needed
  • Monitor existing vendors for material changes in risk posture, including breach disclosures, control changes, and subprocessor changes
  • Prepare and present risk and TPRM reporting, metrics, and updates for internal stakeholders and leadership
  • Operate independently using established TPRM and risk management processes while exercising judgment on prioritization and escalation
Required Skills/Experience (Must-Haves)
  • 5+ years of hands-on experience managing third-party/vendor risk assessments
  • 3+ years of experience in technical or quantitative risk management
  • Strong experience with vendor intake, inherent-risk tiering, security questionnaires, documentation/evidence review, and risk scoring
  • Experience applying FAIR or similar risk quantification methodologies
  • Experience independently owning and maintaining a risk register or risk management program
  • Strong technical fluency with infrastructure, application, and vendor architecture and security documentation
  • Ability to critically evaluate security controls and determine whether they address the underlying risk
  • Working knowledge of common security frameworks including SOC 2, ISO 27001, and NIST CSF
  • Strong organizational skills and ability to manage a high-volume caseload of vendor assessments and risk register items
  • Excellent written and verbal communication skills for vendor-facing correspondence, technical findings, and leadership-level reporting
Preferred Skills/Experience (Nice-to-Haves)
  • Experience working in a SaaS or technology company’s TPRM or Technical Risk Management function
  • Formal training or certification in FAIR / Open FAIR
  • Familiarity with GRC or TPRM tools such as One Trust, Vanta, Archer, Service Now GRC, or similar platforms
  • CISSP, CISA, or CRISC certification
  • Experience with enterprise-level technical risk analysis and risk quantification
  • Third-Party Risk Management and Technical Risk Management…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary