Fractional Supply Chain Analyst
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
Supply Chain Analyst (Vendor & Supply Chain Risk)
Location
:
Hybrid Remote/On-Site in Austin, TX (Set days in-office weekly required)
Experience Level: Mid to Senior Level
Job Type: Contract / Fractional (Full time)
Certifications: GRC or security certifications (CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CIPP) a bonus
About the RoleCrux Security is looking for a self-directed Supply Chain Analyst to stand up a Supply Chain Risk Management (SCRM) program for a client engagement, working under the direction of an experienced Supply Chain lead who will provide subject-matter direction and quality review. This is a force-multiplier role: you will take a defined scope of work and drive it to audit-ready completion with minimal day-to-day oversight, escalating judgment calls rather than routine execution questions.
You will build a supplier register from scratch, design and apply a vendor risk tiering methodology, review and update security contract clauses alongside Legal, stand up a SOC 2 / ISO 27001 certification review process for critical vendors, and design a SaaS procurement security checklist. The end state is an ISO 27001:2022-aligned evidence package (mapped to
A.5.19–A.5.23) that is audit-ready, along with documented procedures and a formal transition plan handing long-term ownership to the client.
Vendor Inventory & Supplier Register
- Confirm whether an existing vendor inventory exists outside of IT, and consolidate all available sources into a single, structured supplier register
- Design the register as a spreadsheet-based artifact capturing vendor name, service type, data access, criticality tier, contract status, and review cadence
Vendor Risk Tiering
- Design and apply a vendor risk tiering methodology to the confirmed supplier inventory, prioritizing critical vendors (approximately tens) first
- Build tiering criteria around data sensitivity, operational dependency, and supply chain risk factors, aligned to ISO 27001 controls
A.5.19 and
A.5.21 - Produce a tiered vendor register as an audit-ready artifact
Security Contract Clauses & Legal Coordination
- Review existing security contract clauses and MSA language for alignment with ISO 27001:2022 requirements
- Update and formalize clause language in active coordination with Legal
- Deliver an updated, audit-ready security contract annex or clause library applicable to new and renewing vendor agreements
Vendor Assurance Review (SOC 2 / ISO 27001)
- Establish a repeatable process for reviewing vendor SOC 2 reports and ISO 27001 certifications as part of ongoing supplier monitoring
- Produce a review methodology, a findings and exceptions log, and completed assessments for all critical vendors within scope
SaaS Procurement Security
- Design a security checklist for evaluating SaaS vendors at the point of procurement, covering data handling, access controls, certifications, incident notification, and exit/portability requirements
- Coordinate with Procurement and Legal throughout checklist design
- Formally introduce security as a touchpoint in the procurement lifecycle, defining where and how reviews occur, who is responsible, and the escalation path for high-risk vendors
- Produce a workflow document that Procurement can operationalize as the long-term owner
ISO 27001:2022 Evidence & Audit Readiness
- Compile all SCRM-related outputs into a structured evidence package mapped to controls
A.5.19,
A.5.20,
A.5.21,
A.5.22, and
A.5.23 - Ensure traceability between the supplier register, tiering methodology, contract clause library, vendor assessments, and control objectives
- Deliver an audit-ready evidence package
Documentation & Transition Planning
- Document all operational procedures for ongoing SCRM program management, including vendor tiering reviews, contract clause…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).