GRC TPRM SME
Listed on 2026-07-12
-
IT/Tech
Cybersecurity
GRC TPRM Assessment and Remediation SME
We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation — from inventory governance through assessment coordination, escalation management, and executive reporting — in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.
Key Responsibilities:
- Supplier Inventory Management
• Maintain the Supplier Inventory (GRC platform, e.g., Supplier Ninja) as the single source of truth for assessment status.
• Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
• Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., One Trust).
- Assessment Execution
• Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC
2) and validate evidence (audit reports, certifications, pen test results).
• Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
• Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
• Confirm onsite-assessed suppliers have current-year coverage (e.g., in Air Table).
• Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
- Remediation Management
• Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
• Coordinate with Legal, Procurement, and Info Sec on remediation timelines and compensating controls.
- Stakeholder Communication & Escalation
• Run a structured outreach cadence with DRIs (kick-off → 3 follow-ups → 3 escalations to management).
• Track response/non-response rates for every outreach cycle.
• Escalate unresolved/high-risk findings to client leadership and track to closure.
- Weekly Reporting
• Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re) assessment, and overall assessment/remediation coverage.
Required Qualifications:
- 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
- Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
- Hands-on experience with GRC/TPRM tools (One Trust, Archer, Service Now GRC, Supplier Ninja, or similar).
- Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
- Excellent written communication for remote, client-facing engagement.
- Experience operating in distributed/remote teams.
Preferred Qualifications:
- Certification: CTPRP, CRISC, CISA, or CISSP.
- Experience with Wrike, Air Table, Jira, or similar tracking tools.
- Prior experience in regulated industries (financial services, healthcare, insurance).
- Track record producing leadership-facing weekly reporting.
Company Benefits & Culture:
- Inclusive and diverse work environment
- Opportunities for professional growth and development
- Comprehensive health and wellness benefits
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).