Sr. TPRM Analyst
Listed on 2026-09-05
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
Senior Third-Party Risk Management Analyst
Required
Skills & Experience:
5+ years of experience in Third-Party Risk Management, Cybersecurity, Information Security, Audit, Risk Management, or GRC. Proven experience leading end-to-end vendor risk assessments, including due diligence, risk analysis, issue management, remediation tracking, and reassessments. Strong understanding of industry frameworks and assurance reports, including SOC 2, ISO 27001, NIST, and related security standards. Ability to independently evaluate vendor security controls and identify material business and cybersecurity risks.
Experience partnering with business owners, procurement, legal, cybersecurity, and vendor stakeholders to drive risk-informed decisions. Strong written and verbal communication skills with the ability to translate technical findings into business risk and executive-level messaging. Experience with Service Now TPRM or a comparable third-party risk management platform. Demonstrated ability to manage multiple assessments simultaneously while meeting contractual, regulatory, and business deadlines.
Comfortable operating in a fast-paced environment with minimal supervision and providing recommendations that support program maturity and continuous improvement.
Job Description:
We are seeking a Senior Third-Party Risk Management (TPRM) Analyst to serve as a trusted risk advisor responsible for managing end-to-end vendor risk assessments and helping drive risk-informed business decisions. In this role, you will partner closely with internal business stakeholders, procurement, legal, cybersecurity, and external vendors to evaluate security controls, assess business and cyber risks, track remediation activities, and ensure timely completion of third-party risk assessments.
The ideal candidate will be comfortable independently managing a high volume of assessments, providing credible challenge to vendors and stakeholders, translating technical findings into clear business risk recommendations, and maintaining audit-ready documentation that supports governance and compliance requirements. This individual will play a key role in optimizing operational workflows, helping business partners navigate the TPRA process from submission through completion, and contributing to the continued maturity and effectiveness of the organization's TPRM program.
Experience working within Service Now TPRM is highly preferred, as the organization continues to evolve and stabilize its third-party risk management processes following a recent platform migration.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).