Job Summary
The TPRM Analyst will be responsible for supporting the organization’s third-party risk management program by identifying, assessing, monitoring, and reporting risks associated with vendors, suppliers, service providers, and other third-party relationships. The role requires collaboration with internal stakeholders such as Information Security, Legal, Compliance, Procurement, Business Owners, and Vendor Management teams to ensure third-party engagements meet the organization’s risk, security, privacy, regulatory, and operational standards.
Key Responsibilities
- Conduct third-party risk assessments during vendor onboarding, renewal, and periodic review cycles.
- Evaluate vendor responses to due diligence questionnaires and validate supporting evidence such as SOC reports, ISO certifications, penetration test summaries, business continuity plans, and security policies.
- Assess risks across information security, data privacy, regulatory compliance, operational resilience, financial stability, and business continuity domains.
- Assign and maintain vendor risk ratings based on established risk assessment methodologies and control frameworks.
- Identify control gaps, document findings, and work with vendors and internal stakeholders to track remediation plans through closure.
- Support contract and agreement reviews by identifying risk-related requirements such as audit rights, breach notification timelines, data protection provisions, service levels, and subcontractor controls.
- Maintain accurate third-party inventory records, risk registers, assessment documentation, and audit-ready evidence.
- Prepare dashboards, scorecards, and reports on vendor risk posture, assessment status, open issues, and remediation progress.
- Monitor third-party risk signals, including vendor incidents, changes in services, subcontractor usage, regulatory issues, and control changes.
- Participate in internal audits, regulatory reviews, and governance meetings related to third-party risk management.
- Contribute to the continuous improvement of TPRM policies, procedures, templates, workflows, and reporting practices.
Skill Requirements
- Bachelor’s degree in Information Security, Risk Management, Business, Finance, Computer Science, or a related discipline.
- 5+ years of relevant experience in third-party risk management, vendor risk management, information security risk, compliance, procurement risk, audit, or operational risk.
- Working knowledge of vendor due diligence, risk assessment methods, control validation, issue tracking, and remediation management.
- Understanding of information security, privacy, and risk frameworks such as ISO 27001, NIST, SOC 1/SOC 2, PCI DSS, GDPR, or similar standards.
- Experience working with GRC or TPRM tools such as ServiceNow, Archer, OneTrust, LogicGate, ProcessUnity, or similar platforms is desirable.
- Strong analytical, documentation, communication, and stakeholder management skills.
- Ability to manage multiple assessments, prioritize tasks, and work independently in a deadline-driven environment.
Other Requirements
- Vendor risk assessment and due diligence
- Risk identification, analysis, scoring, and reporting
- Information security and data privacy awareness
- Third-party lifecycle management
- Stakeholder coordination and vendor communication
- Audit readiness and evidence management
- Remediation tracking and issue management
- Strong written and verbal communication
- Attention to detail and ability to translate technical risks into business impact
Success Measures
- Timely completion of vendor risk assessments within defined SLAs.
- Accurate vendor risk ratings and well-documented assessment outcomes.
- Effective tracking and closure of risk remediation actions.
- Improved visibility into third-party risk posture through clear reporting and dashboards.
- Strong collaboration with business, procurement, legal, compliance, information security, and vendor teams.