Third-Party Risk Analyst
Posted yesterday
virtual vocationsDenver (CO)
Compliance ManagersOther Management Consulting Services
SENIORITY
Senior
About the role
Building the vendor risk function from the ground up, the full-time Third-Party Risk Analyst will manage end-to-end security assessments for model providers and subprocessors, ensuring compliance with evolving regulations in a remote setting.
Key responsibilities
Own and execute security assessments for vendors, facilitating timely onboarding without bottlenecks
Design and implement the Third-Party Risk Management (TPRM) program, including intake processes, tiering, and risk acceptance
Continuously monitor critical vendors and conduct annual reviews to ensure compliance with relevant regulations
Required qualifications
4+ years of experience in third-party/vendor security risk or security assessment
Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, along with knowledge of the EU AI Act
Technical literacy in cloud architecture, access models, and data flows
Experience with Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs)
Strong writing skills and ability to navigate ambiguity in regulatory environments
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
