Third-Party Risk Analyst

Posted yesterday

virtual vocationsDenver (CO)
Compliance ManagersOther Management Consulting Services

SENIORITY

Senior

Apply

About the role

Building the vendor risk function from the ground up, the full-time Third-Party Risk Analyst will manage end-to-end security assessments for model providers and subprocessors, ensuring compliance with evolving regulations in a remote setting. Key responsibilities Own and execute security assessments for vendors, facilitating timely onboarding without bottlenecks Design and implement the Third-Party Risk Management (TPRM) program, including intake processes, tiering, and risk acceptance Continuously monitor critical vendors and conduct annual reviews to ensure compliance with relevant regulations Required qualifications 4+ years of experience in third-party/vendor security risk or security assessment Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, along with knowledge of the EU AI Act Technical literacy in cloud architecture, access models, and data flows Experience with Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs) Strong writing skills and ability to navigate ambiguity in regulatory environments

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this

Third-Party Risk Analyst Jobs at virtual vocations | David Careers