Source Job

  • Conduct vendor risk reviews and evaluate third-party attestations.
  • Analyze vendor contracts and identify potential risk clauses.
  • Support annual high-risk vendor audits and maintain documentation.

Information Security SOC 2 NIST

20 jobs similar to Sr. TPRM Analyst

Jobs ranked by similarity.

Global

  • Manage a worldwide portfolio of vendor assessments using a defined methodology.
  • Assess responses to Information Security controls and identify risks.
  • Liaise with stakeholders to ensure appropriate escalation and timely remediation.

TELUS Agriculture & Consumer Goods tackles the challenge of efficient production with lower environmental impact. They deliver data insights and technology solutions connecting producers to consumers, improving the quality, safety and sustainability of food and consumer goods globally.

Europe US

  • Collaborate with cross-functional teams to maintain and improve the company's comprehensive compliance program.
  • Manage the end-to-end audit process for SOC 2 compliance, ensuring timely and accurate completion.
  • Oversee the Information Security Risk Management Program, documenting identified risks, coordinating mitigation efforts.

airSlate is a global SaaS technology company that develops no-code workflow automation, electronic signature, and document management solutions. They have teammates in more than 20 countries across three continents and main hubs in the United States, Poland, Romania, Ukraine and Philippines.

Canada

  • Lead comprehensive security audits of client security operations programs.
  • Analyze security monitoring and alerting to perform a gap analysis.
  • Conduct cyber risk assessments using industry frameworks.

They build cybersecurity software and solutions. Palo Alto Networks challenges the status quo, and they are looking for innovators who are as committed to shaping the future of cybersecurity as they are.

Europe

  • Refine existing regulatory compliance programs related to third party suppliers.
  • Oversee due diligence and performance monitoring activities for regulatory compliance.
  • Act as a subject matter expert for audit and exam requests.

Jobgether helps partner companies to find the right candidate. They use an AI-powered matching process to ensure applications are reviewed quickly, objectively, and fairly against the role's core requirements.

$108,890–$184,028/yr
US

  • Own the end-to-end process for client and prospect security questionnaires.
  • Collaborate with internal stakeholders, managing timelines to ensure accurate responses.
  • Develop and maintain a "Trust Center" to proactively address common security questions.

Included Health is a healthcare company that delivers integrated virtual care and navigation. They aim to break down barriers to provide high-quality care for every person, offering care guidance, advocacy, and access to personalized virtual and in-person care.

US

  • Collaborate with business leadership, Legal, Procurement, and Cyber to review terms and conditions.
  • Track status of risk remediations in the risk register with business stakeholders.
  • Contribute to overall program enhancements and drive automation with various IT and Cybersecurity stakeholders.

NBCUniversal is a leading media and entertainment company that creates world-class content across film, television, and streaming. They own and operate entertainment and news brands, with a focus on improving communities, championing an inclusive culture, and attracting a talented workforce.

$93,500–$126,500/yr
US Unlimited PTO

  • Monitor SIEM alerts, triage incidents, and escalate as needed to ensure timely resolution
  • Conduct third-party and supply chain risk management reviews, including audit report analysis
  • Collaborate with engineering, IT, and operations teams to integrate and maintain security controls

Jobgether uses an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. It identifies top-fitting candidates and shares this shortlist with the hiring company.

$117,763–$147,204/yr
Canada

  • Lead, mentor, and grow a team of international and domestic risk analysts.
  • Conduct and oversee complex risk assessments across cloud environments and on-premise telecommunications systems.
  • Develop and deliver high-impact, executive-level risk reporting.

At Twilio, they're shaping the future of communications. They deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences, with a strong culture of connection and global inclusion.

Global

  • Own and lead incident response process and actively investigate events.
  • Prioritize alerts based on risk and collaborate with stakeholders for remediation.
  • Design, implement, and maintain comprehensive security dashboards and generate periodic reports.

Deel is the all-in-one payroll and HR platform for global teams with a vision to unlock global opportunity for every person, team, and business. As one of the largest globally distributed companies, Deel's team of 7,000 spans more than 100 countries and speaks 74 languages.

US Unlimited PTO

  • Deliver world-class cyber security assessment and advisory services across multiple Compliance offerings.
  • Work effectively as a team member on large engagements and remain current on technical knowledge.
  • Demonstrate GuidePoint’s Core Values at all times and achieve and maintain relevant cyber security and audit certifications.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. Since its inception in 2011, GuidePoint has grown to over 1000 employees and firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere.

Europe

  • Acting as the primary subject matter expert for all security and compliance inquiries.
  • Taking end-to-end ownership of certification lifecycles, such as ISO 27001 and Cyber Essentials.
  • Working closely with the GRC team to improve existing programs.

Sword Health is shifting healthcare from human-first to AI-first through its AI Care platform, making world-class healthcare available anytime, anywhere. They have over 1,000 enterprise clients and are backed by 42 clinical studies and over 44 patents.

5w PTO

  • Own our information security strategy and build our security roadmap.
  • Maintain our ISO 27001 certification, preparing for SOC 2 readiness.
  • Operate strategically and tactically, developing policy and reviewing cloud configurations.

ApprovalMax is redefining how finance teams manage the Money Out cycle — from purchase orders and supplier bills to employee expense management and payroll. Trusted by 18,000+ businesses worldwide, our platform empowers companies to automate financial controls, ensure compliance, and scale efficiently.

$126,480–$175,000/yr
US

  • Lead the configuration and management of GRC tools to ensure integration with security systems.
  • Manage the main dashboard for SOC 2 reporting, ensuring accuracy and compliance.
  • Develop and maintain a comprehensive risk management program and conduct risk assessments.

Engine is transforming business travel into something personalized, rewarding, and simple. They have over 20,000 companies relying on Engine to support over 1 million travelers and billions in annual bookings each year and have been recognized as one of the fastest-growing travel and fintech platforms in North America.

US

  • Performs analysis of Alliance information security practices.
  • Identifies, investigates, and resolves security breaches.
  • Leads and performs staff training on information security.

Central California Alliance for Health (the Alliance) is an award-winning regional Medi-Cal managed care plan that provides health insurance for children, adults, seniors and people with disabilities. They currently serve more than 418,000 members with over 500 employees.

Europe

  • Maintain and improve security policies and controls across the platform.
  • Perform compliance validation and prepare for audits.
  • Conduct risk assessments on new workloads and track mitigation actions.

Jobgether is a platform that connects job seekers with companies. They use AI to match candidates with roles and ensure fair application reviews.

Global

  • Maintain and improve security policies and controls across the platform.
  • Perform compliance validation and prepare for audits.
  • Conduct risk assessments on new workloads and track mitigation actions.

Jobgether is a platform that connects job seekers with companies. They appear to value teamwork and innovation, and invest in employee growth.

Global

  • Maintain and improve security policies and controls across the platform.
  • Perform compliance validation and prepare for audits.
  • Conduct risk assessments on new workloads and track mitigation actions.

Jobgether is a platform that connects job seekers with companies. They use AI-powered matching to ensure applications are reviewed quickly and fairly. We do not have enough information to assess the company size and culture.

US

  • Play a critical role in the technical development, implementation, and maintenance of the GRC platform.
  • Drive integration strategies between GRC platforms and enterprise systems for automated data sharing and reporting.
  • Provide expert guidance and leadership on GRC technical matters to senior leadership and business stakeholders.

Jobgether is a platform helping candidates find jobs. They use AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements.

US

  • Own vulnerability management, SIEM tuning and monitoring, incident response, and threat investigation.
  • Maintain secure baseline configurations based on industry standards.
  • Oversee AWS security controls and enforce cloud security guardrails.

Jobgether posts this position on behalf of a partner company. They use an AI-powered matching process to ensure applications are reviewed quickly and fairly.

US

  • Drive execution of complex technical programs at the intersection of Security, Engineering, and Compliance.
  • Translate complex technical initiatives into clear programs that meet security and regulatory obligations.
  • Influence security strategy and drive alignment across Engineering, Compliance, and People Ops.

Rula is dedicated to treating the whole person and creating a world where mental health is embraced. They are a remote-first company that strives to be a force for positive change in the field of mental healthcare and hire in most U.S. states.