Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
An established industry player is seeking a Security Assurance Analyst to lead Third Party Risk Management and Supply Chain security assessments. This pivotal role involves evaluating vendor security postures, identifying control gaps, and ensuring compliance with regulatory frameworks. You will contribute to security initiatives, perform audits, and enhance the organization's resilience against supply chain risks. Join a dynamic team where your expertise in security assurance will help safeguard critical business operations, and enjoy a collaborative environment that champions professional growth and development.
Job DescriptionJob Description
Job Summary
The Security Assurance Analyst-TPRM will be responsible for leading, processing, and executing Third Party Risk Management (TPRM) and Supply Chain security assessments on prospective and existing vendors. This encompasses identifying and tracking remediation action plans, performing remote investigative questioning or audits, and in-person on-site security reviews (at the vendor location). This role plays a key part in protecting the organization from supply chain risks by evaluating vendor security postures, identifying control gaps, and ensuring compliance with regulatory and industry frameworks.
Additionally, you will contribute to the testing and validation of security and IT controls, support internal security assurance initiatives, and assist in compliance activities related to SOC 2, ISO 27001, NIST, or other applicable frameworks and industry best practices.
This role participates in and/or conducts the following, among other duties: raises the level of security awareness among employees and about vendor integration risks, does individual user and group trainings on the vendor relationship owner duties, issues and evaluates security questionnaires to third parties, reviews external vulnerability testing including audit reports and auditor assessments, assists with creating or updating security policies, other internal and external auditor activities, raises internal documentation standards, and moves the organization toward mitigation of information security risks.
* Applicants must be legally eligible to work in the United States to be considered. Visa sponsorship is not available for this role *
Essential Duties and Responsibilities
Third Party Security Risk Management:
Security Assurance & Compliance Testing:
Supply Chain Risk Assessments:
Collaboration & Reporting:
Travel Requirements: Less than 25%
Supervisory Responsibility
This position has no direct supervisory responsibilities but does serve as a coach and mentor for other positions in the department.
Education
4 Year / Bachelors Degree in a related field
Minimum Certification: One or more of the following Certifications: CISSP, CRISC, CISA, CISM or other equivalents
Certification: One or more of the following Certifications: CSCP or CRISC
Experience
3 years Experience in 3rd party risk management, vendor security assessments, and supply chain risk evaluations including both physical and cyber risks.
2 years Experience in IT security assurance, auditing, and controls testing, and supply chain operations, logistics, and procurement processes.
Knowledge, Skills, and Abilities
Working Conditions and Physical Requirements
• Able to sit, stand, and type for a long period of time in an office environment using computer equipment.
• Dexterity of hands and fingers to operate a computer keyboard, mouse, webcam, tools, and to handle other computer components.
• Employee must have a reliable source of internet service when not on-site.
• Local personnel are currently required to work part of the week in the office.
• On-video attendance is expected for most meetings.
Benefits
Pay Range: Actual pay may vary up or down depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for incentive compensation.
Company Summary
Our Mission…Harnessing the power of , we connect diverse people and enrich the human experience.
Our Vision…To provide global services that expand opportunities, nurture belonging, and empower the world to connect beyond words.
As one of the world’s leading services providers, Sorenson combines patented technology with human-centric solutions. We strive to increase , equity, , and accessibility for underrepresented people through communication solutions for all: call captioning and video relay services, over-video and in-person sign and spoken interpreting, translation, real-time captioning, and post-production services.
Sorenson’s impact vision and plan extends to supporting employment opportunities for diverse employees, customers, and communities. As a minority-owned company, we are committed to expanding opportunities for underserved communities while promoting an inclusive workplace for our own employees.
Equal Employment Opportunity:
Sorenson Communications is an Equal Opportunity, Affirmative Action Employer.