Fractional SCRM Analyst: ISO 27001 Vendor Risk

Gofractional

Austin (TX)

Hybrid

USD 90,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Crux Security is seeking a self-directed Supply Chain Analyst to stand up a SCRM program for a client engagement in Austin, TX. This contract/fractional role will drive vendor risk tiering, SOC 2 and ISO 27001 review processes, and an audit-ready evidence package with formal procedures.

You will build a supplier register from scratch, design tiering criteria, and coordinate with Legal and Procurement to ensure security clauses and a SaaS procurement checklist are operable and auditable for

Qualifications

  • Demonstrated experience designing or applying a vendor risk tiering methodology
  • Experience drafting or revising security contract clauses / annexes, ideally in coordination with Legal
  • Experience reviewing SOC 2 reports and ISO 27001 certifications from a vendor risk perspective
  • Experience designing procurement-stage security checklists or vendor questionnaires for SaaS
  • Comfortable coordinating directly with Procurement and Legal stakeholders
  • Experience building supplier inventories or risk registers
  • Working knowledge of ISO 27001:2022 evidence requirements and audit expectations
  • Able to work independently against a defined scope with minimal supervision, escalating judgment calls rather than routine questions
  • Strong written communication; proficiency producing audit-ready documentation with limited rework
  • Must pass a background check and comply with client security policies

Responsibilities

  • Build a supplier register from scratch and consolidate sources into a single, structured artifact
  • Design and apply a vendor risk tiering methodology
  • Review and update security contract clauses alongside Legal
  • Stand up a SOC 2 / ISO 27001 certification review process for critical vendors
  • Design a SaaS procurement security checklist
  • Coordinate with Procurement and Legal throughout checklist design
  • Produce an audit-ready evidence package mapped to ISO controls
  • Document operational procedures and develop a handoff plan to Procurement as long-term owner

Skills

Vendor risk tiering
SOC 2 awareness
ISO 27001 familiarity
Procurement security
Contract clauses drafting
Cross-functional collaboration
Audit readiness documentation

Job description

Crux Security is seeking a self-directed Supply Chain Analyst to stand up a SCRM program for a client engagement in Austin, TX. This contract/fractional role will drive vendor risk tiering, SOC 2 and ISO 27001 review processes, and an audit-ready evidence package with formal procedures.

You will build a supplier register from scratch, design tiering criteria, and coordinate with Legal and Procurement to ensure security clauses and a SaaS procurement checklist are operable and auditable for

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid SCRM Analyst: Vendor Risk & ISO 27001
Hybrid SCRM Analyst: Vendor Risk & ISO 27001

Crux Security • Austin (TX)

Hybrid
USD 90,000 - 130,000
Fractional Supply Chain Analyst
Fractional Supply Chain Analyst

Gofractional • Austin (TX)

Hybrid
USD 90,000 - 130,000
Supply Chain Analyst (Vendor & Supply Chain Risk)
Supply Chain Analyst (Vendor & Supply Chain Risk)

Crux Security • Austin (TX)

Hybrid
USD 90,000 - 130,000
Remote SCRM Analyst — Enterprise Vendor Risk & Security
Remote SCRM Analyst — Enterprise Vendor Risk & Security

Leidos Inc • Reston (VA)

On-site
USD 92,000 - 167,000
Senior SCRM Analyst: Enterprise Vendor Risk & Security
Senior SCRM Analyst: Enterprise Vendor Risk & Security

Leidos • Washington

On-site
USD 116,000 - 211,000
Senior Supply Chain Risk Analyst - SCRM & Vendor Risk
Senior Supply Chain Risk Analyst - SCRM & Vendor Risk

Leidos • Washington

On-site
USD 116,000 - 211,000
Senior SCRM Lead: Enterprise Risk & Procurement Strategy
Senior SCRM Lead: Enterprise Risk & Procurement Strategy

Koitecc Solutions • Washington

On-site
USD 116,000 - 210,000
Senior SCRM Analyst: Enterprise Vendor Risk Lead
Senior SCRM Analyst: Enterprise Vendor Risk Lead

Via Logic LLC • Washington

On-site
USD 116,000 - 210,000
Remote Supply Chain Risk Analyst (SCRM)
Remote Supply Chain Risk Analyst (SCRM)

Leidos Inc • United States

On-site
USD 92,000 - 167,000
Remote C-SCRM & Post-Quantum Crypto SME
Remote C-SCRM & Post-Quantum Crypto SME

Navanti Group • Arlington (VA)

On-site
USD 120,000 - 190,000