GRC TPRM Assessment and Remediation SME

Programmers.io

Austin (TX)

Remote

USD 120,000 - 160,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Programmers.io seeks an experienced Third-Party Risk Management (TPRM) Assessment and Remediation SME to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation in a fully remote, client-facing environment.

This role requires precise, proactive communication to maintain trust with high-visibility stakeholders, serving as the process authority for risk assessments, findings, and remediation across Legal, Procurement, and InfoSec teams.

Qualifications

  • 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
  • Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
  • Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
  • Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
  • Excellent written communication for remote, client-facing engagement.
  • Experience operating in distributed/remote teams.

Responsibilities

  • Supplier Inventory Management: maintain the Supplier Inventory as the single source of truth for assessment status.
  • Assessment Execution: evaluate suppliers against standard frameworks and validate evidence.
  • Remediation Management: own CAPs end-to-end and track progress with vendors.

Skills

Cybersecurity
TPRM
GRC operations
Supplier risk coordination
Stakeholder communication
Remote work coordination

Education

CTPRP
CRISC
CISA
CISSP
Certifications

Tools

OneTrust
Archer
ServiceNow GRC
SupplierNinja
Wrike
AirTable
Jira

Job description

Job Description:
  • We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation - from inventory governance through assessment coordination, escalation management, and executive reporting - in a fully remote, client-facing environment.
  • This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.
Key Responsibilities
  • Supplier Inventory Management:
    • Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
    • Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
    • Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).
  • Assessment Execution:
    • Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
    • Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
    • Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
    • Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
    • Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
  • Remediation Management:
    • Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
    • Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
  • Stakeholder Communication & Escalation:
    • Run a structured outreach cadence with DRIs (kick-off 3 follow-ups 3 escalations to management).
    • Track response/non-response rates for every outreach cycle.
    • Escalate unresolved/high-risk findings to client leadership and track to closure.
  • Weekly Reporting:
    • Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.
Required Qualifications:
  • 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
  • Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
  • Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
  • Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
  • Excellent written communication for remote, client-facing engagement.
  • Experience operating in distributed/remote teams.
Preferred Qualifications
  • Certification: CTPRP, CRISC, CISA, or CISSP.
  • Experience with Wrike, AirTable, Jira, or similar tracking tools.
  • Prior experience in regulated industries (financial services, healthcare, insurance).
  • Track record producing leadership-facing weekly reporting.
  • Experience Required: 8-10
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

W2/ Subject Matter Expert
W2/ Subject Matter Expert

VensIT Corp • United States

Remote
USD 120,000 - 180,000
Remote TPRM Assessment & Remediation Lead
Remote TPRM Assessment & Remediation Lead

Programmers.io • Austin (TX)

Remote
USD 120,000 - 160,000
Information Technology Security Manager
Information Technology Security Manager

Meet Life Sciences • Princeton (NJ)

Hybrid
USD 124,000 - 165,000
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
GRC Analyst
GRC Analyst

Golden Technology • North Carolina

On-site
USD 120,000 - 160,000
Remote TPRM Assessment & Remediation Lead
Remote TPRM Assessment & Remediation Lead

VensIT Corp • United States

Remote
USD 120,000 - 180,000
Remote TPRM Risk Assessment & Remediation Lead
Remote TPRM Risk Assessment & Remediation Lead

Tata Consultancy Services • Sunnyvale (CA)

On-site
USD 80,000 - 140,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

Automotivemastermind • Centreville (VA)

On-site
USD 70,000 - 90,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

Mobility Global • Centreville (VA)

On-site
USD 70,000 - 100,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000