Senior TPRM Analyst

Evolution Cloud Services (EVOCS)

Denver (CO)

On-site

USD 130,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Evolution Cloud Services (EVOCS) is seeking a Senior TPRM Analyst to own complex third-party risk reviews across cloud providers, MSPs, and critical technology vendors. You will escalate findings and write executive-ready risk summaries for leadership reviews.

This senior individual contributor role emphasizes depth of judgment and strong collaboration with business, technology, and procurement stakeholders to manage risk in a dynamic environment.

Qualifications

  • 7+ years of experience in cybersecurity, risk, audit, or compliance.
  • At least 5 years in third-party risk management or vendor risk.
  • Fluency reading SOC 2 reports and ISO 27001 certifications, including scope carve-outs and control exceptions.
  • Experience writing executive-ready risk summaries and risk acceptance recommendations.

Responsibilities

  • Own end-to-end risk assessments for high-criticality third parties (cloud providers, MSPs, and critical vendors).
  • Read and interpret SOC 2 Type II and ISO 27001 reports beyond mere existence of documents.
  • Evaluate control evidence, remediation plans, and security questionnaires; challenge weak answers.
  • Set inherent and residual risk ratings; define compensating controls; track remediation.
  • Map fourth-party dependencies and assess concentration risk across vendors.
  • Present risk posture, trends, and exceptions to governance forums and senior leadership.
  • Mentor junior analysts on evidence review and stakeholder handling.

Skills

Vendor risk management
Cybersecurity
Risk assessment
Executive communication
Stakeholder management
SOC 2 & ISO 27001

Job description

EVOCS OVERVIEW

EVOCS was founded with a clear purpose: to help businesses operate more effectively, solve complex challenges, and create opportunities for growth through practical expertise and technology solutions.

As an IT consulting firm, we work with our clients to understand their needs, identify the right technologies, and deliver solutions that improve performance and support their business objectives.

Today, EVOCS is a trusted technology partner to a growing number of organizations and industry leaders. Our team combines technical expertise, business understanding, and a commitment to quality to deliver effective solutions and build lasting client relationships based on responsiveness, consistency, and results.

Senior TPRM Analyst

As a Senior TPRM Analyst, you are the experienced hand on the third-party risk team. You own the complex vendor reviews - the cloud providers, MSPs, and critical technology vendors where a shallow assessment creates real exposure - and you are the person escalations land on when a finding is contested or a risk needs to be accepted at the leadership level.

You are also the one who writes what goes up. Executive-ready risk summaries, escalation memos, and risk acceptance recommendations come from you, and they need to be right the first time. This is a senior individual contributor role: depth of judgment, not headcount, is what makes you effective here.

We are hiring two Senior TPRM Analysts.

What You Will Do
Vendor Risk Assessment and Due Diligence
  • Own end-to-end risk assessments for the highest-criticality third parties, including cloud service providers, managed service providers, and critical technology vendors
  • Read SOC 2 Type II reports and ISO 27001 certificates for what they actually say - scope carve-outs, excluded systems, qualified opinions, exceptions in the testing results, and complementary user entity controls - rather than confirming that a document exists
  • Evaluate control evidence, penetration test summaries, remediation plans, and security questionnaire responses, and challenge answers that do not hold up
  • Set inherent and residual risk ratings, define compensating controls, and track remediation commitments to closure
  • Assess vendor security posture in context: data classification, access model, integration depth, and business criticality
Fourth-Party and Supply Chain Analysis
  • Map fourth-party and subcontractor dependencies behind critical vendors, including where the work is actually performed
  • Analyze vendor concentration risk and identify single points of failure across the third-party portfolio
  • Assess geopolitical and jurisdictional exposure, including offshore delivery locations, data residency, and sub-processor chains
  • Incorporate security ratings and continuous monitoring signals into ongoing vendor risk views, and separate real signal from noise
Escalation, Reporting, and Governance
  • Serve as the escalation point for contested findings, vendor pushback, and time-pressured reviews tied to contract or go-live deadlines
  • Write executive-ready risk summaries that state the risk, the business impact, and the recommendation in language leadership can act on
  • Run risk acceptance conversations with senior business, technology, and procurement stakeholders - documenting the decision, the owner, and the expiration
  • Present third-party risk posture, trends, and exceptions to governance forums and senior leadership
  • Support and improve the TPRM program itself: assessment standards, tiering criteria, evidence requirements, and playbooks that raise the floor for the whole team
  • Mentor junior analysts on evidence review, write-up quality, and stakeholder handling
What You Will Bring

The top candidate will have the following qualifications:

  • 7+ years of experience in cybersecurity, risk, audit, or compliance
  • At least 5 of those years in third-party risk management or vendor risk specifically
  • Demonstrated experience assessing cloud providers, MSPs, and critical technology vendors - not only routine or low-criticality suppliers
  • Fluency reading SOC 2 reports and ISO 27001 certifications, including the ability to identify scope carve-outs, qualified opinions, and control exceptions
  • Fourth-party and supply chain risk analysis: vendor concentration, criticality tiering, geopolitical exposure, and subcontractor dependencies
  • Proven ability to write executive-ready risk summaries for senior audiences
  • Experience leading escalation and risk acceptance conversations with senior stakeholders, including holding a position under pressure
  • Working knowledge of common control frameworks - NIST CSF, NIST 800-53, ISO 27001/27002, CIS - and how they map to vendor assessments
  • Strong interpersonal and communication skills - this role involves frequent interaction with vendors and internal stakeholders via email, calls, and meetings
Key Skills and Competencies
  • Third-party and vendor risk assessment
  • Audit repor
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TPRM Analyst
TPRM Analyst

Evolution Cloud Services (EVOCS) • United States

On-site
USD 85,000 - 120,000
Senior Vendor Risk Analyst: TPRM Expert
Senior Vendor Risk Analyst: TPRM Expert

Evolution Cloud Services (EVOCS) • Denver (CO)

On-site
USD 130,000 - 170,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

Intercontinental Exchange Holdings, Inc. • Atlanta (GA)

On-site
USD 80,000 - 120,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE Clear Europe Limited • Northern (KY)

Hybrid
USD 90,000 - 120,000
Senior Vendor Risk & Compliance Analyst
Senior Vendor Risk & Compliance Analyst

Evolution Cloud Services (EVOCS) • United States

On-site
USD 85,000 - 120,000
Manager, Third Party Risk Management
Manager, Third Party Risk Management

CrowdStrike • United States

On-site
USD 130,000 - 150,000
Market leader in compensation and equity awards
Comprehensive wellness programs
Paid parental and adoption leaves
Vendor Infrastructure IT Risk Manager - Chief Risk Office
Vendor Infrastructure IT Risk Manager - Chief Risk Office

Selby Jennings • New York (NY)

On-site
Sr. Manager, Third Party Risk Management
Sr. Manager, Third Party Risk Management

Asurion • United States

On-site
USD 120,000 - 150,000
Legal - Contracts Manager - Junior
Legal - Contracts Manager - Junior

Spectraforce Technologies • Westlake (TX)

Hybrid
USD 120,000 - 150,000
Third-Party Risk Analyst
Third-Party Risk Analyst

OpenRouter • New York (NY)

On-site
USD 140,000 - 190,000