Senior Vendor Security Risk Analyst

Turo

San Francisco (CA)

Hybrid

USD 131,000 - 164,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive salary
Equity
Medical, dental, and vision insurance
Retirement employer match
Learning & Development stipend
In-office/hybrid schedule
Office lunch / snacks

Job summary

Turo is seeking a Senior Vendor Security Risk Analyst to own and scale our third-party risk management program within Enterprise Security. You will manage the vendor review lifecycle, evaluate evidence such as SOC 2 reports and pen tests, and coordinate with Legal and Procurement on contracting from a security perspective.

The role requires hands-on experience with AWS cloud security, IAM, and data protection principles, plus strong communication skills to translate risk for non-technical

Qualifications

  • 5+ years in third-party risk management or GRC with vendor security ownership.
  • Experience evaluating SOC 2, ISO reports, and pen-test results.
  • Knowledge of DPAs & MSAs from a security perspective and collaboration with Legal/Procurement.
  • Experience with TPRM tooling and security-automation platforms.

Responsibilities

  • Own the vendor security review lifecycle from intake to renewals.
  • Evaluate vendor evidence and translate findings into risk recommendations.
  • Review contracts, DPAs, and MSAs for security protections and approvals.
  • Build scalable tiering frameworks and ongoing monitoring for vendor risk.
  • Partner with Procurement, Legal, and Privacy to integrate security reviews into onboarding and renewals.
  • Develop and deliver security awareness training including phishing simulations.
  • Lead quarterly user access review campaigns and certify access decisions.

Skills

Vendor security risk management
SOC 2 / ISO evidence evaluation
Penetration testing results
Cloud security (AWS)
IAM and data protection
Contract review security perspective
Clear risk communication

Education

Bachelor's degree in Computer Science or Information Security

Tools

Vanta
Drata
ZenGRC

Job description

# **About the team**Turo is searching for a highly motivated and versatile Senior Vendor Security Risk Analyst under the Enterprise Security team to own Turo's third-party security risk management (TPRM) program and partners with Security teammates to lead security awareness training and user access review campaigns. You will assess and manage vendor risk end-to-end, build scalable review processes, and help strengthen Turo's security culture. You will operate with significant autonomy across Procurement, Legal, Privacy, IT, and the business.# **What you will do*** Own the vendor security review lifecycle: intake, risk tiering, due diligence, findings documentation, remediation tracking, and renewals.* Evaluate vendor evidence: SOC 2 reports, ISO certificates, pen-test results, and security questionnaires - deliver clear risk recommendations.* Review vendor contracts, DPAs, and MSAs from a security standpoint; provide approval recommendations before contracts are signed.* Build scalable tiering frameworks, intake workflows, and continuous monitoring capabilities that grow with vendor volume.* Partner with Procurement, Legal, and Privacy to integrate security review into onboarding and renewal cycles without becoming a bottleneck.* Complete and maintain external partnership-facing security questionnaires and trust-center content in support of integrations.* Partner with Security team members to design and deliver security awareness training programs, including role-specific content on phishing, social engineering, third-party risk, and data handling.* Track training completion and effectiveness; align program content with TPRM findings and emerging threats.* Partner with IT and Security teams to design and run quarterly user access review campaigns, ensuring timely completion, accurate certification decisions, and clear remediation of access exceptions.* Report on TPRM, training, and access review metrics to security leadership: cycle time, open findings, remediation aging, and completion rates.# **Your profile*** 5+ years in third-party risk management, vendor security, or GRC, with direct ownership of vendor security review programs.* Hands-on experience evaluating SOC 2 reports, ISO certificates, and penetration test results, and translating findings into business-ready risk recommendations.* Familiarity with contract review from a security perspective (e.g., DPAs & MSA) and comfort working with Legal and Procurement.* Working knowledge of cloud security (AWS), IAM, and data-protection principles.* Strong communicator: able to distill complex risk findings for non-technical stakeholders at all levels.* Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience.* Relevant certification: CISA, CISM, CISSP, or equivalent security certification.* Experience with TPRM or GRC tooling (e.g., Vanta, Drata, ZenGRC) and security-automation platforms.* Experience developing or delivering security awareness training, including content creation or phishing simulation.* Background in a regulated or high-trust industry - fintech, marketplace, or SaaS handling sensitive data.For this role, the target base salary range in San Francisco is $131,000-$164,000 annually. This role is also eligible for equity and benefits. In general, our ranges reflect the market-based target for new hire salaries based on the level and location of the role. Within the range, individual pay is determined by objective factors assessed during the application and interview process, such as job-related skills, experience, and relevant education or training. We encourage you to talk with your recruiter to learn more about the total compensation and benefits available for this role.***Turo highly values having employees working in-office to foster a collaborative work environment and company culture. This is central to how we work, and this role will be subject to our current in-office hybrid schedule that requires Turists to work in the office three days per week on Mondays, Wednesdays, and Thursdays. We expect that employees will meet these required in-office days consistently as part of their role. Your recruiter can share more information about this requirement and the in-office perks Turo offers.***# **Turo Recruiting Scam Alert:***We've learned that there are scammers targeting job candidates by impersonating Turo and its employees. We ask candidates to be careful of fraudulent job postings or suspicious recruiting activity during their job search, especially if they're contacted through unofficial channels (such as Instagram, Telegram, MS Teams, etc.). In general, Turo interacts with candidates through our* *and via turo.com email addresses, and we don't ask candidates for sensitive financial or personal info or request money as part of the hiring process (so an application fee or equipment costs).* *If candidates are not sure whether they're dealing with an impersonator, they can contact Turo's Recruiting Team at* *recruit@turo.com*. *Candidates can also report suspicious activity to the* *or other appropriate authorities.*# **Turo AI Policy:**Turo may use AI-enabled tools to support our recruiting operations, including gathering information from candidates, drafting communications, helping with interview note-taking and assessment, and so on. These tools only supplement our team; all decisions to advance or hire candidates are made by Turo employees. While we welcome candidates to use AI-enabled tools to help prepare for their interviews, the use of such tools, including any AI chatbots or note-takers, is not permitted during live interviews or technical assessments. We want to see how you consider and solve problems in real-time, so interviews and assessments are all you (unless we indicate otherwise and ask you specifically to use an AI-enabled tool to answer a question). If during the application process you require the use of an AI-enabled tool as a reasonable accommodation for a disability, please let us know at PeopleOps@turo.com.## **Benefits*** Competitive salary, equity, benefits, and perks for all full-time employees* Employer-paid medical, dental, and vision insurance (Country specific)* Retirement employer match* Learning & Development stipend to invest in your professional development* Turo host matching program* Turo travel credit* Cell phone and internet stipend* Paid time off to relax and recharge* Paid holidays, volunteer time off, and parental leave* For those who are in the office full-time or hybrid we have in-office lunch, office snacks, and fun activitiesWe are committed to building a diverse team. If you are from a background that's underrepresented in tech, we'd love to meet you.Aside from an award winning work environment and the opportunity to be part of the world's largest car sharing marketplace, we are also growing the team quickly - join us! Even if you don't meet every qualification, we are looking for people with enthusiasm for what we do and we will consider you for this and other possibilities.# ****About Turo****Turo is the world's largest car sharing marketplace where you can book the perfect car for wherever you're going from a vibrant community of trusted hosts across the US, UK, Canada, Australia, and France. Whether you're flying in from afar or looking for a car down the street, searching for a rugged truck or something smooth and swanky, Turo puts you in the driver's seat of an extraordinary selection of cars shared by local hosts.Discover Turo at, the App Store, and Google Play, and check out our blog,.about the Turo culture according to Turo CEO, Andre Haddad.Turo is an Equal Opportunity Employer and a participant in the U.S. Federal E-Verify program. Women, minorities, individuals with disabilities and protected veterans are encouraged to apply. We welcome people of different backgrounds, experiences,
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

Turo • San Francisco (CA)

Hybrid
USD 131,000 - 164,000
Equity
In-office lunch
Office snacks
+4
Senior Software Engineer, Android
Senior Software Engineer, Android

Turo • San Francisco (CA)

Hybrid
USD 156,000 - 195,000
Equity
Medical, dental, vision insurance
Retirement match
+1
Senior Security Engineer, Enterprise Security
Senior Security Engineer, Enterprise Security

Turo Inc • San Francisco (CA)

On-site
USD 148,000 - 185,000
Employer-paid medical, dental, and vision insurance
Retirement employer match
Learning & Development stipend
+6
Lead Product Manager, Host Pricing
Lead Product Manager, Host Pricing

Turo • San Francisco (CA), Northern (KY)

Hybrid
USD 174,000 - 218,000
Equity
Hybrid work schedule (3 days in office
Travel credit
+2
Senior Software Engineer, Frontend, Design Systems
Senior Software Engineer, Frontend, Design Systems

Turo • San Francisco (CA), Northern (KY)

Hybrid
USD 156,000 - 195,000
Senior Vendor Security Risk Analyst
Senior Vendor Security Risk Analyst

Turo Inc. • San Francisco (CA)

Hybrid
USD 131,000 - 164,000
Employer-paid medical/dental/vision
401(k) match
Learning & Development stipend
+6
Senior Director, Fraud Prevention
Senior Director, Fraud Prevention

Turo, Inc. • Phoenix (AZ), Northern (KY)

On-site
USD 180,000 - 220,000
Competitive salary
Equity and benefits
Hybrid in-office schedule (Phoenix)
+1
Director, Liability
Director, Liability

Turo, Inc. • Phoenix (AZ), Northern (KY)

On-site
USD 160,000 - 185,000
Competitive salary
Equity
Benefits
+2
Senior Security GRC Analyst
Senior Security GRC Analyst

Turo Inc. • San Francisco (CA)

Hybrid
USD 131,000 - 164,000
Competitive salary and equity
Medical, dental, vision insurance
Retirement match
+5
Staff Data Engineer, Data Platform
Staff Data Engineer, Data Platform

Turo • San Francisco (CA), Northern (KY)

Hybrid
USD 182,000 - 228,000
Equity
Medical insurance
Hybrid work schedule
+5