Sr. TPRM Security Analyst

Claritev

United States

On-site

USD 135,000 - 145,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) with company match
Paid time off
Bonus opportunity
Professional development

Job summary

Claritev in the United States seeks a seasoned Third-Party Risk Management professional to support leadership in driving vendor risk assessments, onboarding, due diligence, ongoing monitoring, and deficiency management across complex environments.

You will collaborate with Procurement, Legal, Compliance, Privacy, IT and business teams to mature risk evaluation methodologies, enhance automation, and deliver actionable risk reporting with audit readiness. 5+ years in cybersecurity GRC required.

Qualifications

  • At least 5+ years' experience in cybersecurity or information security GRC.
  • Ability to interpret system architecture, data flows, and cloud/on-prem designs.
  • Experience with vendor risk assessments and third-party governance.
  • Familiarity with Onspring, Archer, LogicGate or similar GRC tools.

Responsibilities

  • Serve as SME for third-party risk management and security governance throughout the vendor lifecycle.
  • Collaborate with stakeholders to mature the TPRM program and dashboards.
  • Execute and improve core TPRM workflows, risk assessments, evidence collection, and remediation tracking.
  • Review vendor security artifacts such as SOC reports and questionnaires to assess risk.
  • Produce metrics and reports on third-party risk exposure and program effectiveness.

Skills

Third-party risk
Vendor risk assessments
GRC programs
Security governance
Cloud security
Audit support
Stakeholder collaboration

Tools

Onspring
Archer
LogicGate

Job description

Job Description
JOB SUMMARY

This role will support leadership in the Third-Party Risk Management (TPRM) aspects of Claritev’s GRC program, with emphasis on vendor security risk assessments, vendor onboarding and due diligence, ongoing monitoring, deficiency management, and third-party risk reporting. Working closely with Procurement, Legal, Compliance, Privacy, IT, and business stakeholders, this position will be responsible for executing and maturing core TPRM processes, improving the scalability and consistency of vendor risk evaluations, and strengthening the organization’s ability to identify, assess, treat, and monitor risks introduced by third-party relationships. This role requires the ability to engage in deep technical discussions with vendors and internal engineering teams, including evaluation of system architecture, data flows, and control implementations within complex environments.

Job Roles And Responsibilities
  • Serve as a trusted advisor and subject matter expert, providing third-party risk management and security governance support to Procurement, IT, and business stakeholders throughout the vendor lifecycle.
  • Support the GRC leader in executing strategy and multi-year roadmaps to mature Claritev’s TPRM program.
  • Collaborate with security, IT, procurement, privacy, legal, compliance, and business stakeholders to develop standards and processes that protect the confidentiality, integrity, and availability of Claritev data in third-party environments.
  • Own and execute core TPRM workflows and tooling, including vendor intake and risk tiering, security risk assessment (SRA) scoping, evidence collection, assessment execution, deficiency tracking, risk acceptance, and risk escalation processes.
  • Conduct in-depth security risk assessments of third-party vendors, including evaluation of system architectures, data flows, authentication mechanisms, encryption implementations, network segmentation, and cloud security controls.
  • Lead technical discussions with vendor engineering and security teams to validate architectural design, control effectiveness, and alignment with Claritev security requirements.
  • Review and analyze vendor-provided documentation, including SOC reports, penetration test results, security policies, and completed questionnaires, to assess inherent and residual risk.
  • Identify control gaps and deficiencies, document findings, and coordinate remediation activities or risk acceptance decisions with business stakeholders.
  • Track and manage third-party remediation plans through closure, ensuring timely follow-up, appropriate documentation, and audit readiness.
  • Support ongoing monitoring of third-party risk, including reassessments, periodic reviews, and integration of continuous monitoring tools and threat intelligence sources.
  • Build and maintain consistent assessment methodologies and templates to improve efficiency, quality, and defensibility of vendor risk evaluations.
  • Assist with audits and reviews of TPRM processes to evaluate control effectiveness, document findings, and track remediation activities through closure.
  • Develop and maintain metrics, reporting, and dashboards that communicate third-party risk exposure, assessment volume, deficiency trends, SLA performance, and program effectiveness.
  • Coordinate with the Risk Management team to ensure material third-party risks are escalated into the enterprise risk register and reporting framework.
  • Partner with Procurement to ensure alignment between vendor onboarding workflows and TPRM requirements, including integration with procurement systems and contract lifecycle events.
  • Continuously identify opportunities to improve TPRM processes, automation, and tooling within platforms such as Onspring.
  • Collaborate, coordinate, and communicate effectively across disciplines and departments, and demonstrate the Company’s Core Competencies and values held within.
  • The position responsibilities outlined above are in no way to be construed as all encompassing. Other duties, responsibilities, and qualifications may be required and/or assigned as necessary.
REQUIREMENTS (Education, Experience, And Training)
  • At least 5+ years' experience directly in cybersecurity or information security GRC, with a demonstrated track record of leading complex projects in at least two of the following areas: third-party risk management, vendor risk assessments, compliance operations, control assurance, or audit support.
  • Strong technical background is required, with the ability to interpret and evaluate system architecture diagrams, application data flows, and infrastructure designs across cloud and on-prem environments.
  • Hands‑on or practical experience in one or more technical domains such as cloud engineering, network security, application security, or systems engineering.
  • Demonstrated ability to engage in detailed technical discussions with engineers and architects regarding control implementation and security design decisions.
  • Strong working knowledge of cloud architectures (e.g., AWS, Azure), including identity models, network design, data protection mechanisms, and shared responsibility considerations.
  • Demonstrated experience conducting risk, security, or governance assessments of AI/Generative AI technologies and vendors, including evaluation of data privacy, model security, and responsible AI controls.
  • A deep understanding of third‑party risk assessment methodologies and frameworks, including NIST CSF, HITRUST, HIPAA, SOC 2, ISO 27001, and related security and privacy requirements.
  • Strong knowledge and experience with the TPRM lifecycle, including vendor intake, tiering, due diligence, risk assessment execution, deficiency management, remediation tracking, and ongoing monitoring.
  • Experience reviewing and interpreting vendor security artifacts such as SOC reports, penetration tests, security policies, and questionnaire responses.
  • Experience building and maintaining TPRM reporting, dashboards, and program metrics that support executive‑level decision‑making.
  • Strong knowledge of control frameworks, risk identification and assessment techniques, and remediation tracking processes as applied to third‑party environments.
  • Functional knowledge of information security domains, industry standards, and best practices, along with the ability to identify and recommend process improvements and automation opportunities.
  • Previous experience with GRC solutions such as Onspring, Archer, Lockpath, LogicGate, or similar platforms; hands‑on workflow and reporting configuration experience preferred.
  • Experience collaborating with cross‑functional stakeholders such as procurement, Legal, Compliance, Privacy, Internal Audit, and IT.
  • CISSP, CISA, CISM, CRISC, or similar certifications are a plus.
  • Ability to maintain confidentiality of information and exercise sound judgment when handling sensitive matters.
  • Ability to work independently as well as within a team, communicate effectively with technical and non‑technical stakeholders, and influence decisions through clear recommendations.
  • Ability to organize, prioritize, and coordinate multiple work activities, adapt to changing priorities, and meet target deadlines.
  • Ability to travel as needed to Company locations and third‑party locations within the US.
  • Individual in this position must be able to work in a standard office environment which requires sitting and viewing monitor(s) for extended periods of time, operating standard office equipment such as, but not limited to, a keyboard, copier, and telephone.
Compensation

The salary range for this position is $135k - $145K. Specific offers take into account a candidate’s education, experience and skills, as well as the candidate’s work location and internal equity. This position is also eligible for health insurance, 401k and bonus opportunity.

About Us
Why Claritev?

Healthcare is complex. We help make it clearer. At Claritev, you’ll do work that matters. Together, we’re helping make healthcare more transparent and affordable for all through the power of data, technology, and expertise. We offer meaningful opportunities to grow your career, collaborate with talented colleagues, and make an impact on the clients and communities we serve. If you’re looking for purpose, growth, and a team that succeeds together, you’ll find it here.

What Guides Us

At Claritev, innovation, agility, and a focus on results drive our success. We embrace bold thinking, work as one team, take ownership, and strive for excellence in everything we do — creating meaningful impact for our clients, communities, and each other.

My Total Value

Claritev’s Global Total Rewards Philosophy — My Total Value — Is Grounded In Investing In Our Associates And Rewarding Performance. This Includes

  • Competitive compensation and incentive opportunities (where eligible)
  • Medical, dental, and vision coverage
  • Life and disability coverage
  • 401(k) with company match
  • Employee stock purchase plan
  • Flexible spending accounts and health savings accounts
  • Paid time off and company holidays
  • Paid parental leave
  • Mental health resources
  • Tuition reimbursement
  • Financial planning resources
  • Professional development opportunities
Our Commitment to Inclusion

At Claritev, we believe diverse perspectives strengthen our teams and lead to better outcomes. We are committed to fostering an inclusive workplace where every associate feels respected, valued, and empowered to succeed.

Claritev is an Equal Opportunity Employer and complies with all applicable laws and regulations. Qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Counsel, Product and Tech
Associate Counsel, Product and Tech

MultiPlan • McLean (VA)

On-site
USD 155,000 - 170,000
Director of AI, Provider Network
Director of AI, Provider Network

Claritev • United States

On-site
USD 210,000 - 230,000
Health insurance
401(k) with match
Employee stock purchase plan
+1
DevSecOps Engineer
DevSecOps Engineer

Claritas Rx • Northern (KY)

Hybrid
USD 130,000 - 160,000
Assoc,Tech Ldrshp Rotation
Assoc,Tech Ldrshp Rotation

Claritev • United States

On-site
USD 90,000 - 110,000
Health insurance
401(k) matching
Bonus opportunity
RVP New Business Development
RVP New Business Development

Claritev • United States

On-site
USD 132,000 - 180,000
Medical, dental and vision coverage
Life and disability coverage
401(k) with company match
+2
Security Operations Analyst
Security Operations Analyst

Claritev • United States

On-site
USD 95,000 - 105,000
Health insurance
401(k) plan
Bonus opportunity
Business Acceptance Testing Associate
Business Acceptance Testing Associate

Claritev • United States

On-site
USD 61,000 - 70,000
Medical, dental, and vision coverage
401(k) with company match
Paid time off
EUC Support II, DePere office
EUC Support II, DePere office

MultiPlan • McLean (VA)

On-site
USD 82,656,000 - 89,544,000
Medical, dental, vision coverage
401(k) + match
Paid time off
AI Innovation, Principal
AI Innovation, Principal

Claritev • United States

On-site
USD 180,000 - 230,000
Health insurance
401k plan
Bonus opportunity
Security Third Party Risk Management Lead
Security Third Party Risk Management Lead

Webhosting • Austin (TX)

On-site
USD 140,000 - 210,000