Technical Risk Management Professional

KellyMitchell Group

Renton (WA)

Remote

USD 52,000 - 76,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, Dental & Vision
ESOP
401K

Job summary

KellyMitchell Group is seeking an experienced Third-Party/Technical Risk Management professional for a contract role (approx. 1 year). You will own the TPRM program end-to-end, including risk register maintenance, vendor intake, and risk scoring, plus quantitative assessments using FAIR.

The role is fully remote in the US, with responsibilities spanning risk identification, analysis, remediation tracking, and leadership reporting. Strong communication and independent work style are essential.

Qualifications

  • 5+ years hands-on third-party/vendor risk assessments.
  • 3+ years in technical or quantitative risk management.
  • Experience with vendor intake, inherent-risk tiering, security questionnaires, documentation review and risk scoring.
  • Experience applying FAIR or similar risk quantification methodologies.
  • Experience owning and maintaining a risk register or risk management program.
  • Strong technical fluency across infrastructure, applications and security documentation.
  • Knowledge of SOC 2, ISO 27001 and NIST CSF.

Responsibilities

  • Own and operate the Technical Risk Management program end-to-end, including risk register maintenance and risk closure.
  • Manage the Third-Party Risk Management lifecycle for vendors, including intake, tiering, evidence review and risk scoring.
  • Apply structured risk quantification methods (e.g., FAIR) to assess risks in financial terms.
  • Perform technical risk analysis across infrastructure, applications, and vendor architecture.
  • Translate technical findings into clear business-relevant risk statements for stakeholders.
  • Collaborate with security engineering and GRC to evaluate diagrams, scans and configurations.
  • Track findings and remediation through closure and raise stalled items as needed.
  • Monitor vendors for changes in risk posture and subprocess changes.
  • Prepare and present risk and TPRM reporting for leadership.

Skills

Vendor risk
Quantitative risk
Security questionnaires
FAIR
Risk register
Security frameworks
Technical fluency
Documentation review
Stakeholder communication

Tools

OneTrust
Vanta
Archer
ServiceNow GRC

Job description

Job Summary

Our client is seeking an experienced Third-Party Risk Management / Technical Risk Management professional to join their team. This is a contract opportunity for a hands-on risk professional who can independently manage the vendor risk lifecycle, maintain and analyze an enterprise technical risk register, perform technical and quantitative risk assessments, and translate technical findings into business-relevant risk. The ideal candidate will have strong experience with vendor risk assessments, risk quantification methodologies such as FAIR, security frameworks, and technical risk analysis, while being comfortable operating independently with minimal oversight.

Contract Details
  • Contract type and duration: Contract, approximately 1 year
  • Contract dates: 10/19/2026 – 10/15/2027
  • Work location: Remote – US
  • Onsite, hybrid or remote expectations: Fully Remote
Core Responsibilities
  • Own and operate the Technical Risk Management program end-to-end, including maintaining the enterprise risk register and driving risk identification, analysis, ownership, and closure
  • Manage the Third-Party Risk Management lifecycle for assigned vendors, including intake, inherent-risk tiering, security questionnaire review, evidence/documentation review, and risk scoring
  • Apply structured risk quantification methods such as FAIR or similar methodologies to assess and prioritize vendor and technical risks in financial or business-impact terms
  • Perform technical risk analysis across infrastructure, applications, and vendor architecture findings
  • Translate technical control gaps and findings into clear, business-relevant risk statements
  • Partner with security engineering and GRC stakeholders to evaluate architecture diagrams, scan results, control configurations, and other technical evidence
  • Track vendor findings and remediation commitments through closure and raise stalled items as needed
  • Monitor existing vendors for material changes in risk posture, including breach disclosures, control changes, and subprocessor changes
  • Prepare and present risk and TPRM reporting, metrics, and updates for internal stakeholders and leadership
  • Operate independently using established TPRM and risk management processes while exercising judgment on prioritization and escalation
Required Skills/Experience (Must-Haves)
  • 5+ years of hands-on experience managing third-party/vendor risk assessments
  • 3+ years of experience in technical or quantitative risk management
  • Strong experience with vendor intake, inherent-risk tiering, security questionnaires, documentation/evidence review, and risk scoring
  • Experience applying FAIR or similar risk quantification methodologies
  • Experience independently owning and maintaining a risk register or risk management program
  • Strong technical fluency with infrastructure, application, and vendor architecture and security documentation
  • Ability to critically evaluate security controls and determine whether they address the underlying risk
  • Working knowledge of common security frameworks including SOC 2, ISO 27001, and NIST CSF
  • Strong organizational skills and ability to manage a high-volume caseload of vendor assessments and risk register items
  • Excellent written and verbal communication skills for vendor-facing correspondence, technical findings, and leadership-level reporting
Preferred Skills/Experience (Nice-to-Haves)
  • Experience working in a SaaS or technology company’s TPRM or Technical Risk Management function
  • Formal training or certification in FAIR / Open FAIR
  • Familiarity with GRC or TPRM tools such as OneTrust, Vanta, Archer, ServiceNow GRC, or similar platforms
  • CISSP, CISA, or CRISC certification
  • Experience with enterprise-level technical risk analysis and risk quantification
  • Third-Party Risk Management and Technical Risk Management expertise
Key Competencies & Behaviors
  • Strong technical analysis and risk assessment skills
  • Ability to translate technical findings into business-relevant risk
  • Strong risk quantification, prioritization, and decision-making skills
  • Ability to independently own and operate risk management programs
  • Strong vendor management and stakeholder collaboration skills
  • Excellent organizational skills and follow-through
  • Effective written, verbal, and leadership communication
  • Proactive problem-solving and escalation management
  • Ability to work independently with minimal oversight
Work Environment

Location: Remote – US Onsite, Hybrid or Remote: Fully Remote Work schedule: Monday–Friday, 40 hours per week Collaboration with security engineering, GRC, vendors, and internal stakeholders Personal laptop required

Compensation & Benefits
  • Pay Range: The approximate pay range for this position is between $38.00 and $55.00. Please note that the pay range provided is a good faith estimate. Final compensation may vary based on factors including but not limited to background, knowledge, skills, and location. We comply with local wage minimums.
  • Medical, Dental, & Vision Insurance Plans
  • Employee-Owned Profit Sharing (ESOP)
  • 401K offered

About KellyMitchell At KellyMitchell, our culture is world class. We're movers and shakers! We don't mind a bit of friendly competition, and we reward hard work with unlimited potential for growth. This is an exciting opportunity to join a company known for innovative solutions and unsurpassed customer service. We're passionate about helping companies solve their biggest IT staffing & project solutions challenges. As an employee-owned, women-led organization serving Fortune 500 companies nationwide, we deliver expert service at a moment's notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Technical Risk & Vendor Risk Leader
Remote Technical Risk & Vendor Risk Leader

KellyMitchell Group • Renton (WA)

Remote
USD 52,000 - 76,000
Medical, Dental & Vision
ESOP
401K
Vendor Risk Manager
Vendor Risk Manager

Skill • Westlake (TX)

On-site
USD 49,593 - 56,481
Health insurance
Contracts Manager - Junior/ Third-Party Risk Management (TPRM)
Contracts Manager - Junior/ Third-Party Risk Management (TPRM)

Spectraforce Technologies • Westlake (TX)

On-site
USD 120,000 - 150,000
Senior Third-Party Risk Management Analyst
Senior Third-Party Risk Management Analyst

Phyton Talent Advisors • Red Bank (NJ)

On-site
USD 90,000 - 150,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

Automotivemastermind • Centreville (VA)

On-site
USD 70,000 - 90,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

Mobility Global • Centreville (VA)

On-site
USD 70,000 - 100,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

R. L. Polk Mobility LLC • Centreville (VA)

On-site
USD 65,000 - 90,000
Senior Third-Party Risk Management Consultant - 2-Year Engagement
Senior Third-Party Risk Management Consultant - 2-Year Engagement

MENA Consultant • United States

Remote
USD 120,000 - 180,000
Vendor Risk Manager [AQ-18897]
Vendor Risk Manager [AQ-18897]

Aquent • Roanoke (TX)

On-site
USD 120,000 - 180,000
Health & Dental
Sick leave
401(k) match
Sr. TPRM Security Analyst
Sr. TPRM Security Analyst

Claritev • United States

On-site
USD 135,000 - 145,000
Health insurance
401(k) with company match
Paid time off
+2