W2/ Subject Matter Expert

VensIT Corp

United States

Remote

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

VensIT Corp is seeking an experienced Subject Matter Expert for Third-Party Risk Management (TPRM) assessments and remediation in a fully remote, client-facing role. You will manage the end-to-end lifecycle from inventory governance to escalation management, with executive reporting and high-visibility stakeholder engagement.

Responsibilities include supplier inventory validation, adherence to frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2), remediation coordination, and weekly metrics

Qualifications

  • Experience managing end-to-end vendor risk assessments.
  • Strong coordination with legal, procurement and InfoSec.
  • Ability to operate in a fully remote, client-facing environment.

Responsibilities

  • Manage supplier inventory and DRIs in the GRC platform.
  • Coordinate assessment execution across multiple frameworks.
  • Own remediation plans and CAPs end-to-end.
  • Communicate with stakeholders and escalate as needed.
  • Produce weekly leadership reports with metrics.

Skills

Vendor risk management
Stakeholder communication
Project coordination
GRC tools

Tools

Wrike
AirTable
OneTrust
SupplierNinja

Job description

Subject Matter Expert

Remote

Long term

We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation --- from inventory governance through assessment coordination, escalation management, and executive reporting --- in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.

Key Responsibilities
1. Supplier Inventory Management
  • Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
  • Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
  • Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).
2. Assessment Execution
  • Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
  • Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
  • Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
  • Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
  • Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
3. Remediation Management
  • Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
  • Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
4. Stakeholder Communication & Escalation
  • Run a structured outreach cadence with DRIs (kick-off → 3 follow-ups → 3 escalations to management).
  • Track response/non-response rates for every outreach cycle.
  • Escalate unresolved/high-risk findings to client leadership and track to closure.
5. Weekly Reporting

Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC TPRM Assessment and Remediation SME
GRC TPRM Assessment and Remediation SME

Programmers.io • Austin (TX)

Remote
USD 120,000 - 160,000
Remote TPRM Assessment & Remediation Lead
Remote TPRM Assessment & Remediation Lead

Programmers.io • Austin (TX)

Remote
USD 120,000 - 160,000
Remote TPRM Risk Assessment & Remediation Lead
Remote TPRM Risk Assessment & Remediation Lead

Tata Consultancy Services • Sunnyvale (CA)

On-site
USD 80,000 - 140,000
Remote TPRM Assessment & Remediation Lead
Remote TPRM Assessment & Remediation Lead

VensIT Corp • United States

Remote
USD 120,000 - 180,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

Automotivemastermind • Centreville (VA)

On-site
USD 70,000 - 90,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

Mobility Global • Centreville (VA)

On-site
USD 70,000 - 100,000
Third Party Risk Management (TPRM) Analyst
Third Party Risk Management (TPRM) Analyst

R. L. Polk Mobility LLC • Centreville (VA)

On-site
USD 65,000 - 90,000
Information Technology Security Manager
Information Technology Security Manager

Meet Life Sciences • Princeton (NJ)

Hybrid
USD 124,000 - 165,000
Senior Third-Party Risk Management Analyst
Senior Third-Party Risk Management Analyst

Phyton Talent Advisors • Red Bank (NJ)

On-site
USD 90,000 - 150,000
Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst

Wright-Patt Credit Union Inc. • Beavercreek (OH)

On-site
USD 90,000 - 120,000