Skip to content

Third-Party Risk Management - Cybersecurity

  • On-site, Hybrid
    • Austin, Texas, United States
    • Cupertino, California, United States
    +1 more
  • Information Technology

TPRM/GRC SME managing vendor cybersecurity assessments, remediation, CAPs, escalations & reporting. 5+ yrs experience with NIST, ISO 27001, SOC 2, SIG/CAIQ and GRC tools required.

Job description

Job Description:

GRC TPRM Assessment and Remediation SME

We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert (SME) to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation.

The role will be responsible for supplier inventory governance, assessment coordination, findings management, remediation tracking, escalation management, and executive reporting. The ideal candidate will have strong TPRM/GRC expertise, excellent communication skills, and experience managing high-volume, multi-step risk assessment workflows.

Location: Austin, TX / Cupertino, CA
Work Model: Hybrid – 3 Days a Week Onsite
Duration: 12+ Months Contract

Key Responsibilities

1. Supplier Inventory Management

  • Maintain the Supplier Inventory within the GRC platform as the single source of truth for assessment status.

  • Tier and filter suppliers requiring reassessment versus new assessments based on program criteria.

  • Maintain accurate Direct Responsible Individual (DRI) records within the GRC tool.

2. Assessment Execution

  • Evaluate suppliers against established frameworks and standards, including:

    • SIG

    • CAIQ

    • NIST CSF

    • ISO 27001

    • SOC 2

  • Review and validate supplier evidence, including audit reports, certifications, penetration test results, and other security documentation.

  • Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.

  • Log and track assessment tasks in workflow/tracking tools, including acknowledgement evidence.

  • Verify that onsite-assessed suppliers have current-year assessment coverage.

  • Participate in recurring findings-review meetings and provide guidance on policy requirements and evidence standards.

3. Remediation Management

  • Own Corrective Action Plans (CAPs) from initiation through closure.

  • Define remediation SLAs and track progress against established timelines.

  • Drive remediation closure with suppliers and internal business owners.

  • Coordinate with Legal, Procurement, and Information Security (InfoSec) teams regarding remediation timelines and compensating controls.

  • Monitor open findings and ensure appropriate documentation and evidence are maintained.

4. Stakeholder Communication & Escalation

  • Manage a structured outreach cadence with DRIs, including:

    • Initial kick-off

    • Follow-up communications

    • Management escalations

  • Track response and non-response rates for each outreach cycle.

  • Escalate unresolved or high-risk findings to appropriate leadership.

  • Maintain clear documentation of all communications, decisions, and remediation activities.

  • Build and maintain strong relationships with business stakeholders and suppliers.

5. Weekly Reporting

  • Prepare and deliver weekly metrics and status reports for leadership.

  • Track and report:

    • Outreach volume

    • Supplier response rates

    • Follow-up and escalation status

    • Suppliers approved for new assessments or reassessments

    • Assessment completion and coverage

    • Open findings and remediation status

    • Overall TPRM program progress

Job requirements

Required Qualifications

  • 5+ years of experience in Cybersecurity, Third-Party Risk Management (TPRM), GRC Operations, Supplier Risk, or a related field.

  • Strong working knowledge of:

    • NIST CSF

    • ISO 27001

    • SOC 2

    • SIG

    • CAIQ

  • Hands-on experience with GRC/TPRM platforms, such as:

    • OneTrust

    • RSA Archer

    • ServiceNow GRC

    • SupplierNinja

    • or similar platforms

  • Proven experience managing high-volume, multi-step communication and assessment workflows.

  • Strong findings and remediation management experience.

  • Excellent written and verbal communication skills.

  • Strong documentation, organization, and follow-through skills.

  • Experience working with distributed or remote teams.

  • Ability to communicate effectively with business stakeholders, suppliers, and leadership.

Preferred Qualifications

  • Relevant certification such as CTPRP, CRISC, CISA, or CISSP.

  • Experience with workflow and tracking tools such as:

    • Wrike

    • Airtable

    • Jira

    • or similar platforms

  • Experience working in regulated industries such as:

    • Financial Services

    • Healthcare

    • Insurance

  • Experience preparing leadership-facing metrics, dashboards, and weekly reports.

  • Experience managing supplier cybersecurity assessments and remediation programs in a large enterprise environment.

or