
Third-Party Risk Management - Cybersecurity
- On-site, Hybrid
- Austin, Texas, United States
- Cupertino, California, United States
+1 more- Information Technology
TPRM/GRC SME managing vendor cybersecurity assessments, remediation, CAPs, escalations & reporting. 5+ yrs experience with NIST, ISO 27001, SOC 2, SIG/CAIQ and GRC tools required.
Job description
Job Description:
GRC TPRM Assessment and Remediation SME
We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert (SME) to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation.
The role will be responsible for supplier inventory governance, assessment coordination, findings management, remediation tracking, escalation management, and executive reporting. The ideal candidate will have strong TPRM/GRC expertise, excellent communication skills, and experience managing high-volume, multi-step risk assessment workflows.
Location: Austin, TX / Cupertino, CA
Work Model: Hybrid – 3 Days a Week Onsite
Duration: 12+ Months Contract
Key Responsibilities
1. Supplier Inventory Management
Maintain the Supplier Inventory within the GRC platform as the single source of truth for assessment status.
Tier and filter suppliers requiring reassessment versus new assessments based on program criteria.
Maintain accurate Direct Responsible Individual (DRI) records within the GRC tool.
2. Assessment Execution
Evaluate suppliers against established frameworks and standards, including:
SIG
CAIQ
NIST CSF
ISO 27001
SOC 2
Review and validate supplier evidence, including audit reports, certifications, penetration test results, and other security documentation.
Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
Log and track assessment tasks in workflow/tracking tools, including acknowledgement evidence.
Verify that onsite-assessed suppliers have current-year assessment coverage.
Participate in recurring findings-review meetings and provide guidance on policy requirements and evidence standards.
3. Remediation Management
Own Corrective Action Plans (CAPs) from initiation through closure.
Define remediation SLAs and track progress against established timelines.
Drive remediation closure with suppliers and internal business owners.
Coordinate with Legal, Procurement, and Information Security (InfoSec) teams regarding remediation timelines and compensating controls.
Monitor open findings and ensure appropriate documentation and evidence are maintained.
4. Stakeholder Communication & Escalation
Manage a structured outreach cadence with DRIs, including:
Initial kick-off
Follow-up communications
Management escalations
Track response and non-response rates for each outreach cycle.
Escalate unresolved or high-risk findings to appropriate leadership.
Maintain clear documentation of all communications, decisions, and remediation activities.
Build and maintain strong relationships with business stakeholders and suppliers.
5. Weekly Reporting
Prepare and deliver weekly metrics and status reports for leadership.
Track and report:
Outreach volume
Supplier response rates
Follow-up and escalation status
Suppliers approved for new assessments or reassessments
Assessment completion and coverage
Open findings and remediation status
Overall TPRM program progress
Job requirements
Required Qualifications
5+ years of experience in Cybersecurity, Third-Party Risk Management (TPRM), GRC Operations, Supplier Risk, or a related field.
Strong working knowledge of:
NIST CSF
ISO 27001
SOC 2
SIG
CAIQ
Hands-on experience with GRC/TPRM platforms, such as:
OneTrust
RSA Archer
ServiceNow GRC
SupplierNinja
or similar platforms
Proven experience managing high-volume, multi-step communication and assessment workflows.
Strong findings and remediation management experience.
Excellent written and verbal communication skills.
Strong documentation, organization, and follow-through skills.
Experience working with distributed or remote teams.
Ability to communicate effectively with business stakeholders, suppliers, and leadership.
Preferred Qualifications
Relevant certification such as CTPRP, CRISC, CISA, or CISSP.
Experience with workflow and tracking tools such as:
Wrike
Airtable
Jira
or similar platforms
Experience working in regulated industries such as:
Financial Services
Healthcare
Insurance
Experience preparing leadership-facing metrics, dashboards, and weekly reports.
Experience managing supplier cybersecurity assessments and remediation programs in a large enterprise environment.
or
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.
