The Role
Conducts end-to-end third-party risk assessments across vendor onboarding, contracting, monitoring, remediation, and offboarding. Reviews SOC 1, SOC 2, and ISO 27001 reports, evaluates data flows and system configurations, monitors regulatory compliance, tracks contract and SLA requirements, coordinates remediation, and maintains GRC inventories, dashboards, and executive reports. Partners with Procurement, Legal, vendors, and business owners to identify and resolve security and compliance risks.
Summary Generated by Built In
Role Overview
We are looking for a Third-Party Risk Analyst acts as a critical line of defense protecting data and operational integrity. The role executes end-to-end risk assessments across the entire vendor lifecycle — from onboarding and contract review through continuous monitoring and offboarding. This is a hands-on assessment role embedded in the Compliance & GRC function, working daily with Procurement, Legal, and business owners across the enterprise.
Key Responsibilities
- Risk assessments: Execute comprehensive due diligence reviews on new and existing vendors using specialized questionnaires, architecture diagrams, and data-flow assessments.
- Documentation review: Analyze third-party audit reports and security certifications, including SOC 1, SOC 2, and ISO 27001, to identify security weaknesses or compliance gaps.
- Regulatory compliance: Monitor and ensure vendor alignment with privacy regulations and framework criteria such as PCI DSS, SOX, HIPAA, and GLBA.
- Contract and SLA tracking: Partner with Procurement and Legal to review contract language, integrate required security clauses, and track vendor performance against Service Level Agreements (SLAs).
- Issue remediation: Coordinate with business owners and external vendors to build remediation roadmaps, track open security items, and validate corrective evidence before closing risk exceptions.
- Reporting and metrics: Maintain the centralized Governance, Risk, and Compliance (GRC) platform inventory, updating risk dashboards and compiling status reports for executive committees and auditors.
Requirements
- Third-Party Risk Management (TPRM)
- Information Security Auditing
- IT Compliance
- SOC 1 Report Analysis
- SOC 2 Report Analysis
- ISO 27001 Report Analysis
- Analytical Skills
- Technical Literacy
- Data Flow Interpretation
- System Configuration Analysis
- GRC Platforms
- Vendor Risk Indexing Tools
- UpGuard
- OneTrust
- SecurityScorecard
- Bitsight
- Stakeholder Management
- Written Communication
- Verbal Communication
- English
Preferred Skills
- PCI DSS Compliance
- SOX Compliance
- HIPAA Compliance
- GLBA Compliance
- Contract Review
- Vendor Inventory Management
- Executive Dashboard Management
- CTPRP Certification
- CISA Certification
Qualifications
- At least 2 years of dedicated experience in Third-Party Risk Management (TPRM), information security auditing, or IT compliance
- Ability to read and interpret SOC 1, SOC 2, and ISO 27001 reports and translate findings into actionable risk language
- Sharp analytical skills and strong technical literacy, including the ability to interpret data flows and system configurations
- Hands-on experience with GRC platforms and vendor risk indexing tools (e.g., UpGuard, OneTrust, SecurityScorecard, or Bitsight)
- Exceptional cross-functional stakeholder management — comfortable holding vendors and internal owners to commitments
- Excellent written and verbal communication skills in English
- Experience supporting PCI DSS, SOX, HIPAA, or GLBA compliance programs at retail or multi-brand scale (preferred)
- Prior exposure to contract review in partnership with Procurement and Legal (preferred)
- Experience maintaining a vendor inventory and executive-level risk dashboards (preferred)
- Bachelor's degree in Information Technology, Cybersecurity, Management Information Systems, Business Administration, Finance, or a related discipline — or equivalent hands-on experience
- CTPRP (Certified Third-Party Risk Professional) or CISA (Certified Information Systems Auditor) strongly preferred
Skills Required
- At least 2 years of dedicated experience in Third-Party Risk Management, information security auditing, or IT compliance
- Ability to read and interpret SOC 1, SOC 2, and ISO 27001 reports and translate findings into actionable risk language
- Analytical skills and technical literacy, including interpreting data flows and system configurations
- Hands-on experience with GRC platforms and vendor risk indexing tools such as UpGuard, OneTrust, SecurityScorecard, or Bitsight
- Cross-functional stakeholder management skills
- Excellent written and verbal communication skills in English
- Experience supporting PCI DSS, SOX, HIPAA, or GLBA compliance programs at retail or multi-brand scale
- Contract review experience in partnership with Procurement and Legal
- Experience maintaining vendor inventories and executive-level risk dashboards
- Bachelor's degree in Information Technology, Cybersecurity, Management Information Systems, Business Administration, Finance, or a related discipline, or equivalent hands-on experience
- CTPRP or CISA certification
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Simfluent builds and operates global capability centers for modern enterprises. It creates fully integrated hubs that function as permanent extensions of clients’ businesses, with capabilities spanning engineering and platforms, cloud, architecture, product, data, and AI. Through greenfield, build-operate-transfer, and hybrid models, Simfluent helps organizations scale technology delivery while preserving quality, culture, strategic alignment, and local control, with predictable execution at enterprise scale.







