Third-Party Risk Analyst

Posted 5 Days Ago
Easy Apply
Be an Early Applicant
Bengaluru, Karnataka
Hybrid
Mid level
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Travel & expense made easy.
The Role
Own vendor lifecycle risk assessments, review SOC2/ISO/pen-test reports, redline security and data agreements, engage vendors for remediation, monitor vendor posture, and collaborate with Procurement, Legal, Privacy, and Engineering.
Summary Generated by Built In
About The Position

As Navan continues to scale globally, our ecosystem of vendors and partners grows with us. We are looking for a Third-Party Risk Analyst to join our Security & Compliance team. In this role, you will be the gatekeeper of our vendor lifecycle, ensuring that every third party—from software providers to Travel Management Companies (TMCs)—meets our rigorous security and privacy standards. You will sit at the intersection of Procurement, Legal, and Security, driving the risk assessment process and ensuring that Navan’s data remains protected across our entire supply chain.

What You’ll Do
  • Risk Assessment Ownership: Conduct comprehensive security and privacy risk assessments for new and existing third parties using procurement and GRC tools and partner with Security leadership to escalate high-risk vendors and support documented risk acceptance or remediation decision
  • Vendor Due Diligence: Review SOC2 reports, ISO certifications, and penetration test summaries to identify potential vulnerabilities in a vendor’s posture.
  • Contractual Redlining: Partner with Legal to review and redline Security Addendums and Data Processing Addendums (DPAs), ensuring vendors commit to Navan’s required security controls.
  • Vendor Engagement: Lead the outreach to vendor security teams to clarify questionnaire responses, follow up on remediation items, and ensure compliance with our standards.
  • TMC & Partner Management: Work closely with our Travel Management Companies to gather essential security documentation and manage the lifecycle of partner-specific risk reviews and contracts.
  • Continuous Monitoring: Monitor the existing vendor landscape for security incidents, certification expirations, for security alerts, news of breaches, or changes in risk profiles, and trigger re-assessments when necessary.
  • Cross-Fuctional Collaboration: You will work closely with Procurement, Legal, Privacy, and Engineering teams on third-party security and risk considerations throughout the vendor lifecycle
What We’re Looking For
  • Experience: 2–4 years in Third-Party Risk Management (TPRM), Vendor Risk, or IT Audit.
  • Regulatory Knowledge: Familiarity with privacy frameworks (GDPR, CCPA) and security standards (SOC 2, ISO 27001).
  • Procurement Savvy: Experience working within procurement workflows and using GRC or Vendor Management tools (e.g., OneTrust, Prevalent, or Vanta).
  • Analytical Mindset: Ability to spot "red flags" in a vendor’s security documentation and translate those risks into business impact for internal stakeholders.
  • Negotiation Skills: Comfortable holding vendors accountable and negotiating security terms in contracts.
  • Organization: You can manage dozens of active vendor assessments simultaneously without losing track of deadlines or documentation gaps.

Top Skills

Ccpa
Gdpr
Iso 27001
Onetrust
Prevalent
Soc 2
Vanta

What the Team is Saying

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Palo Alto, CA
3,300 Employees
Year Founded: 2015

What We Do

Navan (Nasdaq: NAVN) is the leading all-in-one business travel, payments, and expense management platform that makes travel easy for frequent travelers. From finding flights and hotels to automating expense reconciliation, with 24/7 support along the way, Navan delivers an intuitive experience travelers love and finance teams rely on. See how Navan customers benefit and learn more at navan.com.

Why Work With Us

At Navan, we’re never satisfied with the status quo, and we know breakthrough ideas come from diverse perspectives. We are committed to cultivating a workplace that reflects the diversity of the customers we serve while fostering leadership and innovation.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Navan Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

In-person connections is the foundation of Navan, the connections forged through face-to-face interactions improve company culture and what we can achieve together. We operate on a hybrid working model, which we define as four days a week in-office.

Typical time on-site: 4 days a week
HQPalo Alto, CA
Austin, TX
Bengaluru, IN
Berlin, DE
Boston, MA
Dallas, TX
Gurugram, IN
Lisbon, PT
London, GB
New Delhi, Delhi
New York, NY
Paris, FR
San Francisco, CA
Singapore
Sydney, AU
Tel Aviv-Yafo, IL
Learn more

Similar Jobs

Navan Logo Navan

Senior Full-stack Engineer

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
Bengaluru, Karnataka, IND
3300 Employees

Navan Logo Navan

Senior Back-end Engineer

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
Bengaluru, Karnataka, IND
3300 Employees

Navan Logo Navan

Senior Software Engineer

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
Bengaluru, Karnataka, IND
3300 Employees

Navan Logo Navan

Senior Software Engineer

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
Bengaluru, Karnataka, IND
3300 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account