- Company Name
- BioSpace
- Job Title
- Third Party Risk Management Analyst (Contractor)
- Job Description
-
**Job Title**
Third Party Risk Management Analyst (Contractor)
**Role Summary**
The Analyst provides end‑to‑end Third‑Party Security Risk Management (TPSRM) support, evaluating vendor security posture, data privacy compliance, and AI risk. Acts as the subject‑matter expert, leading assessments, defining risk tiers, and collaborating with Legal, Compliance, Procurement, and business units to remediate identified risks.
**Expectations**
- Deliver thorough third‑party assessments in accordance with industry best practices.
- Communicate findings, risk levels, and remediation plans clearly to stakeholders.
- Maintain robust documentation, risk registers, and vendor tiering.
- Continuously improve assessment timeliness, remediation rates, and residual risk reduction.
- Adapt quickly to shifting priorities and business needs.
**Key Responsibilities**
1. Execute vendor management processes and schedule security/privacy/AI assessments.
2. Evaluate key information security risks (confidentiality, integrity, availability) through operational reviews (vulnerability management, monitoring, incident response, defense in depth).
3. Define risk levels, corrective actions, and formally communicate outcomes.
4. Document assessments, findings, recommendations, and remediation status.
5. Conduct post‑assessment validation, follow‑ups, and re‑assessments per TPSRM schedule.
6. Maintain risk register, vendor tier listings, and continuous improvement metrics.
7. Act as a subject‑matter expert on TPSRM, advising on new and existing vendor risks.
8. Collaborate with Procurement and business owners to align risk mitigation with procurement activities.
9. Provide supporting TPSRM documentation for audit purposes.
10. Lead kickoff meetings with vendors to define assessment scope and technologies used.
**Required Skills**
- In‑depth knowledge of TPSRM frameworks, security operations, and privacy regulations (GDPR, CCPA, PIPL).
- Strong analytical and risk assessment abilities.
- Excellent written and verbal communication skills for stakeholder engagement and documentation.
- Ability to build and maintain relationships with Legal, Compliance, Procurement, and business units.
- Proficiency with continuous assessment tools and metrics development.
- Agile, result‑focused mindset with capability to shift priorities quickly.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Computer Science, Business, or related field (advanced degree preferred).
- Minimum 5+ years of TPSRM or public‑accounting 3rd‑party risk experience.
- Preferred certifications: CISA, CISSP, CRVPM.
- Ability to work onsite at least 3 days per week.