About this role
Role Overview
We are looking for a Third-Party Risk Analyst acts as a critical line of defense protecting data and operational integrity. The role executes end-to-end risk assessments across the entire vendor lifecycle — from onboarding and contract review through continuous monitoring and offboarding. This is a hands-on assessment role embedded in the Compliance & GRC function, working daily with Procurement, Legal, and business owners across the enterprise.
\nKey Responsibilities- Risk assessments: Execute comprehensive due diligence reviews on new and existing vendors using specialized questionnaires, architecture diagrams, and data-flow assessments.
- Documentation review: Analyze third-party audit reports and security certifications, including SOC 1, SOC 2, and ISO 27001, to identify security weaknesses or compliance gaps.
- Regulatory compliance: Monitor and ensure vendor alignment with privacy regulations and framework criteria such as PCI DSS, SOX, HIPAA, and GLBA.
- Contract and SLA tracking: Partner with Procurement and Legal to review contract language, integrate required security clauses, and track vendor performance against Service Level Agreements (SLAs).
- Issue remediation: Coordinate with business owners and external vendors to build remediation roadmaps, track open security items, and validate corrective evidence before closing risk exceptions.
- Reporting and metrics: Maintain the centralized Governance, Risk, and Compliance (GRC) platform inventory, updating risk dashboards and compiling status reports for executive committees and auditors.
- Third-Party Risk Management (TPRM)
- Information Security Auditing
- IT Compliance
- SOC 1 Report Analysis
- SOC 2 Report Analysis
- ISO 27001 Report Analysis
- Analytical Skills
- Technical Literacy
- Data Flow Interpretation
- System Configuration Analysis
- GRC Platforms
- Vendor Risk Indexing Tools
- UpGuard
- OneTrust
- SecurityScorecard
- Bitsight
- Stakeholder Management
- Written Communication
- Verbal Communication
- English
- PCI DSS Compliance
- SOX Compliance
- HIPAA Compliance
- GLBA Compliance
- Contract Review
- Vendor Inventory Management
- Executive Dashboard Management
- CTPRP Certification
- CISA Certification
- At least 2 years of dedicated experience in Third-Party Risk Management (TPRM), information security auditing, or IT compliance
- Ability to read and interpret SOC 1, SOC 2, and ISO 27001 reports and translate findings into actionable risk language
- Sharp analytical skills and strong technical literacy, including the ability to interpret data flows and system configurations
- Hands-on experience with GRC platforms and vendor risk indexing tools (e.g., UpGuard, OneTrust, SecurityScorecard, or Bitsight)
- Exceptional cross-functional stakeholder management — comfortable holding vendors and internal owners to commitments
- Excellent written and verbal communication skills in English
- Experience supporting PCI DSS, SOX, HIPAA, or GLBA compliance programs at retail or multi-brand scale (preferred)
- Prior exposure to contract review in partnership with Procurement and Legal (preferred)
- Experience maintaining a vendor inventory and executive-level risk dashboards (preferred)
- Bachelor's degree in Information Technology, Cybersecurity, Management Information Systems, Business Administration, Finance, or a related discipline — or equivalent hands-on experience
- CTPRP (Certified Third-Party Risk Professional) or CISA (Certified Information Systems Auditor) strongly preferred
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?