Sr. Technology Risk Analyst
About this role
Senior Technology Risk Analyst
About Sungrow:
Sungrow Power Supply Co., Ltd. (“Sungrow”) is a global leading PV inverter and ESS provider with 515 GW of power electronic converters installed worldwide as of December 2023. Founded in 1997 by University Professor Cao Renxian, Sungrow leads in the research and development of solar inverters with the largest dedicated R&D team in the industry and a broad product portfolio offering PV inverter solutions and ESS for utility-scale, commercial & industrial, and residential applications, as well as internationally recognized floating PV plant solutions, NEV driving solutions, EV charging solutions, and renewable hydrogen production systems. With a strong 27-year track record in the PV space, Sungrow products power in 170 countries and regions worldwide. For more information, visit: www.sungrowpower.com.
The Position:
Sungrow Americas is seeking a Senior Technology Risk Analyst to support the execution and continuous improvement of the organization's Risk Management program.
Working under the direction of the Third-Party Risk Management Lead and in partnership with the Governance, Risk & Compliance (GRC) Manager, this role is responsible for performing vendor security assessments, reviewing security evidence, validating third-party controls, coordinating remediation activities, and maintaining a mature, auditable vendor risk management program.
The ideal candidate possesses strong experience reviewing security documentation, collaborating across Procurement, Legal, IT, Engineering, Product Security, and business stakeholders, and translating complex technical findings into practical business risk.
This position plays a key role in strengthening Sungrow's cybersecurity posture across SaaS, cloud, operational technology (OT), software suppliers, manufacturing partners, and strategic service providers supporting critical infrastructure operations.
Key Responsibilities
Third-Party Risk Operations
- Execute Sungrow's Third-Party Risk Management lifecycle, including vendor onboarding, periodic reassessments, contract renewals, and offboarding.
- Perform vendor intake reviews to determine inherent risk, business criticality, data sensitivity, connectivity, and regulatory impact.
- Maintain the enterprise vendor inventory, vendor classifications, and risk tiering methodology.
- Coordinate vendor assessment schedules and ensure timely completion of required reviews.
Security Assessments & Due Diligence
- Conduct security assessments for software vendors, cloud providers, managed service providers, professional services firms, product suppliers, and strategic third parties.
- Review and evaluate:
- SOC 2 Type II reports
- ISO 27001 certifications
- Penetration test summaries
- Security questionnaires (SIG, CAIQ, custom)
- Security policies and standards
- Business Continuity and Disaster Recovery documentation
- Privacy and data protection controls
- Identify control gaps, residual risks, and recommended mitigation strategies.
- Validate vendor controls against Sungrow security requirements and applicable regulatory frameworks.
Continuous Monitoring & Risk Management
- Monitor vendor security posture throughout the vendor lifecycle.
- Track remediation commitments and coordinate follow-up activities through closure.
- Monitor vendor certifications, attestations, and supporting documentation for expiration and renewal.
- Maintain accurate vendor risk records within the organization's GRC platform.
- Assist in identifying changes in vendor ownership, subcontractors, or security posture that may affect organizational risk.
Governance & Customer Assurance
- Maintain complete, accurate, and audit-ready documentation supporting Sungrow's Third-Party Risk Management program.
- Support customer security assessments by providing vendor assurance documentation and supporting evidence.
- Prepare reports and operational metrics covering:
- Assessment completion
- Vendor inventory
- Remediation status
- Assessment aging
- High-risk vendors
- Outstanding exceptions
- Support internal audits, customer reviews, and regulatory inquiries.
Contract & Procurement Support
- Partner with Procurement and Legal during vendor onboarding and contract renewals.
- Review vendor security documentation supporting contractual security obligations.
- Validate vendor compliance with contractual security requirements including:
- Incident notification
- Encryption
- Access control
- Data protection
- Business continuity
- Audit rights
- Escalate material risks requiring management review.
Business Continuity Support
Working alongside the Third-Party Risk Management Lead:
- Review vendor Business Continuity and Disaster Recovery capabilities during security assessments.
- Maintain Business Impact Analysis (BIA) documentation related to critical third-party services.
Company at a glance
Founded in 1997, Sungrow Power Supply Co., Ltd. is a leading global renewable energy company specializing in the R&D, production, sales, and services of renewable energy equipment.
Sungrow operates in more than 100 countries and regions worldwide, with 20+ international subsidiaries, 4 major manufacturing bases, and 7 R&D centers.
With strong global presence and continuous innovation, Sungrow has been honored with numerous awards, including “Global Top 500 New Energy Enterprises”, “The World's Most Bankable PV Inverter and Energy Storage Company (BloombergNEF).”, “Best Employer Brand among Globalized Enterprises”, and “MSCI ESG Rating AAA”.
Looking ahead, Sungrow will remain committed to its mission of “Clean power for all,” to bridge to a sustainable future while building a trusted, world-renowned brand.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?