

TEK NINJAS
Senior Security Risk Management Analyst
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a Senior Security Risk Management Analyst, remote for 6 months, with a pay rate of "X". Requires 6-8 years in third-party risk assessment, knowledge of ISO 27001/2, and certifications like CISA or CISSP.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
Unknown
-
ποΈ - Date
June 24, 2026
π - Duration
More than 6 months
-
ποΈ - Location
Remote
-
π - Contract
Unknown
-
π - Security
Unknown
-
π - Location detailed
United States
-
π§ - Skills detailed
#PCI (Payment Card Industry) #Cybersecurity #Compliance #Monitoring #Security #Leadership #Jira #Computer Science
Role description
Job Title: Senior Security Risk Management Analyst
Location: Remote
Duration: 6 months
Summary
:Client is seeking an experienced professional to join our Third-Party/ Vendor Risk Assessment team. This team focuses on analyzing and managing risks associated with our vendors, service providers, and other third parties, ensuring our organization upholds the highest standards of compliance, security, and business resilience. While your primary responsibility will be Third-Party Risk Management, you will also collaborate on other cybersecurity risk management initiatives. Building strong cross-functional relationships across the company is a key component of this role. To excel, you must showcase exceptional leadership, communication, and decision-making skills, and have a proven track record in managing third-party risk, vendor governance, or related domains
.
Responsibilitie
β’ s:Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory complianc
β’ e.Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentatio
β’ n.Coordinate with vendors to request and verify security controls, remediation plans, and ongoing complianc
β’ e.Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolutio
β’ n.Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediatio
β’ n.Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profile
β’ s.Participate in continuous security monitoring of existing suppliers to track changing risk profile
β’ s.Partner with Procurement, Legal, Privacy, and InfoSec teams to improve supplier security management processe
β’ s.Identify opportunities to automate parts of the assessment process, thereby reducing manual work and enhancing efficienc
β’ y.Keep abreast of emerging risks, industry standards, and regulatory requirements affecting third-party vendor
β’ s.Contribute to broader cybersecurity risk management initiatives, including identifying, assessing, and tracking information security risks beyond the third-party domai
β’ n.Provide guidance and knowledge transfer to team members, supporting a collaborative team environmen
t.
Preferred Qualificatio
β’ ns:Bachelorβs degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related fie
β’ ld.6-8 years of professional experience in third-party risk assessment within cybersecurity or information risk manageme
β’ nt.Understanding of relevant information security frameworks, including related regulatory compliance requirements, such as ISO 27001/2 (including ISO 27017 & 18), FedRAMP, SOC 2 Trust Services Criteria, PCI DSS, NIST C
β’ SF.Solid understanding of risk assessment methodologies and best practic
β’ es.Ability to synthesize and communicate complex risk findings to both technical and non-technical audienc
β’ es.Detail-oriented, process-driven, and capable of managing multiple vendor assessments concurrent
β’ ly.Experience with tools such as Coupa, OneTrust, JIRA and Coverbase is a pl
β’ us.Professional certifications in Information Security or Risk Management (e.g. CISA, CISM, CISSP, CRISC) is a pl
us.
Job Title: Senior Security Risk Management Analyst
Location: Remote
Duration: 6 months
Summary
:Client is seeking an experienced professional to join our Third-Party/ Vendor Risk Assessment team. This team focuses on analyzing and managing risks associated with our vendors, service providers, and other third parties, ensuring our organization upholds the highest standards of compliance, security, and business resilience. While your primary responsibility will be Third-Party Risk Management, you will also collaborate on other cybersecurity risk management initiatives. Building strong cross-functional relationships across the company is a key component of this role. To excel, you must showcase exceptional leadership, communication, and decision-making skills, and have a proven track record in managing third-party risk, vendor governance, or related domains
.
Responsibilitie
β’ s:Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory complianc
β’ e.Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentatio
β’ n.Coordinate with vendors to request and verify security controls, remediation plans, and ongoing complianc
β’ e.Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolutio
β’ n.Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediatio
β’ n.Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profile
β’ s.Participate in continuous security monitoring of existing suppliers to track changing risk profile
β’ s.Partner with Procurement, Legal, Privacy, and InfoSec teams to improve supplier security management processe
β’ s.Identify opportunities to automate parts of the assessment process, thereby reducing manual work and enhancing efficienc
β’ y.Keep abreast of emerging risks, industry standards, and regulatory requirements affecting third-party vendor
β’ s.Contribute to broader cybersecurity risk management initiatives, including identifying, assessing, and tracking information security risks beyond the third-party domai
β’ n.Provide guidance and knowledge transfer to team members, supporting a collaborative team environmen
t.
Preferred Qualificatio
β’ ns:Bachelorβs degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related fie
β’ ld.6-8 years of professional experience in third-party risk assessment within cybersecurity or information risk manageme
β’ nt.Understanding of relevant information security frameworks, including related regulatory compliance requirements, such as ISO 27001/2 (including ISO 27017 & 18), FedRAMP, SOC 2 Trust Services Criteria, PCI DSS, NIST C
β’ SF.Solid understanding of risk assessment methodologies and best practic
β’ es.Ability to synthesize and communicate complex risk findings to both technical and non-technical audienc
β’ es.Detail-oriented, process-driven, and capable of managing multiple vendor assessments concurrent
β’ ly.Experience with tools such as Coupa, OneTrust, JIRA and Coverbase is a pl
β’ us.Professional certifications in Information Security or Risk Management (e.g. CISA, CISM, CISSP, CRISC) is a pl
us.





