Third-Party Risk Analyst
Location: Remote
Compensation: To Be Discussed
Reviewed: Tue, Aug 11, 2026
This job expires in: 22 days
Job Summary
Building the vendor risk function from the ground up, the full-time Third-Party Risk Analyst will manage end-to-end security assessments for model providers and subprocessors, ensuring compliance with evolving regulations in a remote setting.
Key responsibilities
- Own and execute security assessments for vendors, facilitating timely onboarding without bottlenecks
- Design and implement the Third-Party Risk Management (TPRM) program, including intake processes, tiering, and risk acceptance
- Continuously monitor critical vendors and conduct annual reviews to ensure compliance with relevant regulations
Required qualifications
- 4+ years of experience in third-party/vendor security risk or security assessment
- Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, along with knowledge of the EU AI Act
- Technical literacy in cloud architecture, access models, and data flows
- Experience with Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs)
- Strong writing skills and ability to navigate ambiguity in regulatory environments
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 47,805 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee