GRC Vendor Risk Consultant

Prophecy Technologies

• $110K — $130K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-10 years of experience in cybersecurity and governance, risk, and compliance (GRC) roles.
  • Expertise in vendor and third-party risk assessments.
  • Experience with SOC 2 analysis and compliance processes.
  • Knowledge of ISO 27001 and enterprise security frameworks.
  • Proficiency with risk management platforms like RSA Archer and ServiceNow.
  • Strong ability to conduct technical security reviews of cloud architectures.
  • Excellent communication skills for interacting with diverse stakeholders.

Responsibilities

  • Lead comprehensive third-party vendor risk assessments across various environments.
  • Identify control gaps and recommend effective risk mitigation strategies.
  • Perform in-depth technical security reviews of applications and architectures.
  • Conduct hands-on SOC 2 analysis, ensuring control design and effectiveness.
  • Ensure alignment with security policies and frameworks like SOC 2 and ISO 27001.
  • Manage risk lifecycle activities using GRC and risk intelligence platforms.
  • Develop and report risk metrics and insights to senior leadership.

Benefits

  • Opportunities for professional development and skill enhancement.
  • Work with cutting-edge security technologies and frameworks.
  • Collaborative environment fostering innovation and knowledge sharing.
  • Access to various GRC and risk intelligence tools for daily tasks.
  • Engagement in meaningful risk management initiatives that have organizational impact.
Full Job Description
Role Overview:

This role involves leading and executing comprehensive third-party vendor risk assessments across various technological and supply chain environments. The consultant will be responsible for identifying control gaps, recommending mitigation strategies, and performing deep technical security reviews of solutions and cloud architectures. A key aspect is conducting hands-on SOC 2 analysis and ensuring alignment with enterprise security policies and frameworks like ISO 27001.

Key Responsibilities:
  • Lead and execute end-to-end third-party vendor risk assessments across technology, supply chain, SaaS, and hybrid environments, identifying control gaps and recommending risk mitigation strategies.
  • Perform deep technical reviews of solution, application, and solution architectures, security controls, and cloud solutions from a security engineering perspective, translating findings into actionable remediation guidance.
  • Conduct hands-on SOC 2 analysis, evaluate control design and operating effectiveness, and clearly articulate control gaps and risk impacts to stakeholders.
  • Ensure alignment of third-party assessments and internal practices with enterprise security policies, data protection standards, and frameworks such as SOC 2 and ISO 27001.
  • Leverage and administer GRC and risk intelligence platforms such as RSA Archer, Onspring, BitSight, UpGuard, SecurityScorecard, ServiceNow, or similar tools to manage risk lifecycle activities.
  • Coordination with business partners such as Legal, Procurement, IT, Privacy, Audit, and Security Operations to drive timely assessment completion and remediation tracking.
  • Develop and report meaningful risk metrics and program insights to leadership, demonstrating effectiveness and continuous improvement of the TPRM program.
  • Contribute to the development, enhancement, and rationalization of information security policies, standards, and exception processes based on risk findings and industry best practices.
  • Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders, building trusted relationships across business units.

Required Skills:
  • GRC - Vendor risk assessment / Third-party risk assessment expertise.
  • Cyber Security - GRC - Data Security.
  • Experience with SOC 2 analysis and compliance.
  • Knowledge of ISO 27001 and enterprise security policies.
  • Proficiency with GRC and risk intelligence platforms (e.g., RSA Archer, Onspring, BitSight, UpGuard, SecurityScorecard, ServiceNow).
  • Ability to perform deep technical security reviews of architectures and cloud solutions.
  • Strong communication skills for technical and non-technical stakeholders.

Qualifications:
  • 8-10 Years of experience in cyber security and GRC roles.

Similar Jobs

More Jobs at Prophecy Technologies

More Information Technology Jobs

Find similar GRC Vendor Risk Consultant jobs: