Turo

Senior Vendor Security Risk Analyst

Turo • $131K — $164K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in third-party risk management, vendor security, or GRC with direct ownership of vendor security review programs.
  • Hands-on experience evaluating SOC 2 reports, ISO certificates, and penetration test results.
  • Familiarity with contract review from a security perspective, including DPAs and MSAs.
  • Working knowledge of cloud security (AWS), IAM, and data-protection principles.
  • Strong communicator, able to distill complex risk findings for non-technical stakeholders.
  • Bachelor's degree in Computer Science, Information Security, or equivalent experience.
  • Relevant certification: CISA, CISM, CISSP, or equivalent security certification.

Responsibilities

  • Own the vendor security review lifecycle, including risk tiering and remediation tracking.
  • Evaluate vendor evidence and deliver clear risk recommendations.
  • Review vendor contracts from a security standpoint and provide approval recommendations.
  • Build scalable tiering frameworks and continuous monitoring capabilities.
  • Partner with Procurement, Legal, and Privacy to integrate security review into onboarding processes.
  • Complete and maintain external partnership-facing security questionnaires.
  • Design and deliver security awareness training programs, tracking completion and effectiveness.

Benefits

  • Competitive salary, equity, benefits, and perks for all full-time employees.
  • Employer-paid medical, dental, and vision insurance.
  • Retirement employer match.
  • Learning & Development stipend for professional development.
  • Turo host matching program and travel credit.
  • Cell phone and internet stipend.
  • Paid time off to relax and recharge, along with paid holidays and volunteer time off.
  • In-office lunch, snacks, and fun activities for hybrid employees.
Full Job Description
What you will do

  • Own the vendor security review lifecycle: intake, risk tiering, due diligence, findings documentation, remediation tracking, and renewals.
  • Evaluate vendor evidence: SOC 2 reports, ISO certificates, pen-test results, and security questionnaires - deliver clear risk recommendations.
  • Review vendor contracts, DPAs, and MSAs from a security standpoint; provide approval recommendations before contracts are signed.
  • Build scalable tiering frameworks, intake workflows, and continuous monitoring capabilities that grow with vendor volume.
  • Partner with Procurement, Legal, and Privacy to integrate security review into onboarding and renewal cycles without becoming a bottleneck.
  • Complete and maintain external partnership-facing security questionnaires and trust-center content in support of integrations.
  • Partner with Security team members to design and deliver security awareness training programs, including role-specific content on phishing, social engineering, third-party risk, and data handling.
  • Track training completion and effectiveness; align program content with TPRM findings and emerging threats.
  • Partner with IT and Security teams to design and run quarterly user access review campaigns, ensuring timely completion, accurate certification decisions, and clear remediation of access exceptions.
  • Report on TPRM, training, and access review metrics to security leadership: cycle time, open findings, remediation aging, and completion rates.


Your profile

  • 5+ years in third-party risk management, vendor security, or GRC, with direct ownership of vendor security review programs.
  • Hands-on experience evaluating SOC 2 reports, ISO certificates, and penetration test results, and translating findings into business-ready risk recommendations.
  • Familiarity with contract review from a security perspective (e.g., DPAs & MSA) and comfort working with Legal and Procurement. 
  • Working knowledge of cloud security (AWS), IAM, and data-protection principles.
  • Strong communicator: able to distill complex risk findings for non-technical stakeholders at all levels.
  • Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience.
  • Relevant certification: CISA, CISM, CISSP, or equivalent security certification.
  • Experience with TPRM or GRC tooling (e.g., Vanta, Drata, ZenGRC) and security-automation platforms.
  • Experience developing or delivering security awareness training, including content creation or phishing simulation.
  • Background in a regulated or high-trust industry - fintech, marketplace, or SaaS handling sensitive data.


For this role, the target base salary range in San Francisco is $131,000-$164,000 annually. This role is also eligible for equity and benefits. In general, our ranges reflect the market-based target for new hire salaries based on the level and location of the role. Within the range, individual pay is determined by objective factors assessed during the application and interview process, such as job-related skills, experience, and relevant education or training. We encourage you to talk with your recruiter to learn more about the total compensation and benefits available for this role.


Turo highly values having employees working in-office to foster a collaborative work environment and company culture. This is central to how we work, and this role will be subject to our current in-office hybrid schedule that requires Turists to work in the office three days per week on Mondays, Wednesdays, and Thursdays. We expect that employees will meet these required in-office days consistently as part of their role. Your recruiter can share more information about this requirement and the in-office perks Turo offers.

Benefits
  • Competitive salary, equity, benefits, and perks for all full-time employees

  • Employer-paid medical, dental, and vision insurance (Country specific)

  • Retirement employer match

  • Learning & Development stipend to invest in your professional development

  • Turo host matching program

  • Turo travel credit

  • Cell phone and internet stipend

  • Paid time off to relax and recharge

  • Paid holidays, volunteer time off, and parental leave

  • For those who are in the office full-time or hybrid we have in-office lunch, office snacks, and fun activities

We are committed to building a diverse team. If you are from a background that's underrepresented in tech, we'd love to meet you.

Aside from an award winning work environment and the opportunity to be part of the world’s largest car sharing marketplace, we are also growing the team quickly - join us!  Even if you don't meet every qualification, we are looking for people with enthusiasm for what we do and we will consider you for this and other possibilities.

About Turo

Turo is a peer-to-peer car sharing company headquartered in San Francisco, California. The company was founded in 2009 by Shelby Clark and has since grown to over 10 million users in over 5,500 cities worldwide. Turo allows car owners to rent out their personal vehicles to other users, providing an alternative to traditional car rental companies. The company offers a variety of vehicles, from economy cars to luxury vehicles and sports cars.
Learn more about Turo
Size
200 employees
Industry
Founded
2009

Similar Jobs

More Jobs at Turo

More Information Technology Jobs

Find similar Senior Vendor Security Risk Analyst jobs: