Job TitleResponsibilitiesReview incoming documents from suppliers (e.g., SOC 2 Type II reports, high level system architecture diagrams, information security policies)Consult with other shared service departments, as appropriate (e.g., Procurement, Privacy, Operational Risk, Legal)Compile information into a summary report, highlighting concerns in the form of a risk report/profile for a supplier or particular engagementMonitor key supplier changes and risk indicatorsIssue monitoring, exception tracking and oversight of remediation actions to improve overall supplier performanceDefine, measure and monitor progress of supplier risk management activities (Issue Tracking, Risk Remediation Efforts, Key Supplier Metrics)Create reporting materials detailing program activities, supplier metrics and issue remediationMaintain supplier data accuracy within designated systemsProvide guidance and training to stakeholders on supplier risk management policies and proceduresRequirementsBachelor’s degree in Business Information Systems, Computer Science or similarMinimum four years related experience, including at least two years of third party risk management experience conducting risk or compliance assessmentsUnderstanding of information security frameworks and standards (e.g., NIST 800-171, ISO27002/27002, PCI, GDPR)Ability to document and communicate assessment results clearly and conciselyKnowledge of supplier risk management methodologies, risk mitigation principlesAbility to work both independently and as part of a team to deliver quality workAttention to detail, and the ability to prioritize works efficiently and effectivelyNice to haveExperience with OneTrustSecurity-related certifications (CISA, CISM, CISSP, SANS GIAC)Higher education and/or research institution experienceUnderstanding of higher education legal and regulatory environment