Unknown Company

REMOTE Supplier Risk Analyst

irvine, ca • Posted 5 days ago
Onsite Full Time General

Supplier Risk AnalystThe Supplier Risk Analyst will be responsible for reviewing supplier documents, consulting with appropriate departments and compiling information into a summary for the teams use.ResponsibilitiesCoordinate and perform supplier security risk reviews:Review incoming documents from Suppliers (e.g., SOC 2 Type II reports, high level system architecture diagrams, information security policies)Consult with other shared service departments, as appropriate (e.g., Procurement, Privacy, Operational Risk, Legal)Compile information into a summary report, highlighting concerns in the form of a risk report/profile for a supplier or particular engagementSupport reporting and analysis of supplier security risk:Monitor key supplier changes and risk indicators.Issue monitoring, exception tracking and oversight of remediation actions to improve overall Supplier performanceDefine, measure and monitor progress of supplier risk management activities (Issue Tracking, Risk Remediation Efforts, Key Supplier Metrics)Create reporting materials detailing program activities, supplier metrics and issue remediationMaintain supplier data accuracy within designated systems.Provide guidance and training to stakeholders on supplier risk management policies and procedures.Experience:Bachelor’s degree in Business Information Systems, Computer Science or similar.Minimum four years related experience, including at least two years of third party risk management experience conducting risk or compliance assessmentsUnderstanding of information security frameworks and standards (e.g., NIST 800-171, ISO27002/27002, PCI, GDPR)Ability to document and communicate assessment results clearly and conciselyKnowledge of supplier risk management methodologies, risk mitigation principlesAbility to work both independently and as part of a team to deliver quality workAttention to detail, and the ability to prioritize works efficiently and effectivelyNice to haveExperience with ServiceNow and/or OneTrust.Security-related certifications (CISA, CISM, CISSP, SANS GIAC)Higher education and/or research institution experienceUnderstanding of higher education legal and regulatory environment (e.g.

Back to Job Search