Hudson Information Technology and Manpower Services Logo

Hudson Information Technology and Manpower Services

Third-Party Risk Management - Cybersecurity

Posted 2 Days Ago
Be an Early Applicant
Hybrid
Austin, TX, USA
Senior level
Hybrid
Austin, TX, USA
Senior level
Manage the end-to-end lifecycle of supplier cybersecurity risk assessments, including inventory governance, assessment coordination, evidence review, findings management, corrective action plans, remediation tracking, escalations, stakeholder communications, and executive reporting. The role requires expertise with TPRM/GRC frameworks, platforms, high-volume workflows, and supplier risk remediation programs.
The summary above was generated by AI

Job Description:

GRC TPRM Assessment and Remediation SME

We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert (SME) to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation.

The role will be responsible for supplier inventory governance, assessment coordination, findings management, remediation tracking, escalation management, and executive reporting. The ideal candidate will have strong TPRM/GRC expertise, excellent communication skills, and experience managing high-volume, multi-step risk assessment workflows.

Location: Austin, TX / Cupertino, CA
Work Model: Hybrid – 3 Days a Week Onsite
Duration: 12+ Months Contract

Key Responsibilities

1. Supplier Inventory Management

  • Maintain the Supplier Inventory within the GRC platform as the single source of truth for assessment status.

  • Tier and filter suppliers requiring reassessment versus new assessments based on program criteria.

  • Maintain accurate Direct Responsible Individual (DRI) records within the GRC tool.

2. Assessment Execution

  • Evaluate suppliers against established frameworks and standards, including:

    • SIG

    • CAIQ

    • NIST CSF

    • ISO 27001

    • SOC 2

  • Review and validate supplier evidence, including audit reports, certifications, penetration test results, and other security documentation.

  • Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.

  • Log and track assessment tasks in workflow/tracking tools, including acknowledgement evidence.

  • Verify that onsite-assessed suppliers have current-year assessment coverage.

  • Participate in recurring findings-review meetings and provide guidance on policy requirements and evidence standards.

3. Remediation Management

  • Own Corrective Action Plans (CAPs) from initiation through closure.

  • Define remediation SLAs and track progress against established timelines.

  • Drive remediation closure with suppliers and internal business owners.

  • Coordinate with Legal, Procurement, and Information Security (InfoSec) teams regarding remediation timelines and compensating controls.

  • Monitor open findings and ensure appropriate documentation and evidence are maintained.

4. Stakeholder Communication & Escalation

  • Manage a structured outreach cadence with DRIs, including:

    • Initial kick-off

    • Follow-up communications

    • Management escalations

  • Track response and non-response rates for each outreach cycle.

  • Escalate unresolved or high-risk findings to appropriate leadership.

  • Maintain clear documentation of all communications, decisions, and remediation activities.

  • Build and maintain strong relationships with business stakeholders and suppliers.

5. Weekly Reporting

  • Prepare and deliver weekly metrics and status reports for leadership.

  • Track and report:

    • Outreach volume

    • Supplier response rates

    • Follow-up and escalation status

    • Suppliers approved for new assessments or reassessments

    • Assessment completion and coverage

    • Open findings and remediation status

    • Overall TPRM program progress

Required Qualifications

  • 5+ years of experience in Cybersecurity, Third-Party Risk Management (TPRM), GRC Operations, Supplier Risk, or a related field.

  • Strong working knowledge of:

    • NIST CSF

    • ISO 27001

    • SOC 2

    • SIG

    • CAIQ

  • Hands-on experience with GRC/TPRM platforms, such as:

    • OneTrust

    • RSA Archer

    • ServiceNow GRC

    • SupplierNinja

    • or similar platforms

  • Proven experience managing high-volume, multi-step communication and assessment workflows.

  • Strong findings and remediation management experience.

  • Excellent written and verbal communication skills.

  • Strong documentation, organization, and follow-through skills.

  • Experience working with distributed or remote teams.

  • Ability to communicate effectively with business stakeholders, suppliers, and leadership.

Preferred Qualifications

  • Relevant certification such as CTPRP, CRISC, CISA, or CISSP.

  • Experience with workflow and tracking tools such as:

    • Wrike

    • Airtable

    • Jira

    • or similar platforms

  • Experience working in regulated industries such as:

    • Financial Services

    • Healthcare

    • Insurance

  • Experience preparing leadership-facing metrics, dashboards, and weekly reports.

  • Experience managing supplier cybersecurity assessments and remediation programs in a large enterprise environment.

Similar Jobs

An Hour Ago
Remote or Hybrid
US
175K-175K Annually
Expert/Leader
175K-175K Annually
Expert/Leader
Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Lead the architecture, development, and scaling of data pipelines and infrastructure for a customer-facing Data Lake platform. Build ETL and ingestion systems using GCP, Debezium, Pub/Sub, Dataflow, BigQuery, Python, Golang, and SQL. Establish engineering standards, deliver strategic projects, mentor engineers, influence cross-functional technical decisions, optimize data services, and shape the platform roadmap.
Top Skills: BigQueryCi/CdConfluenceDataflowDebeziumGoGoogle Cloud Platform (Gcp)JIRAPub/SubPythonRest ApisScrumSQL
3 Hours Ago
Hybrid
29K-48K Hourly
Internship
29K-48K Hourly
Internship
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Audit Interns support financial statement audits by reviewing financial documents, analyzing financial data, documenting audit procedures and findings, evaluating internal controls, and applying GAAP and GAAS. The role provides foundational exposure to audit methodologies, financial reporting, risk assessment, client service, and professional collaboration while developing accounting and data analysis skills.
54K-104K Annually
Entry level
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Supports client assurance engagements involving data analytics, ERP integration, IT controls, business process improvement, and technology solutions. Assists with audit and assurance services, interprets data, develops recommendations, evaluates financial and non-financial information, and helps clients meet regulatory requirements. The role is designed for students or recent graduates developing technical, analytical, and client-service skills.
Top Skills: Artificial IntelligenceData AnalyticsErp SystemsIt Controls

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account