Jobs and Careers
ST

Vendor Risk Specialist

Stride, Inc.
United StatesRemotefull_timeVerifiedPosted 15 Nov 2024
💰 $170,038/yr($66,380/yr$170,038/yr)

About the role

Job Description

The Vendor Risk Specialist is responsible for implementing, maintaining, managing, and operating vendor risk management platforms & capabilities. The Specialist delivers these capabilities in accordance with the organization’s architectural designs, best practices, and regulatory or compliance requirements. As risks change, the Specialist is responsible for recommending modifications and enhancements to ensure the organization is evolving with the threat landscape.  

The Vendor Risk Specialist is expected to conduct risk assessments and audits of the organization’s vendors' security program, environments, systems, infrastructure, and applications.   The role is responsible for providing detailed reports of technical and procedural findings and recommendations.  Recipients of the Specialist’s reports include business functions, purchasing, security, audit, and external stakeholders.

ESSENTIAL FUNCTIONS Reasonable accommodations may be made to enable individuals with disabilities to perform the essential duties.

  • Maintain knowledge of applicable policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Conduct third-party risk assessments to assist in determining their ability to protect confidential and sensitive data
  • Examine and research security controls and frameworks as it relates to vendor risk management
  • Administer the vendor risk management process and make confident risk recommendations with respect to the integrity and business stability of new vendors or vendors nearing contract renewal
  • Evaluate applicable security controls to apply against vendor services being provided and the applicability of compensating controls for vendor security assessments
  • Collect, analyze, interpret, evaluate, and integrate risk data from multiple sources to conduct a comprehensive analysis.
  • Maintain relationships with the third parties to ensure compliance, requesting an audit, tests, or other evidence
  • Maintain an inventory of in‐scope vendor artifacts and report their compliance status as required by stakeholders, management, review boards, regulatory bodies, and auditors as necessary
  • Act as a subject matter expert, and liaise with key business and technology stakeholders to ensure compliance expectations are realized in a timely manner
  • Develop security deliverables based on the security documentation that is provided by the vendor
  • Maintain a security risk register.
  • Identify opportunities for process improvements to deliver increased operational efficiency in the vendor security oversight processes
  • Maintains an up-to-date understanding of industry best practices
  • Distribution and interpretation of compliance questionnaires, analyzing vendor audit reports from various sources, and engaging vendor representatives for additional details regarding security controls

Supervisory Responsibilities: This position has no formal supervisory responsibilities.

Certificates and Licenses: None Required

MINIMUM REQUIRED QUALIFICATIONS 

  • Five (5) years of experience in cybersecurity/IT with a strong focus on the analysis of security programs or controls
  • Understanding of risk assessments and compliance with major regulatory initiatives (e.g.  SOX, PCI-DSS, HIPAA, FedRAMP)
  • Understanding of cyber security and information security program management and frameworks (e.g., NIST CSF, ISO/IEC 27000)
  • Possess a good understanding of appropriate leading-edge governance-enabling technologies & practices.
  • Strong demonstrated ability to gain consensus and support across diverse functions and departments.
  • Excellent communication and presentation skills (verbal and written).
  • Project management planning and organization skills.
  • Ability to identify, document, and communicate information security issues to business and information owners
  • Ability to maintain the confidentiality of sensitive information
  • Microsoft Office (Outlook, Word, Excel, PowerPoint, Project, Visio, etc.); Web proficiency.
  • Ability to travel 5% of the time
  • Ability to clear required background check

DESIRED QUALIFICATIONS:  

  • Bachelor’s degree in Computer Science, Information Assurance, MIS, Business, or related field
  • Prior experience with vendor, contract, and/or program risk assessments
  • Prior work experience in a regulated environment; education organization experience desired.
  • Ability to establish good working relationships with team members, colleagues, and external organizations. 
  • Demonstrable abi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Stride, Inc.

View company profile →