A company is looking for a Third Party Risk Analyst to safeguard its ecosystem from third-party security risks.
Key Responsibilities
Conduct vendor risk reviews and evaluate third-party attestations such as SOC 2 and ISO 2700x
Analyze vendor contracts to identify potential risk clauses and data security implications
Support annual high-risk vendor audits and maintain compliance documentation
Required Qualifications
5-8+ years of experience in information security, vendor risk management, or related technical risk roles
Strong understanding of security frameworks and certifications (SOC 2, ISO 2700x, NIST, etc.)
Familiarity with authentication, disaster recovery, and infrastructure security concepts
Ability to interpret and challenge vendor-provided attestations and control summaries
Comfort reviewing contracts and identifying clauses impacting data handling or access control
Third Party Risk Analyst • Renton, Washington, United States