TPRM Security Assessor
We are seeking an experienced TPRM Security Assessor to join our global security team. In this role, you will support our efforts in assessing and managing cybersecurity risks associated with third-party vendors and suppliers. This is an excellent opportunity for individuals with a background in Third-Party Risk Management, Information Security, Cybersecurity Risk, IT Audit, or GRC who enjoy evaluating security controls and collaborating with both technical and business stakeholders.
Key Responsibilities
- Conduct third-party/vendor security assessments and due diligence.
- Review vendor security questionnaires and supporting evidence.
- Assess supplier controls across several areas, including:
- Access Management
- Vulnerability Management
- Incident Response
- Business Continuity
- Security Monitoring
- Data Protection
- Review security assurance documentation such as SOC 2, ISO 27001, CAIQ, and SIG.
- Identify security gaps, risks, and control weaknesses.
- Document assessment findings and support risk remediation.
- Communicate findings and requirements clearly to vendors and internal stakeholders.
- Work closely with Security, Risk, Procurement, Legal, and other business teams.
- Support ongoing vendor reassessments and third-party risk activities.
Requirements
- 2+ years of experience in TPRM, Information Security, Cybersecurity Risk Management, IT Audit, or GRC.
- Hands-on experience conducting vendor/supplier security assessments.
- Strong understanding of cybersecurity controls and risk management.
- Experience reviewing security questionnaires and assurance reports.
- Knowledge of SOC 2, ISO 27001, CAIQ, and/or SIG.
- Excellent analytical, written, and verbal communication skills.
- Strong stakeholder management abilities.
- Capability to assess security risks and effectively communicate findings to both technical and non-technical audiences.
Desirable Certifications
- CRISC
- CISA
- CISSP
- ISO 27001 Lead Auditor
- CTPRP
Location
Poland, with a preference for Warsaw.
If you’re a TPRM, Vendor Risk, GRC, or Cybersecurity Risk professional looking for your next opportunity, apply online using the form below. Please note that only applications matching the job profile will be considered.
Work locationEastern Europe, Poland, Switzerland