Job opportunity

TPRM Security Assessor / TPRM Security Assessoress

Red Commerce Schweiz GmbH Eastern Europe, Poland September 30, 2026

TPRM Security Assessor

We are seeking an experienced TPRM Security Assessor to join our global security team. In this role, you will support our efforts in assessing and managing cybersecurity risks associated with third-party vendors and suppliers. This is an excellent opportunity for individuals with a background in Third-Party Risk Management, Information Security, Cybersecurity Risk, IT Audit, or GRC who enjoy evaluating security controls and collaborating with both technical and business stakeholders.

Key Responsibilities

  • Conduct third-party/vendor security assessments and due diligence.
  • Review vendor security questionnaires and supporting evidence.
  • Assess supplier controls across several areas, including:
    • Access Management
    • Vulnerability Management
    • Incident Response
    • Business Continuity
    • Security Monitoring
    • Data Protection
  • Review security assurance documentation such as SOC 2, ISO 27001, CAIQ, and SIG.
  • Identify security gaps, risks, and control weaknesses.
  • Document assessment findings and support risk remediation.
  • Communicate findings and requirements clearly to vendors and internal stakeholders.
  • Work closely with Security, Risk, Procurement, Legal, and other business teams.
  • Support ongoing vendor reassessments and third-party risk activities.

Requirements

  • 2+ years of experience in TPRM, Information Security, Cybersecurity Risk Management, IT Audit, or GRC.
  • Hands-on experience conducting vendor/supplier security assessments.
  • Strong understanding of cybersecurity controls and risk management.
  • Experience reviewing security questionnaires and assurance reports.
  • Knowledge of SOC 2, ISO 27001, CAIQ, and/or SIG.
  • Excellent analytical, written, and verbal communication skills.
  • Strong stakeholder management abilities.
  • Capability to assess security risks and effectively communicate findings to both technical and non-technical audiences.

Desirable Certifications

  • CRISC
  • CISA
  • CISSP
  • ISO 27001 Lead Auditor
  • CTPRP

Location

Poland, with a preference for Warsaw.

If you’re a TPRM, Vendor Risk, GRC, or Cybersecurity Risk professional looking for your next opportunity, apply online using the form below. Please note that only applications matching the job profile will be considered.

Work locationEastern Europe, Poland, Switzerland

Application Form

Please enter your information in the following form and attach your resume (CV)

Only pdf, Word, or OpenOffice file. Maximum file size: 3 MB.