About The Position

The key objectives of the TPRM Program are to: Assess the risk of third-party relationships which drive the rigor of risk management activities both during the third-party onboarding and ongoing monitoring lifecycle phases using the TPRM Program’s formula-based risk methodology; Act as a liaison across key internal stakeholder teams (Procurement, Legal, Enterprise Security and the Business) to ensure clear and accurate communication of third-party risks aligned to risk management activities in order to complete risk assessments in a timely manner; Identify TPRM program enhancements aimed at the effective and efficient management of third-party risk in order to support Business strategic initiatives. Reporting to the TPRM Manager and working closely with the TPRM Risk Analyst, the Associate TPRM Risk Analyst will support day-to-day execution of the third-party risk lifecycle. This is a support-oriented analyst role focused on applying established TPRM procedures and risk methodology to standard engagements, maintaining complete and accurate assessment records, coordinating routine stakeholder activity, and escalating issues that require additional judgment.

Requirements

  • 3-5 years of experience in Third-Party Risk Management (TPRM) or Governance, Risk & Compliance (GRC)
  • Demonstrated experience performing substantive risk assessments and applying formula-based or quantitative risk methodologies
  • Bachelor’s degree in a relevant field (Cybersecurity, Business, Information Systems).
  • Proficiency with a TPRM platform, including the ability to interpret intake data, Data Level classifications, and inherent risk scoring logic.
  • Operational understanding of standard control frameworks (NIST SP 800-53, ISO 27001, SOC 2, SIG Core/Lite, CAIQ).
  • Working knowledge of regulatory requirements relevant to the third-party population (e.g., DORA, GDPR, NIS2, FedRAMP, PCI-DSS, OCC, CCPA).
  • Attention to Detail: ability to gather and check third-party documentation accurately against TPRM methodology.
  • Communication: clear, professional communication with third parties and internal stakeholders on lower-risk gaps.
  • Reliability: ability to manage a defined queue of onboarding and periodic review tasks and escalate appropriately.

Responsibilities

  • Apply the TPRM Program’s formula-based inherent risk methodology and assign Criticality designations for standard third-party relationships, documenting the inputs, rationale, and supporting evidence
  • Perform completeness and consistency checks on intake information, risk calculations, and assessment records; identify missing, inconsistent, or unclear information and escalate exceptions in accordance with defined thresholds.
  • Gather, organize, and maintain third-party-provided information and documentation in accordance with TPRM assessment methodology and audit-readiness expectations.
  • Identify and route required SME reviews using defined risk triggers, track responses, and document completed SME assessments and supporting evidence.
  • Maintain accurate and timely records in Graphite Connect, Jira, and other approved systems of record.
  • Support execution of third-party risk assessment remediation of identified gaps or findings based on defined risk triggers to obtain complete responses and supporting documentation.
  • Support routine communication with third parties to resolve identified gaps, with primary responsibility for Medium-Risk and Low-Risk remediation activities.
  • Track remediation actions, due dates, and supporting evidence; escalate High Risk, Critical, overdue, or otherwise judgment-intensive gaps.
  • Support the third-party periodic review process, including leading communication to third parties to remediate identified gaps; escalate any gaps.
  • Compile assessment-level data, SME review status, remediation activity, and other required information to support standard status and portfolio reporting.
  • Perform data-quality checks and identify field-level trends, recurring documentation gaps, or process issues for review.
  • Prepare routine status updates and supporting materials for internal stakeholder discussions.

Benefits

  • equity
  • participation in the employee stock purchase program
  • flexible paid time off
  • 20 weeks fully-paid gender-neutral parental leave
  • fertility and adoption assistance
  • 401(k) plan
  • mental health counseling
  • access to transgender-inclusive health insurance coverage
  • health benefits offerings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service