Sr. Technology Risk Analyst

Sungrow USA Corporation US,
$0 - $160,000

About The Position

Sungrow Americas is seeking a Senior Technology Risk Analyst to support the execution and continuous improvement of the organization's Risk Management program. Working under the direction of the Third-Party Risk Management Lead and in partnership with the Governance, Risk & Compliance (GRC) Manager, this role is responsible for performing vendor security assessments, reviewing security evidence, validating third-party controls, coordinating remediation activities, and maintaining a mature, auditable vendor risk management program. The ideal candidate possesses strong experience reviewing security documentation, collaborating across Procurement, Legal, IT, Engineering, Product Security, and business stakeholders, and translating complex technical findings into practical business risk. This position plays a key role in strengthening Sungrow's cybersecurity posture across SaaS, cloud, operational technology (OT), software suppliers, manufacturing partners, and strategic service providers supporting critical infrastructure operations.

Requirements

  • Strong experience reviewing security documentation
  • Collaborating across Procurement, Legal, IT, Engineering, Product Security, and business stakeholders
  • Translating complex technical findings into practical business risk

Responsibilities

  • Execute Sungrow's Third-Party Risk Management lifecycle, including vendor onboarding, periodic reassessments, contract renewals, and offboarding.
  • Perform vendor intake reviews to determine inherent risk, business criticality, data sensitivity, connectivity, and regulatory impact.
  • Maintain the enterprise vendor inventory, vendor classifications, and risk tiering methodology.
  • Coordinate vendor assessment schedules and ensure timely completion of required reviews.
  • Conduct security assessments for software vendors, cloud providers, managed service providers, professional services firms, product suppliers, and strategic third parties.
  • Review and evaluate: SOC 2 Type II reports, ISO 27001 certifications, Penetration test summaries, Security questionnaires (SIG, CAIQ, custom), Security policies and standards, Business Continuity and Disaster Recovery documentation, Privacy and data protection controls.
  • Identify control gaps, residual risks, and recommended mitigation strategies.
  • Validate vendor controls against Sungrow security requirements and applicable regulatory frameworks.
  • Monitor vendor security posture throughout the vendor lifecycle.
  • Track remediation commitments and coordinate follow-up activities through closure.
  • Monitor vendor certifications, attestations, and supporting documentation for expiration and renewal.
  • Maintain accurate vendor risk records within the organization's GRC platform.
  • Assist in identifying changes in vendor ownership, subcontractors, or security posture that may affect organizational risk.
  • Maintain complete, accurate, and audit-ready documentation supporting Sungrow's Third-Party Risk Management program.
  • Support customer security assessments by providing vendor assurance documentation and supporting evidence.
  • Prepare reports and operational metrics covering: Assessment completion, Vendor inventory, Remediation status, Assessment aging, High-risk vendors, Outstanding exceptions.
  • Support internal audits, customer reviews, and regulatory inquiries.
  • Partner with Procurement and Legal during vendor onboarding and contract renewals.
  • Review vendor security documentation supporting contractual security obligations.
  • Validate vendor compliance with contractual security requirements including: Incident notification, Encryption, Access control, Data protection, Business continuity, Audit rights.
  • Escalate material risks requiring management review.
  • Review vendor Business Continuity and Disaster Recovery capabilities during security assessments.
  • Maintain Business Impact Analysis (BIA) documentation related to critical third-party services.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service