Senior TPRM Analyst

Evolution Cloud Services (EVOCS)Denver, CO
$90,000 - $105,000Remote

About The Position

As a Senior TPRM Analyst, you are the experienced hand on the third-party risk team. You own the complex vendor reviews — the cloud providers, MSPs, and critical technology vendors where a shallow assessment creates real exposure — and you are the person escalations land on when a finding is contested or a risk needs to be accepted at the leadership level. You are also the one who writes what goes up. Executive-ready risk summaries, escalation memos, and risk acceptance recommendations come from you, and they need to be right the first time. This is a senior individual contributor role: depth of judgment, not headcount, is what makes you effective here. We are hiring two Senior TPRM Analysts.

Requirements

  • 7+ years of experience in cybersecurity, risk, audit, or compliance
  • At least 5 of those years in third-party risk management or vendor risk specifically
  • Demonstrated experience assessing cloud providers, MSPs, and critical technology vendors — not only routine or low-criticality suppliers
  • Fluency reading SOC 2 reports and ISO 27001 certifications, including the ability to identify scope carve-outs, qualified opinions, and control exceptions
  • Fourth-party and supply chain risk analysis: vendor concentration, criticality tiering, geopolitical exposure, and subcontractor dependencies
  • Proven ability to write executive-ready risk summaries for senior audiences
  • Experience leading escalation and risk acceptance conversations with senior stakeholders, including holding a position under pressure
  • Working knowledge of common control frameworks — NIST CSF, NIST 800-53, ISO 27001/27002, CIS — and how they map to vendor assessments
  • Strong interpersonal and communication skills — this role involves frequent interaction with vendors and internal stakeholders via email, calls, and meetings

Nice To Haves

  • Certifications that matter here: CTPRP or CTPRA especially, along with CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor
  • Hands-on platform experience with ProcessUnity, ServiceNow GRC, or Archer
  • Working experience with security ratings tools such as SecurityScorecard, BitSight, RiskRecon, or Black Kite
  • Exposure to regulated environments and the vendor oversight expectations that come with them
  • Experience contributing to TPRM program design, not only executing assessments

Responsibilities

  • Own end-to-end risk assessments for the highest-criticality third parties, including cloud service providers, managed service providers, and critical technology vendors
  • Read SOC 2 Type II reports and ISO 27001 certificates for what they actually say — scope carve-outs, excluded systems, qualified opinions, exceptions in the testing results, and complementary user entity controls — rather than confirming that a document exists
  • Evaluate control evidence, penetration test summaries, remediation plans, and security questionnaire responses, and challenge answers that do not hold up
  • Set inherent and residual risk ratings, define compensating controls, and track remediation commitments to closure
  • Assess vendor security posture in context: data classification, access model, integration depth, and business criticality
  • Map fourth-party and subcontractor dependencies behind critical vendors, including where the work is actually performed
  • Analyze vendor concentration risk and identify single points of failure across the third-party portfolio
  • Assess geopolitical and jurisdictional exposure, including offshore delivery locations, data residency, and sub-processor chains
  • Incorporate security ratings and continuous monitoring signals into ongoing vendor risk views, and separate real signal from noise
  • Serve as the escalation point for contested findings, vendor pushback, and time-pressured reviews tied to contract or go-live deadlines
  • Write executive-ready risk summaries that state the risk, the business impact, and the recommendation in language leadership can act on
  • Run risk acceptance conversations with senior business, technology, and procurement stakeholders — documenting the decision, the owner, and the expiration
  • Present third-party risk posture, trends, and exceptions to governance forums and senior leadership
  • Support and improve the TPRM program itself: assessment standards, tiering criteria, evidence requirements, and playbooks that raise the floor for the whole team
  • Mentor junior analysts on evidence review, write-up quality, and stakeholder handling

Benefits

  • Customer-centric Solutions
  • Innovation & Excellence
  • Integrity & Transparency
  • Data-driven Decision Making
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service