Senior Vendor Security Risk Analyst

Turo•San Francisco, CA
•$131,000 - $164,000•Hybrid

About The Position

Turo is searching for a highly motivated and versatile Senior Vendor Security Risk Analyst under the Enterprise Security team to own Turo's third-party security risk management (TPRM) program and partners with Security teammates to lead security awareness training and user access review campaigns. You will assess and manage vendor risk end-to-end, build scalable review processes, and help strengthen Turo's security culture. You will operate with significant autonomy across Procurement, Legal, Privacy, IT, and the business.

Requirements

  • 5+ years in third-party risk management, vendor security, or GRC, with direct ownership of vendor security review programs.
  • Hands-on experience evaluating SOC 2 reports, ISO certificates, and penetration test results, and translating findings into business-ready risk recommendations.
  • Familiarity with contract review from a security perspective (e.g., DPAs & MSA) and comfort working with Legal and Procurement.
  • Working knowledge of cloud security (AWS), IAM, and data-protection principles.
  • Strong communicator: able to distill complex risk findings for non-technical stakeholders at all levels.
  • Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience.
  • Relevant certification: CISA, CISM, CISSP, or equivalent security certification.

Nice To Haves

  • Experience with TPRM or GRC tooling (e.g., Vanta, Drata, ZenGRC) and security-automation platforms.
  • Experience developing or delivering security awareness training, including content creation or phishing simulation.
  • Background in a regulated or high-trust industry - fintech, marketplace, or SaaS handling sensitive data.

Responsibilities

  • Own the vendor security review lifecycle: intake, risk tiering, due diligence, findings documentation, remediation tracking, and renewals.
  • Evaluate vendor evidence: SOC 2 reports, ISO certificates, pen-test results, and security questionnaires - deliver clear risk recommendations.
  • Review vendor contracts, DPAs, and MSAs from a security standpoint; provide approval recommendations before contracts are signed.
  • Build scalable tiering frameworks, intake workflows, and continuous monitoring capabilities that grow with vendor volume.
  • Partner with Procurement, Legal, and Privacy to integrate security review into onboarding and renewal cycles without becoming a bottleneck.
  • Complete and maintain external partnership-facing security questionnaires and trust-center content in support of integrations.
  • Partner with Security team members to design and deliver security awareness training programs, including role-specific content on phishing, social engineering, third-party risk, and data handling.
  • Track training completion and effectiveness; align program content with TPRM findings and emerging threats.
  • Partner with IT and Security teams to design and run quarterly user access review campaigns, ensuring timely completion, accurate certification decisions, and clear remediation of access exceptions.
  • Report on TPRM, training, and access review metrics to security leadership: cycle time, open findings, remediation aging, and completion rates.

Benefits

  • Competitive salary, equity, benefits, and perks for all full-time employees
  • Employer-paid medical, dental, and vision insurance (Country specific)
  • Retirement employer match
  • Learning & Development stipend to invest in your professional development
  • Turo host matching program
  • Turo travel credit
  • Cell phone and internet stipend
  • Paid time off to relax and recharge
  • Paid holidays, volunteer time off, and parental leave
  • In-office lunch, office snacks, and fun activities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service