Supply Chain Analyst (Vendor & Supply Chain Risk)

Crux SecurityAustin, TX
Hybrid

About The Position

Crux Security is looking for a self-directed Supply Chain Analyst to stand up a Supply Chain Risk Management (SCRM) program for a client engagement, working under the direction of an experienced Supply Chain lead who will provide subject-matter direction and quality review. This is a force-multiplier role: you will take a defined scope of work and drive it to audit-ready completion with minimal day-to-day oversight, escalating judgment calls rather than routine execution questions. You will build a supplier register from scratch, design and apply a vendor risk tiering methodology, review and update security contract clauses alongside Legal, stand up a SOC 2 / ISO 27001 certification review process for critical vendors, and design a SaaS procurement security checklist. The end state is an ISO 27001:2022-aligned evidence package (mapped to A.5.19–A.5.23) that is audit-ready, along with documented procedures and a formal transition plan handing long-term ownership to the client.

Requirements

  • Demonstrated experience designing or applying a vendor risk tiering methodology
  • Experience drafting or revising security contract clauses / annexes, ideally in coordination with Legal
  • Experience reviewing SOC 2 reports and ISO 27001 certifications from a vendor risk perspective
  • Experience designing procurement-stage security checklists or vendor questionnaires for SaaS
  • Comfortable coordinating directly with Procurement and Legal stakeholders
  • Experience building supplier inventories or risk registers
  • Working knowledge of ISO 27001:2022 evidence requirements and audit expectations
  • Able to work independently against a defined scope with minimal supervision, escalating judgment calls rather than routine questions
  • Strong written communication; proficiency producing audit-ready documentation with limited rework
  • Must pass a background check and comply with client security policies

Nice To Haves

  • Direct experience mapping controls to ISO 27001:2022 Annex A, particularly A.5.19–A.5.23
  • Experience developing procedures documentation and FTE transition / handoff plans
  • Prior work in a managed services, consulting, or advisory capacity supporting multiple clients
  • Familiarity with SOC 2 in addition to ISO 27001
  • GRC or security certifications (CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CIPP)
  • Experience with GRC or vendor risk management platforms
  • Prior experience with defense industrial base or DoD-adjacent clients
  • Exposure to cloud services security considerations

Responsibilities

  • Confirm whether an existing vendor inventory exists outside of IT, and consolidate all available sources into a single, structured supplier register
  • Design the register as a spreadsheet-based artifact capturing vendor name, service type, data access, criticality tier, contract status, and review cadence
  • Design and apply a vendor risk tiering methodology to the confirmed supplier inventory, prioritizing critical vendors (approximately tens) first
  • Build tiering criteria around data sensitivity, operational dependency, and supply chain risk factors, aligned to ISO 27001 controls A.5.19 and A.5.21
  • Produce a tiered vendor register as an audit-ready artifact
  • Review existing security contract clauses and MSA language for alignment with ISO 27001:2022 requirements
  • Update and formalize clause language in active coordination with Legal
  • Deliver an updated, audit-ready security contract annex or clause library applicable to new and renewing vendor agreements
  • Establish a repeatable process for reviewing vendor SOC 2 reports and ISO 27001 certifications as part of ongoing supplier monitoring
  • Produce a review methodology, a findings and exceptions log, and completed assessments for all critical vendors within scope
  • Design a security checklist for evaluating SaaS vendors at the point of procurement, covering data handling, access controls, certifications, incident notification, and exit/portability requirements
  • Coordinate with Procurement and Legal throughout checklist design
  • Formally introduce security as a touchpoint in the procurement lifecycle, defining where and how reviews occur, who is responsible, and the escalation path for high-risk vendors
  • Produce a workflow document that Procurement can operationalize as the long-term owner
  • Compile all SCRM-related outputs into a structured evidence package mapped to controls A.5.19, A.5.20, A.5.21, A.5.22, and A.5.23
  • Ensure traceability between the supplier register, tiering methodology, contract clause library, vendor assessments, and control objectives
  • Deliver an audit-ready evidence package
  • Document all operational procedures for ongoing SCRM program management, including vendor tiering reviews, contract clause application, SaaS checklist usage, and annual supplier assessment cadence
  • Develop a structured handoff plan targeting Procurement as the long-term owner, including ownership mapping, recurring task cadence, recommended FTE profile, and a formal knowledge transfer session
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service