TPRM Analyst

Evolution Cloud Services (EVOCS)
Remote

About The Position

EVOCS is an IT consulting firm dedicated to helping businesses operate more effectively, solve complex challenges, and create opportunities for growth through practical expertise and technology solutions. As a trusted technology partner, EVOCS combines technical expertise, business understanding, and a commitment to quality to deliver effective solutions and build lasting client relationships. The company is experiencing hyper-fast growth and is seeking agile team members to join their success story. The TPRM Analyst role is the execution layer of the third-party risk program, responsible for managing a high volume of assessments, ensuring data quality, and driving work to completion. This role requires strong written documentation skills and meticulous attention to detail regarding vendor risk data.

Requirements

  • 5+ years of experience in cybersecurity, audit, compliance, risk, or vendor management
  • At least 3 of those years conducting vendor security assessments or third-party reviews
  • Hands-on comfort with the core mechanics of the role: security questionnaires, evidence requests, control reviews, remediation plans, and risk registers
  • Clear, structured written documentation — assessments and findings that hold up when read by someone who was not in the conversation
  • Strong attention to data quality and consistency across records, ratings, and documentation
  • Ability to drive items to closure independently, following up with vendors and internal stakeholders without being chased yourself
  • Working familiarity with common control frameworks such as NIST CSF, NIST 800-53, ISO 27001/27002, or CIS
  • Strong interpersonal and communication skills — this role involves frequent interaction with vendors and internal stakeholders via email, calls, and meetings

Nice To Haves

  • Certifications such as Security+ or CTPRP
  • CISA, CRISC, CISM, or ISO 27001 Lead Auditor are a plus
  • Hands-on platform experience with ProcessUnity, ServiceNow GRC, or Archer
  • Exposure to security ratings tools such as SecurityScorecard, BitSight, RiskRecon, or Black Kite
  • Experience assessing cloud providers, MSPs, or technology vendors specifically
  • Experience working an assessment queue against SLAs in a regulated environment

Responsibilities

  • Conduct vendor security assessments and third-party reviews across a high-volume queue, on schedule and to a consistent standard.
  • Issue and manage security questionnaires, chase evidence requests, and validate what comes back against what was asked for.
  • Review control evidence — policies, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and supporting artifacts — and document what the evidence does and does not cover.
  • Identify gaps and findings, assign risk ratings under the program’s tiering criteria, and write them up clearly enough that a reader outside the review understands the exposure.
  • Escalate complex, contested, or high-criticality reviews to senior analysts with the work already organized.
  • Build and track remediation plans with vendors and internal owners, including agreed actions, owners, and due dates.
  • Chase stakeholders through to closure — vendors, business owners, procurement, and legal — and keep items from aging out quietly.
  • Re-validate evidence at remediation closure rather than accepting a status update at face value.
  • Maintain reassessment schedules for in-scope vendors and flag material changes between cycles.
  • Own the accuracy and consistency of your entries in the risk register and TPRM platform: complete fields, correct tiering, current status, and traceable evidence links.
  • Maintain assessment documentation to an audit-ready standard.
  • Produce status reporting on queue volume, aging, findings, and open remediation items.
  • Flag inconsistencies in criteria application, data entry, or workflow, and help tighten the process that produced them.

Benefits

  • Consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service