[Hiring] TPRM Analyst @EVOCS
Back to Remote jobs   >   All Others   >   rn analyst
TPRM Analyst @EVOCS
All Others
Salary $75 - $90 usd/h..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type casual
Posted 6d ago

[Hiring] TPRM Analyst @EVOCS

6d ago - EVOCS is hiring a remote TPRM Analyst. πŸ’Έ Salary: $75 - $90 usd/hour πŸ“Location: USA

Role Description

As a TPRM Analyst, you are the execution layer of the third-party risk program. You carry the assessment volume β€” questionnaires out, evidence in, controls reviewed, findings documented, remediation tracked β€” and you keep the work moving without needing someone standing behind you.

Two things make or break this role:

  • Written documentation: your assessments and findings are read by people who were not on the call, so they have to stand on their own.
  • Data quality: a third-party risk program is only worth what its records say, and inconsistent entries quietly erode the value of everything the program produces.

We are hiring four TPRM Analysts.

What You Will Do

  • Assessment Execution
    • Conduct vendor security assessments and third-party reviews across a high-volume queue, on schedule and to a consistent standard.
    • Issue and manage security questionnaires, chase evidence requests, and validate what comes back against what was asked for.
    • Review control evidence β€” policies, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and supporting artifacts β€” and document what the evidence does and does not cover.
    • Identify gaps and findings, assign risk ratings under the program’s tiering criteria, and write them up clearly enough that a reader outside the review understands the exposure.
    • Escalate complex, contested, or high-criticality reviews to senior analysts with the work already organized.
  • Remediation and Follow-Through
    • Build and track remediation plans with vendors and internal owners, including agreed actions, owners, and due dates.
    • Chase stakeholders through to closure β€” vendors, business owners, procurement, and legal β€” and keep items from aging out quietly.
    • Re-validate evidence at remediation closure rather than accepting a status update at face value.
    • Maintain reassessment schedules for in-scope vendors and flag material changes between cycles.
  • Records, Reporting, and Data Quality
    • Own the accuracy and consistency of your entries in the risk register and TPRM platform: complete fields, correct tiering, current status, and traceable evidence links.
    • Maintain assessment documentation to an audit-ready standard.
    • Produce status reporting on queue volume, aging, findings, and open remediation items.
    • Flag inconsistencies in criteria application, data entry, or workflow, and help tighten the process that produced them.

Qualifications

  • 5+ years of experience in cybersecurity, audit, compliance, risk, or vendor management.
  • At least 3 of those years conducting vendor security assessments or third-party reviews.
  • Hands-on comfort with the core mechanics of the role: security questionnaires, evidence requests, control reviews, remediation plans, and risk registers.
  • Clear, structured written documentation β€” assessments and findings that hold up when read by someone who was not in the conversation.
  • Strong attention to data quality and consistency across records, ratings, and documentation.
  • Ability to drive items to closure independently, following up with vendors and internal stakeholders without being chased yourself.
  • Working familiarity with common control frameworks such as NIST CSF, NIST 800-53, ISO 27001/27002, or CIS.
  • Strong interpersonal and communication skills β€” this role involves frequent interaction with vendors and internal stakeholders via email, calls, and meetings.

Key Skills and Competencies

  • Vendor security assessment execution.
  • Control and evidence review.
  • Remediation tracking and stakeholder follow-through.
  • Risk register and documentation hygiene.
  • Written risk communication.
  • Time and queue management across concurrent reviews.

Ideally you have…

  • Certifications such as Security+ or CTPRP; CISA, CRISC, CISM, or ISO 27001 Lead Auditor are a plus.
  • Hands-on platform experience with ProcessUnity, ServiceNow GRC, or Archer.
  • Exposure to security ratings tools such as SecurityScorecard, BitSight, RiskRecon, or Black Kite.
  • Experience assessing cloud providers, MSPs, or technology vendors specifically.
  • Experience working an assessment queue against SLAs in a regulated environment.

Benefits

  • Pay Range: $75 - $90 USD.

Our Values

We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.

  • Customer-centric Solutions
  • Innovation & Excellence
  • Integrity & Transparency
  • Data-driven Decision Making

Need to Know

The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   All Others   >   rn analyst
TPRM Analyst @EVOCS
All Others
Salary $75 - $90 usd/h..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type casual
Posted 6d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later