Third-Party Risk Management - Cybersecurity
Job Description:
GRC TPRM Assessment and Remediation SME
We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert (SME) to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation.
The role will be responsible for supplier inventory governance, assessment coordination, findings management, remediation tracking, escalation management, and executive reporting. The ideal candidate will have strong TPRM/GRC expertise, excellent communication skills, and experience managing high-volume, multi-step risk assessment workflows.
Location: Austin, TX / Cupertino, CA
Work Model: Hybrid – 3 Days a Week Onsite
Duration: 12+ Months Contract
Key Responsibilities
1. Supplier Inventory Management
Maintain the Supplier Inventory within the GRC platform as the single source of truth for assessment status.
Tier and filter suppliers requiring reassessment versus new assessments based on program criteria.
Maintain accurate Direct Responsible Individual (DRI) records within the GRC tool.
2. Assessment Execution
Evaluate suppliers against established frameworks and sta