Jobs · Education · Texas

GRC TPRM Assessment & Remediation SME

VMC Soft Technologies, Inc · Austin, TX · 3 days ago
On-siteEducationContract
Job Title : GRC TPRM Assessment & Remediation SME Location : Austin, TX Job Description We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation from inventory governance through assessment coordination, escalation management, and executive reporting in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders. Key Responsibilities Supplier Inventory Management: Maintain the Supplier Inventory (GRC platform, e.g., Supplier Ninja) as the single source of truth for assessment status. Tier/filter suppliers requiring reassessment vs. new assessment per program criteria. Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., One Trust). Assessment Execution: Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results). Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments. Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence. Confirm onsite-assessed suppliers have current-year coverage (e.g., in Air Table). Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards. Remediation Management Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners. Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls. Stakeholder Communication & Escalation: Run a structured outreach cadence with DRIs (kick-off 3 follow-ups 3 escalations to management). Track response/non-response rates for every outreach cycle. Escalate unresolved/high-risk findings to client leadership and track to closure. Weekly Reporting. Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage. Required Qualifications 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination. Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ. Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar). Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation. Excellent written communication for remote, client-facing engagement. Experience Operating In Distributed/remote Teams. Preferred Qualifications Certification: CTPRP, CRISC, CISA, or CISSP. Experience with Wrike, Air Table, Jira, or similar tracking tools. Prior experience in regulated industries (financial services, healthcare, insurance). Track record producing leadership-facing weekly reporting. Thanks & Regards... Raj Mohan Technical Recruiter Galaxy i Technologies inc. EMail: Rajmohan@galaxyitech.com Ph No: 480-750-7071 Ext: 241

Similar jobs

Remediation Systems SME

GHDKing of Prussia, PA· 2 mo ago
Consulting$15k–$206k/yrapply on ejov.fa.ca2.oraclecloud.com