Overview
The TPRM / Supplier Assurance Analyst will play a pivotal role within the Risk function of a well-established organisation, focusing on the assessment and management of third-party risks. The contractor will collaborate with various stakeholders, including Risk, Compliance, Information Security, and Legal, to ensure effective supplier assessments and the timely resolution of identified risks. This position is ideal for professionals with a background in vendor risk, information security, or third-party risk management.
Responsibilities
- Conduct third-party and supplier risk assessments, including inherent and residual risk assessments.
- Complete supplier due diligence and review risk questionnaires covering security, privacy, financial, operational, and compliance risks.
- Review documentation such as SOC 2 reports, ISO certifications, and business continuity plans to identify risk gaps.
- Document and track supplier risk findings and remediation actions.
- Support the onboarding and ongoing assessment of suppliers.
- Maintain supplier risk classifications and TPRM records.
- Monitor supplier relationships through periodic reassessments.
- Produce risk reports and dashboards for management and governance forums.
Requirements
- Minimum of 2 years' experience in Third Party Risk Management, Supplier Assurance, or Information Security Risk.
- Hands-on experience conducting supplier risk assessments and due diligence.
- Familiarity with frameworks such as NIST, ISO 27001, and SOC 2.
- Strong Excel skills for risk tracking and reporting.
- Experience using GRC or TPRM platforms like ServiceNow or OneTrust.
- Ability to produce clear risk reporting for diverse stakeholders.
- Bachelor's degree in Business, Finance, Information Security, or a related field is advantageous.