MUST HAVE SKILLS: GRC Vendor risk assessment/ Third party risk assessment
Role Descriptions: Lead and execute end-to-end third-partyvendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies.Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.
Essential Skills: Lead and execute end-to-end third-partyvendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies.Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.
Numbers & Facts
Location
Cockeysville, MD
Industry
Computer/IT Services
Company Size
500 to 999 employees
Year Founded
1990
Website
http://q1tech.com/
About Company
Q1 consists of experienced and recognized experts providing the capability to respond to market demand in order to provide professional services for our clients including Enterprise software implementations, application integration and technical / functional support.
Q1 has steadily grown into a Quality IT services and solutions organization with the average experience of our team being over 10 years. We have continuously met or exceeded client expectations by delivering professional services and project implementations on time and under budget to help clients truly recognize return on investment.
Skills
Analysis Skillsunmatched
Best Practicesunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Consultingunmatched
Continuous Improvementunmatched
Design Evaluationunmatched
Enterprise Protectionunmatched
ISO (International Organization for Standardization)unmatched
Information/Data Security (InfoSec)unmatched
Internet Securityunmatched
Leadershipunmatched
Legalunmatched
Metricsunmatched
Purchasing/Procurementunmatched
Reporting Skillsunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Security Consultingunmatched
ServiceNowunmatched
Software Engineeringunmatched
Software as a Service (SaaS)unmatched
Supply Chainunmatched
Time Managementunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.