GRC TPRM Assessment and Remediation SME

PROLIM Global Corporation
  • TX
  • Remote
    9 days ago

    Job Description

    Job Title: GRC TPRM Assessment and Remediation SME

    Location: Austin, TX/Cupertino, CA

    Duration: 6 months

    Hybrid (3 days a week)

    Role Descriptions:

    • We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation - from inventory governance through assessment coordination, escalation management, and executive reporting - in a fully remote, client-facing environment.
    • This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.

    Key Responsibilities

    1. Supplier Inventory Management:
    • Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
    • Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
    • Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).
    1. Assessment Execution:
    • Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
    • Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
    • Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
    • Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
    • Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
    1. Remediation Management
    • Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
    • Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
    1. Stakeholder Communication & Escalation:
    • Run a structured outreach cadence with DRIs (kick-off 3 follow-ups 3 escalations to management).
    • Track response/non-response rates for every outreach cycle.
    • Escalate unresolved/high-risk findings to client leadership and track to closure.
    1. Weekly Reporting.
    • Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.

    Required Qualifications:

    • 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
    • Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
    • Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
    • Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
    • Excellent written communication for remote, client-facing engagement.
    • Experience operating in distributed/remote teams. Preferred Qualifications
    • Certification: CTPRP, CRISC, CISA, or CISSP.
    • Experience with Wrike, AirTable, Jira, or similar tracking tools.
    • Prior experience in regulated industries (financial services, healthcare, insurance).
    • Track record producing leadership-facing weekly reporting.

    Numbers & Facts

    LocationTX (
    Remote
    )

    Skills

    • Atlassian JIRAunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cadenceunmatched
    • Communication Skillsunmatched
    • Corrective Actionunmatched
    • Cross-Functionalunmatched
    • Customer Relationsunmatched
    • Documentationunmatched
    • Financeunmatched
    • Financial Servicesunmatched
    • Health Insuranceunmatched
    • ISO (International Organization for Standardization)unmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Inventory Managementunmatched
    • Leadershipunmatched
    • Legal Support Skillsunmatched
    • Metricsunmatched
    • Project Trackingunmatched
    • Purchasing/Procurementunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Service Level Agreement (SLA)unmatched
    • ServiceNowunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vendor/Supplier Evaluationunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder