Beschreibung

TPRM Security Assessor We are looking for an experienced TPRM Security Assessor to support a global security team in assessing and managing the cybersecurity risks associated with third-party vendors and suppliers. This is a great opportunity for someone with a background in Third-Party Risk Management, Information Security, Cybersecurity Risk, IT Audit or GRC who enjoys assessing security controls and working with both technical and business stakeholders. Key Responsibilities Conduct third-party/vendor security assessments and due diligence Review vendor security questionnaires and supporting evidence Assess supplier controls across areas including: Access Management Vulnerability Management Incident Response Business Continuity Security Monitoring Data Protection Review security assurance documentation such as SOC 2, ISO 27001, CAIQ and SIG Identify security gaps, risks and control weaknesses Document assessment findings and support risk remediation Communicate findings and requirements clearly to vendors and internal stakeholders Work closely with Security, Risk, Procurement, Legal and other business teams Support ongoing vendor reassessments and third-party risk activities Requirements 2+ years of experience in TPRM, Information Security, Cybersecurity Risk Management, IT Audit or GRC Hands-on experience conducting vendor/supplier security assessments Good understanding of cybersecurity controls and risk management Experience reviewing security questionnaires and assurance reports Knowledge of SOC 2, ISO 27001, CAIQ and/or SIG Strong analytical, written and verbal communication skills Strong stakeholder management skills Ability to assess security risks and clearly communicate findings to technical and non-technical audiences Desirable Certifications CRISC CISA CISSP ISO 27001 Lead Auditor CTPRP Location: Poland, with Warsaw preferred If you're a TPRM, Vendor Risk, GRC or Cybersecurity Risk professional looking for your next opportunity, feel free to apply or message me directly.