All Jobs Vacancy

TPRM / Supplier Assurance Analyst

Posted 1 day ago by Technology & Risk Recruitment

TPRM / Supplier Assurance Analyst Role - Contract - Outside IR35 - 6 Months Rolling

We are currently recruiting for a TPRM / Supplier Assurance Analyst to join the Risk function of a well-established organisation.

This is a great opportunity for someone with experience across third-party risk, supplier assurance, vendor risk or information security risk to take ownership of supplier assessments and work closely with stakeholders across Risk, Compliance, Information Security, Privacy, Procurement and Legal.

The role will involve assessing supplier risk, reviewing due diligence and security documentation, identifying gaps and ensuring remediation actions are followed through to completion.

Key Responsibilities

  • Conduct third-party and supplier risk assessments, including inherent and residual risk assessments.
  • Complete supplier due diligence and review risk questionnaires covering security, privacy, financial, operational and compliance risks.
  • Review documentation including SOC 2 reports, ISO certifications, financial information, insurance certificates and business continuity / disaster recovery plans.
  • Identify, document and track supplier risk findings, gaps and remediation actions.
  • Support the onboarding and ongoing assessment of new and existing suppliers.
  • Maintain supplier risk classifications and relevant TPRM records.
  • Monitor supplier relationships through periodic reassessments and ongoing risk monitoring.
  • Work with internal stakeholders to validate findings, agree ownership and track actions through to resolution.
  • Escalate significant or high-risk findings where appropriate.
  • Produce risk reporting, dashboards and PowerPoint presentations for management and governance forums.
  • Support internal and external audits and regulatory reviews relating to third-party risk.
  • Contribute to the development and improvement of TPRM policies, procedures and risk assessment frameworks.

Skills / Experience Required

  • 2+ years' experience within Third Party Risk Management, Supplier Assurance, Vendor Risk, Information Security Risk, Audit or Compliance.
  • Hands-on experience conducting or supporting third-party / supplier risk assessments and due diligence.
  • Understanding of information security, privacy and operational risk.
  • Familiarity with frameworks and standards such as NIST, ISO 27001, SOC 2 or COBIT.
  • Experience reviewing supplier documentation and identifying risk indicators and control gaps.
  • Strong Excel skills for risk tracking, analysis and reporting.
  • Experience using a GRC or TPRM platform such as ServiceNow, OneTrust, Archer or ProcessUnity.
  • Experience producing risk reporting and management information using Excel and PowerPoint.
  • Strong written and verbal communication skills, with the ability to communicate risk findings clearly to technical and non-technical stakeholders.
  • A Bachelor's degree in Business, Finance, Information Security, Risk Management or a related subject would be advantageous.
Rate:
Not specified
Location:
London
IR35 Status:
Outside
Remote Status:
Not specified
Industry:
Data & Analytics
Seniority Level:
Mid-Level

Take-Home Pay

Not Available

Visit calculators for additional details

Share job