





Metro location and generalist GRC associate role increases candidate density.
GRC skills are transferable across industries but frameworks can be industry-specific.
Mandatory 2 years plus framework experience creates moderate filtering; certifications preferred not required.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Manage and support third-party risk management processes including vendor onboarding, risk assessments, and ongoing monitoring.
Review and analyze vendor security documentation (SOC 2 Type II, penetration test reports, ISO reports) to identify risks and control gaps.
Coordinate with stakeholders to respond to client due diligence requests, audit inquiries, and maintain risk registers and compliance monitoring metrics.
Bachelor's degree in IT systems, cybersecurity, risk management, internal audit, or related field required.
Minimum 2 years of experience in third-party risk management, governance, risk and compliance, IT/internal audit, or cybersecurity control assessment.
Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST CSF, HIPAA, CMMC, HITRUST, PCI-DSS, or SOX mandatory.
Work Experience Required: At least 2 years in relevant risk compliance or audit roles.
Experienced in reviewing vendor security documentation and identifying control risks within third-party risk programs.
Skilled in coordinating audit and compliance activities across multiple regulatory frameworks and internal stakeholders.
Comfortable working with GRC tools and responding to client security questionnaires, RFPs, and audit inquiries with clear communication.