Job posting has expired
Security Assurance Analyst-TPRM
![]() | |
![]() | |
![]() United States, Utah, Salt Lake City | |
![]() 4283 590 West (Show on map) | |
![]() | |
Description
Job Summary The Security Assurance Analyst-TPRM will be responsible for leading, processing, and executing Third Party Risk Management (TPRM) and Supply Chain security assessments on prospective and existing vendors. This encompasses identifying and tracking remediation action plans, performing remote investigative questioning or audits, and in-person on-site security reviews (at the vendor location). This role plays a key part in protecting the organization from supply chain risks by evaluating vendor security postures, identifying control gaps, and ensuring compliance with regulatory and industry frameworks. Additionally, you will contribute to the testing and validation of security and IT controls, support internal security assurance initiatives, and assist in compliance activities related to SOC 2, ISO 27001, NIST, or other applicable frameworks and industry best practices. This role participates in and/or conducts the following, among other duties: raises the level of security awareness among employees and about vendor integration risks, does individual user and group trainings on the vendor relationship owner duties, issues and evaluates security questionnaires to third parties, reviews external vulnerability testing including audit reports and auditor assessments, assists with creating or updating security policies, other internal and external auditor activities, raises internal documentation standards, and moves the organization toward mitigation of information security risks. * Applicants must be legally eligible to work in the United States to be considered. Visa sponsorship is not available for this role * Essential Duties and Responsibilities Third Party Security Risk Management:
Security Assurance & Compliance Testing:
Supply Chain Risk Assessments:
Collaboration & Reporting:
Travel Requirements: Less than 25% Supervisory Responsibility This position has no direct supervisory responsibilities but does serve as a coach and mentor for other positions in the department. Education 4 Year / Bachelors Degree in a related field Minimum Certification: One or more of the following Certifications: CISSP, CRISC, CISA, CISM or other equivalents Preferred Certification: One or more of the following Certifications: CSCP or CRISC Experience 3 years Experience in 3rd party risk management, vendor security assessments, and supply chain risk evaluations including both physical and cyber risks. 2 years Experience in IT security assurance, auditing, and controls testing, and supply chain operations, logistics, and procurement processes. Knowledge, Skills, and Abilities
Working Conditions and Physical Requirements * Able to sit, stand, and type for a long period of time in an office environment using computer equipment. Benefits
Pay Range: Actual pay may vary up or down depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for incentive compensation. Company Summary Our Mission...Harnessing the power of language, we connect diverse people and enrich the human experience. Our Vision...To provide global language services that expand opportunities, nurture belonging, and empower the world to connect beyond words. As one of the world's leading language services providers, Sorenson combines patented technology with human-centric solutions. We strive to increase diversity, equity, inclusion, and accessibility for underrepresented people through communication solutions for all: call captioning and video relay services, over-video and in-person sign language and spoken language interpreting, translation, real-time captioning, and post-production language services. Sorenson's impact vision and plan extends to supporting employment opportunities for diverse employees, customers, and communities. As a minority-owned company, we are committed to expanding opportunities for underserved communities while promoting an inclusive workplace for our own employees. Equal Employment Opportunity: Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
|