HomeSearch › Job

TPRM Analyst

integritymarketing.wd1.myworkdayjobs.com

Dallas, TX

Position Summary  The Third-Party Risk Management Analyst runs the vendor due diligence program on the enterprise third-party risk platform. The organization engages thousands of suppliers, a substantial number of which have never been formally risk assessed, and the first mandate of this role is to reduce that population while establishing sustainable ongoing monitoring behind it. Third-party exposure is one of the highest-probability incident vectors in the industry, and vendors with access to enterprise systems or physical facilities all fall within scope.

This role also serves as the first gate in the vendor intake process, assessing risk before the organization commits the limited resources of procurement, contracting, legal, and cybersecurity. The ideal candidate is detail-oriented, comfortable with assessment frameworks, and looking for a strong entry point into a growing enterprise risk function. Key Responsibilities  Run vendor intake, inherent risk tiering, and due diligence assessment on the enterprise third-party risk platform  Reduce the backlog of suppliers that have not been formally risk assessed, working to an agreed prioritization based on access and criticality  Assess vendors with access to enterprise systems, data, or physical facilities, ensuring no in-scope category is omitted  Process vendor security questionnaires to closure within service level targets, coordinating with vendors and internal stakeholders to obtain required documentation  Partner with Cybersecurity on technical vendor reviews and with Contracting and Legal on risk-relevant terms  Serve as the first assessment gate in the vendor intake workflow so downstream functions engage only on vendors that clear  Support integration between the third-party risk platform and the procurement system to avoid duplicated effort across teams  Handle inbound due diligence requests and carrier annual audit responses through the trust center  Establish and execute ongoing monitoring and periodic reassessment based on vendor tier  Absorb the vendor population arriving through acquisitions and bring it into the assessment program  Feed third-party risk findings into the enterprise risk register and reporting  Maintain assessment documentation to an audit-ready standard suitable for control testing  Support sanctions and denied-party screening activity in coordination with Procurement, and support documentation of how flagged results are reviewed and resolved  Required Qualifications  Bachelor's degree in Business, Risk Management, Information Systems, Cybersecurity, or a related field  1 to 4 years of experience in third-party risk, vendor management, compliance, or security governance risk and compliance; internship experience will be considered  Familiarity with vendor assessment frameworks and security questionnaire methodologies  Understanding of how vendor access to systems, data, or facilities translates into organizational risk  Experience working to defined service level targets across a queue of concurrent requests  Skills  Strong analytical thinking and attention to detail, with accurate work across platforms and spreadsheets  Strong written and verbal communication, including direct interaction with external vendors  Organizational skills sufficient to manage a large assessment queue without items aging out  Ability to read a security report and identify what actually matters to the organization  Collaborative approach across procurement, legal, cybersecurity, and business unit stakeholders  Proficiency in Microsoft Office Suite, with strong Excel capability  Preferred Qualifications  Hands-on experience with a third-party risk platform such as Whistic, Archer, ServiceNow, or similar  Professional certification such as CTPRP, CRISC, or similar  Experience in insurance, financial services, or other regulated industries  Familiarity with System and Organization Controls 2 reports, NIST, ISO 27001, or HITRUST  Exposure to procurement or contra

Search all live jobs — free, no account →