evolutioncloudservicesevocs logo

Senior TPRM Analyst

evolutioncloudservicesevocs • Denver, Colorado


No Relocation

Posted: September 8, 2026

Job Description

Senior TPRM Analyst

🎯 Role Overview
As a Senior TPRM Analyst, you are the experienced hand on the third-party risk team. You own the complex vendor reviews — the cloud providers, MSPs, and critical technology vendors where a shallow assessment creates real exposure — and you are the person escalations land on when a finding is contested or a risk needs to be accepted at the leadership level.

You are also the one who writes what goes up. Executive-ready risk summaries, escalation memos, and risk acceptance recommendations come from you, and they need to be right the first time. This is a senior individual contributor role: depth of judgment, not headcount, is what makes you effective here.

We are hiring two Senior TPRM Analysts.

🧩 What You Will Do

Vendor Risk Assessment and Due Diligence
- Own end-to-end risk assessments for the highest-criticality third parties, including cloud service providers, managed service providers, and critical technology vendors
- Read SOC 2 Type II reports and ISO 27001 certificates for what they actually say — scope carve-outs, excluded systems, qualified opinions, exceptions in the testing results, and complementary user entity controls — rather than confirming that a document exists
- Evaluate control evidence, penetration test summaries, remediation plans, and security questionnaire responses, and challenge answers that do not hold up
- Set inherent and residual risk ratings, define compensating controls, and track remediation commitments to closure
- Assess vendor security posture in context: data classification, access model, integration depth, and business criticality

Fourth-Party and Supply Chain Analysis
- Map fourth-party and subcontractor dependencies behind critical vendors, including where the work is actually performed
- Analyze vendor concentration risk and identify single points of failure across the third-party portfolio
- Assess geopolitical and jurisdictional exposure, including offshore delivery locations, data residency, and sub-processor chains
- Incorporate security ratings and continuous monitoring signals into ongoing vendor risk views, and separate real signal from noise

Escalation, Reporting, and Governance
- Serve as the escalation point for contested findings, vendor pushback, and time-pressured reviews tied to contract or go-live deadlines
- Write executive-ready risk summaries that state the risk, the business impact, and the recommendation in language leadership can act on
- Run risk acceptance conversations with senior business, technology, and procurement stakeholders — documenting the decision, the owner, and the expiration
- Present third-party risk posture, trends, and exceptions to governance forums and senior leadership
- Support and improve the TPRM program itself: assessment standards, tiering criteria, evidence requirements, and playbooks that raise the floor for the whole team
- Mentor junior analysts on evidence review, write-up quality, and stakeholder handling

🧠  What You Will Bring
The top candidate will have the following qualifications:
- 7+ years of experience in cybersecurity, risk, audit, or compliance
- At least 5 of those years in third-party risk management or vendor risk specifically
- Demonstrated experience assessing cloud providers, MSPs, and critical technology vendors — not only routine or low-criticality suppliers
- Fluency reading SOC 2 reports and ISO 27001 certifications, including the ability to identify scope carve-outs, qualified opinions, and control exceptions
- Fourth-party and supply chain risk analysis: vendor concentration, criticality tiering, geopolitical exposure, and subcontractor dependencies
- Proven ability to write executive-ready risk summaries for senior audiences
- Experience leading escalation and risk acceptance conversations with senior stakeholders, including holding a position under pressure
- Working knowledge of common control frameworks — NIST CSF, NIST 800-53, ISO 27001/27002, CIS — and how they map to vendor assessments
- Strong interpersonal and communication skills — this role involves frequent interaction with vendors and internal stakeholders via email, calls, and meetings 


Key Skills and Competencies
- Third-party and vendor risk assessment
- Audit report and control evidence analysis
- Fourth-party and supply chain risk
- Executive risk communication and reporting
- Risk acceptance and exception governance
- Stakeholder management and escalation handling

Ideally you have…
- Certifications that matter here: CTPRP or CTPRA especially, along with CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor
- Hands-on platform experience with ProcessUnity, ServiceNow GRC, or Archer
- Working experience with security ratings tools such as SecurityScorecard, BitSight, RiskRecon, or Black Kite
- Exposure to regulated environments and the vendor oversight expectations that come with them
- Experience contributing to TPRM program design, not only executing assessments


#LI-Remote