Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Tata Consultancy Services

GRC TPRM Assessment and Remediation SME

Career Insights for Site Remediation Specialist / Manager

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on national data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Site Remediation Specialist or Manager plans and directs cleanup and redevelopment of contaminated properties for reuse.

$101,352 / year median in the U.S.

+9% projected growth

Explore Career

Job Description

GRC TPRM
Assessment and Remediation SME Tata Consultancy Services - 3.9 Sunnyvale, CA Job Details $80,000 - $140,000 a year 18 hours ago Qualifications ISO standards Operations coordination Governance, risk, and compliance (GRC) software SOC 2 Information security compliance NIST standards Project stakeholder communication Cross-functional communication Full Job Description We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation — from inventory governance through assessment coordination, escalation management, and executive reporting — in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders. ________________________________________ Key Responsibilities 1. Supplier Inventory Management Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status. Tier/filter suppliers requiring reassessment vs. new assessment per program criteria. Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust). 2. Assessment Execution Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST
CSF, ISO 27001, SOC 2
) and validate evidence (audit reports, certifications, pen test results). Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments. Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence. Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable). Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards. 3. Remediation Management Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners. Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls. 4. Stakeholder Communication & Escalation Run a structured outreach cadence with DRIs (kick-off 3 follow-ups 3 escalations to management). Track response/non-response rates for every outreach cycle. Escalate unresolved/high-risk findings to client leadership and track to closure. 5. Weekly Reporting Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage. Required Qualifications 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination. Working knowledge of
NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
Hands-on experience with
GRC/TPRM
tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar). Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation. Excellent written communication for remote, client-facing engagement. Experience operating in distributed/remote teams.
Preferred Qualifications Certification:
CTPRP, CRISC, CISA, or CISSP. Experience with Wrike, AirTable, Jira, or similar tracking tools. Prior experience in regulated industries (financial services, healthcare, insurance). Track record producing leadership-facing weekly reporting.
Location :
Sunnyvale, CA/Austin, TX Salary Range :
$80,000-$140,000 a year #LI-AS3 Location Sunnyvale, CA Job Function
TECHNOLOGY
Role Process Expert Job Id 421167 Desired Skills Cyber Security | GRC Salary Range $80,000-$140,000 a year