6-12 Months Position Summary Seeking a Cybersecurity GRC Consultant with strong expertise in Third-Party Risk Management (TPRM), Vendor Risk Assessments, Data Security, and security control assessments. The consultant will lead end-to-end vendor risk assessments, evaluate security controls and architectures, identify gaps, and drive remediation across technology, SaaS, supply chain, and hybrid environments. Key Responsibilities Lead and execute end-to-end Third-Party / Vendor Risk Assessments across technology, SaaS, supply chain, and hybrid environments. Identify security/control gaps and recommend appropriate risk mitigation and remediation strategies.
Perform technical reviews of:
Solution and application architectures Security controls Cloud solutions Data security practices Conduct hands-on SOC 2 assessments, including evaluation of control design and operating effectiveness. Assess alignment with
SOC 2, ISO
27001, enterprise security policies, and data protection standards. Manage risk lifecycle activities using GRC/risk intelligence platforms such as: RSA Archer Onspring BitSight UpGuard SecurityScorecard ServiceNow Partner with Legal, Procurement, IT, Privacy, Audit, and Security Operations teams to complete assessments and track remediation. Develop and report TPRM risk metrics, program insights, and leadership dashboards. Contribute to information security policies, standards, exception processes, and continuous improvement initiatives. Communicate complex cybersecurity and risk concepts effectively to both technical and business stakeholders. Must-Have Skills Third-Party Risk Management / Vendor Risk Assessment Cybersecurity GRC Data Security SOC 2 control assessment
ISO 27001
Security architecture and cloud security assessment Risk identification, remediation, and exception management GRC platforms - RSA Archer / Onspring / ServiceNow or similar Risk intelligence platforms - BitSight / UpGuard / SecurityScorecard Work Authorization Applicants must be legally authorized to work in the United States. Equal Employment Opportunity [Themesoft Inc] is an Equal Employment Opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other status protected by applicable federal, state, or local law. Email me for prompt response.