job summary:
The TPRM Continuous Monitoring Analyst is responsible for the ongoing oversight of critical third-party vendors, ensuring their risk posture remains aligned with the organization's risk appetite, internal policies, and regulatory expectations throughout the vendor lifecycle. This role plays a key part in safeguarding the organization by conducting periodic reassessments, trigger-based reviews, and continuous monitoring of vendor controls across multiple risk domains -including information security, privacy, business continuity, operational resilience, and compliance. The analyst leverages risk intelligence tooling (e.g., Supply Wisdom and Black Kite) to detect material changes in vendor risk, triage alerts, and drive timely remediation, escalation, and reporting.
location: Telecommute
job type: Contract
salary: $65 - 70 per hour
work hours: 9am to 5pm
education: Bachelors
responsibilities:
Key Responsibilities
Continuous Monitoring & Ongoing Oversight
- Participate in ongoing monitoring of critical vendors, including periodic reassessments and trigger-based reviews.
- Monitor risk intelligence feeds (Supply Wisdom and Black Kite) daily, reviewing alerts across cyber, financial, operational, geopolitical, compliance, and reputational risk domains.
- Perform initial triage and severity validation of incoming alerts, investigating alert context, vendor history, and existing controls to determine whether escalation is warranted.
- Initiate and conduct targeted assessments based on defined cadence and triggers (e.g., breach disclosures, sanctions/adverse media hits, material CVE exposure, breach notifications).
- Track changes in vendor risk posture and maintain monitoring tiers mapped to inherent risk, data sensitivity, concentration risk, and business criticality.
Risk Assessments & Reassessments
- Perform comprehensive risk assessments and reassessments of third-party vendors using standardized frameworks and questionnaires (IRQ/DDQ).
- Evaluate vendor responses, supporting documentation, and control effectiveness across domains such as cybersecurity, data protection, operational resilience, and regulatory compliance in ProcessUnity.
- Conduct SOC report reviews for suppliers in accordance with the annual review cadence.
- Evaluate updated evidence to identify control improvements or deterioration, newly introduced risks, and persistent or systemic issues.
Due Diligence & Analysis
- Analyze vendor risk posture and identify potential gaps or areas of concern.
- Collaborate with internal subject matter experts (e.g., InfoSec, Privacy, Legal, Compliance, Business Continuity) to validate findings and determine risk impact.
- Document risk trend analysis and provide clear rationale for any changes in inherent or residual risk ratings.
Escalation & Communication
- Escalate Critical and High alerts for Tier 1 and Tier 2 vendors within defined SLA timeframes, notifying the Relationship Manager, TPRM Assessment team, and applicable SMEs (e.g., InfoSec, CSIRT).
- Communicate identified issues with Relationship Managers, InfoSec, Privacy, Legal, Compliance, and Business Continuity, and log outcomes in ProcessUnity.
- Provide internal business support as well as supplier support throughout the reassessment process.
Reporting & Documentation
- Document assessment results, risk ratings, and recommendations in the TPRM platform (ProcessUnity).
- Produce monthly operational dashboards and status reports, and support quarterly executive reporting on top risks, identified findings, and SOC/compliance reviews.
- Maintain accurate, audit-ready records of monitoring activity, escalation records, and reassessment outcomes.
qualifications:
Required Qualifications
Experience in third-party risk, vendor assessments, or IT risk management.
Familiarity with risk and control frameworks (e.g., NIST, ISO 27001, SOC 2, SIG).
Working knowledge of risk assessment methodologies and control validation across information security, privacy, business continuity, and compliance domains.
Strong analytical, communication, and stakeholder management skills.
Ability to manage multiple priorities and meet deadlines in a fast-paced environment.
Detail-oriented with a focus on accuracy and completeness.
Key Competencies
Risk-based judgment and the ability to interpret and prioritize risk signals.
Sound decision-making under defined thresholds and escalation protocols.
Collaboration and partnership across cross-functional risk stakeholders.
Ownership, accountability, and the ability to produce measurable, actionable outputs.
skills:
information security,cybersecurity,InfoSec,analytical,Detail-oriented,Communication,Communicate,decision-making,meet deadlines,accountability,Collaboration,business continuity,operational resilience,partnership,business support,assessments,CISSP,CRISC,Continuous Monitoring,data protection,Due Diligence,geopolitical,ISO 27001,IT risk management,financial,NIST,internal policies,regulatory compliance,compliance reviews,reputational risk,risk,Risk Assessments,risks,risk assessment methodologies,risk appetite,stakeholder management skills,vendor assessments,vendor risk,third-party risk,tooling,trend analysis,triage,initial triage
Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.
At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact
Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).
This posting is open for thirty (30) days.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
![]()