... analyst-assistive tooling to focus effort on judgment-intensive decisions. Education and Experience * 8+ years in information security, IT risk, or GRC, including 4+ years focused on third-party ...
... analyst-assistive tooling to focus effort on judgment-intensive decisions. Education and Experience * 8+ years in information security, IT risk, or GRC, including 4+ years focused on third-party ...
... risk exposure from engaging third party service providers to deliver products and services to ... This includes the identification, analysis, reporting, and control of risks that are posed by these ...
... risk exposure from engaging third party service providers to deliver products and services to ... This includes the identification, analysis, reporting, and control of risks that are posed by these ...
Senior Third Party Risk Manager
Denver, CO · On-site
$85 - $100/hr
... risk exposure from engaging third party service providers to deliver products and services to ... This includes the identification, analysis, reporting, and control of risks that are posed by these ...
Senior Third Party Risk Manager
Denver, CO · On-site
$85 - $100/hr
... risk exposure from engaging third party service providers to deliver products and services to ... This includes the identification, analysis, reporting, and control of risks that are posed by these ...
... risk exposure from engaging third party service providers to deliver products and services to ... This includes the identification, analysis, reporting, and control of risks that are posed by these ...
... risk exposure from engaging third party service providers to deliver products and services to ... This includes the identification, analysis, reporting, and control of risks that are posed by these ...
Analyst-Cyber GRC, Sr.
Lakewood, CO · On-site
$100K - $129K/yr
This includes cyber risk management, policy and standards governance, third-party risk management ... The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ...
Analyst-Cyber GRC, Sr.
Lakewood, CO · On-site
$100K - $129K/yr
This includes cyber risk management, policy and standards governance, third-party risk management ... The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ...
Analyst-Cyber GRC, Sr.
Lakewood, CO · On-site
$99K - $128K/yr
This includes cyber risk management, policy and standards governance, third-party risk management ... The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ...
Analyst-Cyber GRC, Sr.
Lakewood, CO · On-site
$99K - $128K/yr
This includes cyber risk management, policy and standards governance, third-party risk management ... The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ...
Enterprise Risk Analyst
Denver, CO · On-site
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... Qualifications * 5+ years of experience in enterprise risk management, GRC, cybersecurity risk ...
Enterprise Risk Analyst
Denver, CO · On-site
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... Qualifications * 5+ years of experience in enterprise risk management, GRC, cybersecurity risk ...
Senior Cybersecurity Risk Analyst - USA Remote
Denver, CO · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ... Familiarity with GRC platforms (e.g., OneTrust, ServiceNow IRM, RSA Archer) and vendor risk tooling ...
Senior Cybersecurity Risk Analyst - USA Remote
Denver, CO · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ... Familiarity with GRC platforms (e.g., OneTrust, ServiceNow IRM, RSA Archer) and vendor risk tooling ...
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... Qualifications * 5+ years of experience in enterprise risk management, GRC, cybersecurity risk ...
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... Qualifications * 5+ years of experience in enterprise risk management, GRC, cybersecurity risk ...
Analyst-Cyber GRC, Sr.
Lakewood, CO · On-site
$100K - $129K/yr
This includes cyber risk management, policy and standards governance, third-party risk management ... The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ...
Analyst-Cyber GRC, Sr.
Lakewood, CO · On-site
$100K - $129K/yr
This includes cyber risk management, policy and standards governance, third-party risk management ... The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
Conduct third party security risk assessments by distributing questionnaires, analyzing responses, verifying controls, and documenting results in the GRC tracking systems. * Identify and escalate ...
Conduct third party security risk assessments by distributing questionnaires, analyzing responses, verifying controls, and documenting results in the GRC tracking systems. * Identify and escalate ...
Manager, Enterprise Risk Management
Denver, CO · On-site
$85K - $135K/yr
Third-Party Risk Management o Lead and execute the third-party risk management program, focusing ... Leadership & Collaboration o Lead, mentor, and develop a team of risk analysts and professionals. o ...
Manager, Enterprise Risk Management
Denver, CO · On-site
$85K - $135K/yr
Third-Party Risk Management o Lead and execute the third-party risk management program, focusing ... Leadership & Collaboration o Lead, mentor, and develop a team of risk analysts and professionals. o ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
Inmation Security Officer ISO GRC cybersecurity Lead
Fountain, CO · On-site
$136.56 - $204.85/hr
Vendor & Third-Party Risk * Build and manage the vendor security program, including due diligence ... GRC experience in regulated or high-growth environments. * Proven record of building and scaling ...
Inmation Security Officer ISO GRC cybersecurity Lead
Fountain, CO · On-site
$136.56 - $204.85/hr
Vendor & Third-Party Risk * Build and manage the vendor security program, including due diligence ... GRC experience in regulated or high-growth environments. * Proven record of building and scaling ...
Risk Technology Consultant
Denver, CO · On-site
... GRC, fraud, customer risk rating, sanctions screening, audit management, third-party risk ... Analyze data to support control testing, compliance reviews, system validation, reporting, and ...
Risk Technology Consultant
Denver, CO · On-site
... GRC, fraud, customer risk rating, sanctions screening, audit management, third-party risk ... Analyze data to support control testing, compliance reviews, system validation, reporting, and ...
Compliance Operations Lead, Third-Party Due Diligence
Westminster, CO · On-site
$158K/yr
Lead day-to-day operations for Vantor's third-party due diligence and screening program, including ... analysis to support compliance, risk, legal, operations, finance, procurement, or sales teams. Pay ...
Compliance Operations Lead, Third-Party Due Diligence
Westminster, CO · On-site
$158K/yr
Lead day-to-day operations for Vantor's third-party due diligence and screening program, including ... analysis to support compliance, risk, legal, operations, finance, procurement, or sales teams. Pay ...
Compliance Operations Lead, Third-Party Due Diligence
Westminster, CO · On-site
$158K/yr
We areseekinga highly motivated and detail-orientedCompliance Operations Lead, Third-Party Due ... analysis to support compliance, risk, legal, operations, finance, procurement, or sales teams. Pay ...
Compliance Operations Lead, Third-Party Due Diligence
Westminster, CO · On-site
$158K/yr
We areseekinga highly motivated and detail-orientedCompliance Operations Lead, Third-Party Due ... analysis to support compliance, risk, legal, operations, finance, procurement, or sales teams. Pay ...
Oversee vendor/third-party risk within the cyber risk portfolio to ensure supply-chain risk is ... Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance ...
Oversee vendor/third-party risk within the cyber risk portfolio to ensure supply-chain risk is ... Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance ...
... third-party risk management, cloud security, incident readiness, and managed risk services. * Identify and qualify high-value expansion opportunities by analyzing client risk maturity, cyber program ...
... third-party risk management, cloud security, incident readiness, and managed risk services. * Identify and qualify high-value expansion opportunities by analyzing client risk maturity, cyber program ...
Grc Third Party Risk Analyst information
What is a GRC Third Party Risk Analyst?
What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?
What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?
What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?
| Aspect | Grc Third Party Risk Analyst | Grc Vendor Risk Analyst |
|---|---|---|
| Certifications | Certifications like CRISC, CISA often preferred | Same certifications commonly required |
| Work Environment | Focuses on third-party relationships and risk assessments | Primarily evaluates vendor-specific risks and compliance |
| Industry Usage | Used across finance, healthcare, and tech sectors | Commonly found in industries with extensive vendor networks |
The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.
What are popular job titles related to Grc Third Party Risk Analyst jobs in Colorado?
For Grc Third Party Risk Analyst jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Grc Third Party Risk Analyst jobs in Colorado look for?
The top searched job categories for Grc Third Party Risk Analyst jobs in Colorado are:
What cities in Colorado are hiring for Grc Third Party Risk Analyst jobs?
Cities in Colorado with the most Grc Third Party Risk Analyst job openings:
Asurion rating
7.2
Based on 84 frontline employees who took The Breakroom Quiz
137th of 225 rated it services
Job description
The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third-party risk lifecycle-intake, inherent-risk tiering, due diligence, contract controls, continuous monitoring, reassessment, and secure offboarding-protecting Asurion and its carrier and partner ecosystem from risks introduced by vendors, service providers, and technology suppliers. The leader partners closely with Procurement, Legal, Privacy, business portfolio owners, and security control owners to translate fragmented vendor information into clear, defensible risk decisions. This is both a program-building and people-leadership role, maturing the vendor risk function in alignment with NIST CSF 2.0 and strengthening supply chain risk outcomes while embedding modern practices for emerging risks such as third-party AI tooling, SaaS sprawl, and vendor concentration.
Key Responsibilities- Own strategy, design, and continuous improvement of the Third-Party/Vendor Risk Management (TPRM) program aligned to NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and regulatory obligations.
- Define and maintain TPRM policy, standards, procedures, and risk-tiering methodology; secure governance approval and drive consistent adoption across the enterprise.
- Establish third-party risk appetite and tolerance thresholds with CISO and GRC leadership and apply them to vendor risk decisions.
- Embed risk gates within sourcing, onboarding, contracting, renewal, and offboarding in partnership with Procurement and Legal.
- Lead the full vendor risk lifecycle: intake, inherent-risk classification, due diligence, residual-risk determination, treatment/acceptance, contracting, continuous monitoring, reassessment, and offboarding.
- Operationalize inherent-risk tiering to scope assessment depth and cadence based on data sensitivity, access, criticality, and business impact.
- Direct security, privacy, and resilience assessments using methodologies such as SIG/Shared Assessments and evidence including SOC 2 Type II, ISO 27001, PCI AOC, and penetration test results.
- Evaluate fourth-party/Nth-party dependencies, vendor concentration, and systemic risk across the supplier portfolio.
- Establish and lead risk reviews for third-party AI/GenAI tooling with security and privacy teams; address model and data-handling risks and shadow AI.
- Translate findings into concise, business-relevant risk narratives and actionable remediation plans with owners and timelines.
- Operate continuous monitoring leveraging external risk ratings, periodic attestations, threat/breach intelligence, and event-driven triggers.
- Coordinate third-party incident response with SOC/IR; assess impact, drive containment, and track remediation to closure.
- Manage the third-party risk register and findings inventory; escalate aging or accepted risks through governance.
- Maintain visibility into critical vendor resilience and BC/DR posture for high-impact suppliers.
- Partner with Legal and Procurement to define and negotiate security, privacy, and resilience terms (control requirements, right-to-audit, breach notification SLAs, data protection, subprocessor controls).
- Develop a standardized library of contractual security requirements scaled to vendor risk tier.
- Define and report outcome-driven metrics and KRIs (e.g., residual risk trends, assessment cycle time/coverage, time-to-remediate, monitoring coverage, exception aging); deliver executive-ready reporting to governance forums.
- Serve as the primary point of contact for internal/external audits, regulatory exams, and carrier-partner due diligence.
- Build, lead, and develop a high-performing team of vendor risk analysts; set objectives, coach performance, and scale capability through playbooks, training, and quality reviews.
- Drive operational efficiency via process automation and analyst-assistive tooling to focus effort on judgment-intensive decisions.
- 8+ years in information security, IT risk, or GRC, including 4+ years focused on third-party/vendor risk management.
- 2+ years of direct people leadership managing analysts or a risk team.
- Demonstrated experience designing or maturing a TPRM program lifecycle end to end.
- Strong working knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and assessment standards such as SIG/Shared Assessments.
- Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test reports) and translating them into risk decisions.
- Hands-on experience with TPRM/GRC platforms and continuous monitoring/security-rating tools (e.g., ProcessUnity, OneTrust, Prevalent/Mitratech, Whistic, BitSight, SecurityScorecard, or comparable).
- Experience partnering with Procurement and Legal on vendor contracting and security/privacy terms.
- Excellent written and verbal communication, including executive briefing and defensible risk narratives.
- Bachelor's degree in a related field or equivalent professional experience.
- Preferred: certifications such as CTPRP, CISSP, CISA, CRISC, or CISM; experience in regulated consumer or financial environments (e.g., GLBA, PCI DSS, state privacy laws); experience with AI/GenAI risk assessment; familiarity with three lines of defense; experience with automation or AI-assisted workflows in GRC.
- Sound risk judgment balancing rigor with business enablement and speed-to-value.
- Ability to influence without authority across Procurement, Legal, Privacy, Security, and business stakeholders.
- Program design, policy/standard development, and governance execution for TPRM.
- Expertise in vendor risk tiering, due diligence, continuous monitoring, issue management, and secure offboarding.
- Strong analytical skills to assess concentration, systemic risk, and fourth-party dependencies.
- Advanced communication skills; distills complex third-party risk into actionable executive decisions.
- Team leadership, talent development, and operational scaling through playbooks, training, and QA.
- Proficiency with metrics/KRIs, dashboards, and executive reporting.
- Negotiation of contractual security/privacy/resilience terms and control requirements.
N/A
Physical Demands- Stationary Position: Frequently
- Vision: 20/20 corrected vision
- Hearing: Receive detailed information if spoken to
About Asurion
Sourced by ZipRecruiter
As the world's leading tech care company, Asurion eliminates the fears and frustrations associated with technology, to ensure our 300 million customers get the most out of their devices, appliances and connections. We provide insurance, repair, replacement, installation and 24/7 support for everything from cellphones to laptops and household appliances. Our experts are available online, on the phone, at one of our more than 700 stores, or can even come to you.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Nashville, TN, US