The consultant will support the day-to-day operations of an enterprise Third-Party Risk Management program by coordinating vendor security assessments and tracking remediation activities. They are responsible for maintaining accurate documentation and ensuring vendor risk activities align with security and compliance standards.
Junior Cybersecurity Risk Management Consultant
$55-$60/hr | 3-Month Consultant Contract | W2 |
Remote
Del Oro Consulting
is seeking a Junior Cybersecurity Risk Management Consultant to
support the day-to-day operations of an enterprise Third-Party Risk Management
(TPRM) program. This consultant is responsible for coordinating vendor security
assessments, tracking remediation activities, maintaining accurate
documentation, and ensuring vendor risk activities are completed efficiently
and in accordance with established security and compliance standards.
The ideal
candidate is highly organized, detail-oriented, and experienced working within
cybersecurity governance, risk, and compliance (GRC) environments. This is a
remote engagement supporting a large enterprise cybersecurity team.
Responsibilities:
- Support the onboarding of
new third-party vendors into the organization's Third-Party Risk
Management (TPRM) program.
- Review vendor intake
requests to ensure required information is complete and accurate.
- Coordinate the
distribution, collection, and tracking of vendor security questionnaires
and assessment documentation.
- Monitor vendor assessment
progress and proactively follow up on outstanding questionnaires, evidence
requests, and documentation.
- Maintain accurate
assessment records and workflow updates within the ServiceNow platform.
- Collect, organize, and
maintain vendor security documentation, including policies,
certifications, and supporting evidence.
- Coordinate remediation
efforts by tracking identified security gaps and following up on
corrective actions.
- Validate vendor security
controls and supporting documentation against established security
requirements.
- Support vendor risk
tracking, reporting, and status updates for internal stakeholders.
- Assist with daily
operational activities within the Third-Party Risk Management program as
assigned by the TPRM Manager.
- Ensure all assigned work is
completed according to established priorities and timelines.
Deliverables:
- Vendor risk assessment
documentation
- Assessment status report
updates
- Updated vendor inventory
records
- Organize vendor security
documentation repositories
- Vendor communication logs
- Engagement summary
Qualifications:
- 3+ years of experience
supporting Third-Party Risk Management (TPRM), Vendor Risk Management
(VRM), Cybersecurity Risk Management, and/or Governance, Risk &
Compliance (GRC) programs.
- Experience coordinating
vendor security assessments and managing assessment documentation.
- Familiarity with industry
security questionnaires (SIG, CAIQ, custom questionnaires, etc.).
- Experience working with
ServiceNow
- Understanding of
cybersecurity controls and vendor risk assessment processes.
- Strong organizational
skills with the ability to manage multiple vendor assessments
simultaneously.
- Excellent written and
verbal communication skills with experience interacting directly with
vendors and internal stakeholders.
- Strong attention to detail
and ability to maintain accurate records and documentation.
Details of Position:
- Work Arrangement: Remote
- $55-$60/hr Consultant, 3-Month Contract Opportunity on W2
- Benefits include Medical,
Dental, Vision & 401(k) (with a match)
- Applicants must be
authorized to work for any employer in the United States. We are currently
unable to sponsor or take over sponsorship of employment Visa.
Del Oro Consulting is an equal
opportunity employer, and all qualified applicants will receive consideration
for employment without regard to race, color, religion, sex, national origin,
disability status, protected veteran status, or any other characteristic
protected by law.