JOBSEARCHER

TPRM Analyst

Evocs OverviewEVOCS was founded with a clear purpose: to help businesses operate more effectively, solve complex challenges, and create opportunities for growth through practical expertise and technology solutions.As an IT consulting firm, we work with our clients to understand their needs, identify the right technologies, and deliver solutions that improve performance and support their business objectives.Today, EVOCS is a trusted technology partner to a growing number of organizations and industry leaders. Our team combines technical expertise, business understanding, and a commitment to quality to deliver effective solutions and build lasting client relationships based on responsiveness, consistency, and results.TPRM AnalystEVOCS OverviewEVOCS’s journey began with a mission to empower businesses with advisory expertise, empowered with ideal technologies to provide them with comprehensive solutions to grow and prosper.Founded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success.If you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let’s talk!🎯 Role OverviewAs a TPRM Analyst, you are the execution layer of the third-party risk program. You carry the assessment volume — questionnaires out, evidence in, controls reviewed, findings documented, remediation tracked — and you keep the work moving without needing someone standing behind you.Two things make or break this role. The first is written documentation: your assessments and findings are read by people who were not on the call, so they have to stand on their own. The second is data quality. A third-party risk program is only worth what its records say, and inconsistent entries quietly erode the value of everything the program produces. If you are the person who notices that two vendors were tiered differently on the same facts, you will do well here.We are hiring four TPRM Analysts.🧩 What You Will DoAssessment ExecutionConduct vendor security assessments and third-party reviews across a high-volume queue, on schedule and to a consistent standardIssue and manage security questionnaires, chase evidence requests, and validate what comes back against what was asked forReview control evidence — policies, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and supporting artifacts — and document what the evidence does and does not coverIdentify gaps and findings, assign risk ratings under the program’s tiering criteria, and write them up clearly enough that a reader outside the review understands the exposureEscalate complex, contested, or high-criticality reviews to senior analysts with the work already organizedRemediation and Follow-ThroughBuild and track remediation plans with vendors and internal owners, including agreed actions, owners, and due datesChase stakeholders through to closure — vendors, business owners, procurement, and legal — and keep items from aging out quietlyRe-validate evidence at remediation closure rather than accepting a status update at face valueMaintain reassessment schedules for in-scope vendors and flag material changes between cyclesRecords, Reporting, and Data QualityOwn the accuracy and consistency of your entries in the risk register and TPRM platform: complete fields, correct tiering, current status, and traceable evidence linksMaintain assessment documentation to an audit-ready standardProduce status reporting on queue volume, aging, findings, and open remediation itemsFlag inconsistencies in criteria application, data entry, or workflow, and help tighten the process that produced them🧠 What You Will BringThe Top Candidate Will Have The Following Qualifications5+ years of experience in cybersecurity, audit, compliance, risk, or vendor managementAt least 3 of those years conducting vendor security assessments or third-party reviewsHands-on comfort with the core mechanics of the role: security questionnaires, evidence requests, control reviews, remediation plans, and risk registersClear, structured written documentation — assessments and findings that hold up when read by someone who was not in the conversationStrong attention to data quality and consistency across records, ratings, and documentationAbility to drive items to closure independently, following up with vendors and internal stakeholders without being chased yourselfWorking familiarity with common control frameworks such as NIST CSF, NIST 800-53, ISO 27001/27002, or CISStrong interpersonal and communication skills — this role involves frequent interaction with vendors and internal stakeholders via email, calls, and meetingsKey Skills And CompetenciesVendor security assessment executionControl and evidence reviewRemediation tracking and stakeholder follow-throughRisk register and documentation hygieneWritten risk communicationTime and queue management across concurrent reviewsIdeally you have…Certifications such as Security+ or CTPRP; CISA, CRISC, CISM, or ISO 27001 Lead Auditor are a plusHands-on platform experience with ProcessUnity, ServiceNow GRC, or ArcherExposure to security ratings tools such as SecurityScorecard, BitSight, RiskRecon, or Black KiteExperience assessing cloud providers, MSPs, or technology vendors specificallyExperience working an assessment queue against SLAs in a regulated environmentPay Range for jobs in the US.Pay Range$75 - $90 USD👥 Our ValuesWe are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.The Values We Live ByCustomer-centric SolutionsInnovation & ExcellenceIntegrity & TransparencyData-driven Decision Making📝 Need to KnowThe posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.