Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Patrianna

Vendor Risk, GRC Analyst

Patrianna

Managing vendor and third-party risk lifecycle, supporting GRC program for fast-scaling tech company. Collaborating on compliance and risk management efforts.

Posted 7/20/2026full-timeRemote • 🇧🇬 BulgariaMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in vendor and third-party risk management, including executing risk assessments aligned with ISO 31000 and maintaining compliance with ISO 27001 and GDPR. Proficient in vendor due diligence, security questionnaires, and policy maintenance to ensure audit readiness.

Highest-signal resume keywords
Vendor Risk ManagementISO 27001 Supplier ControlsRisk Assessment ExecutionGRC ExperienceClear Communication

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vendor Due DiligenceRisk AssessmentISO 31000 MethodologySecurity QuestionnairesControl MappingDPIAsRoPA MaintenanceStatement of ApplicabilityCritical Supplier OversightFourth-Party Dependency Tracking
Soft Skills
Independent ThinkingPragmatic Compliance MindsetClear Communication
Industry Keywords
GRCIT AuditInformation SecurityDORA ICT RequirementsGDPR Processor ObligationsSupplier RegisterRisk & Control Self-AssessmentConcentration RiskEvidence CollectionAudit-Ready

About the role

Key responsibilities & impact
  • Own the vendor and third-party risk lifecycle for a fast-scaling tech company.
  • Maintain the supplier register and drive reassessment cadence based on criticality.
  • Track fourth-party dependencies and concentration risk across critical suppliers, aligning oversight with DORA ICT third-party requirements and ISO 27001 supplier controls.
  • Support policy maintenance, control mapping, and evidence collection to keep the Statement of Applicability (SoA) audit-ready.
  • Execute risk assessments using an ISO 31000-aligned methodology and contribute to Risk & Control Self-Assessment workshops and remediation tracking.
  • Support RoPA maintenance, DPIAs, and data subject requests.

Requirements

What you’ll need
  • Solid GRC grounding — A proven track record in GRC, IT audit, vendor risk, or information security, with hands-on third-party/supplier risk responsibility.
  • Third-party risk proficiency — Practical experience running vendor due diligence, security questionnaires (SIG, CAIQ, or equivalent), and contractual risk review.
  • Framework knowledge — Working knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, and GDPR processor obligations; familiarity with DORA third-party requirements is a plus.
  • Independent thinker — Understand the *why* behind a control, spot gaps, and propose improvements without being prompted.
  • Pragmatic compliance mindset — Balance rigor with momentum.
  • Clear communicator — Precise writing across questionnaires, risk memos, and supplier-facing responses.

Benefits

Comp & perks
  • Equal Opportunities Statement
  • Diversity fuels innovation and growth.
  • Values diverse perspectives and skills.