Overview
TITLE: TPRM / User Access Review Analyst
DURATION: Contract 9-12 months, possibly longer.
PAY: Market Rate
LOCATION: Remote/ Hybrid: these are 90% offsite (maybe 100% for some). Onsite is downtown Manhattan.
NOTE: All expenses paid by the client for travel, lodging and per-diem
INDUSTRY: Investment firms for a financial-services cybersecurity engagement
CITIZENSHIP: Must be US Citizen or Legal/Permanent Resident Green Card
REQUIREMENTS: Clear written communication, experience, professionalism, and quality work are a must. Support an existing third-party risk management program and user access review workstream. Likely work includes vendor/security assessments, SOC 2 / ISO / HIPAA-style evidence review, control validation, risk writeups, stakeholder follow-up, and onboarding systems into an access-review platform such as Conductor One.
Strong fit: TPRM, vendor risk, GRC, security assessments, identity governance, user access reviews, and audit/control evidence.
Application questions – Part 1
- Legal name and if you have a preferred or nickname:
- Linked In:
- Best contact info (Email, cell):
- Citizenship (US, Legal/Permanent Resident Green Card, or other):
- Availability:
- Where you live: (City, St, Zip)
- Willing to work 100% onsite, hybrid or remote:
- Willing to relocate if necessary:
- City, State, Zip and desired geographical work locations:
- Active passport and willing to travel if necessary
- Hourly/salary history and expectations:
- Sizes of Staff overseen:
- Budgetary Responsibility:
- Hierarchy/Report to:
- Education/Degrees/Active Certs:
JOB SCREENING QUESTIONS – Part 2 – Di@DKKDstaffing.com
Please answer next to each question.
- How many years of experience and how recent is your experience with TPRM?
- How many years of experience and how recent is your experience in Supporting an existing third-party risk management program and user access review workstream?
- How many years of experience and how recent is your experience in vendor/security assessments, SOC 2 / ISO / HIPAA-style evidence review, control validation, risk writeups, and stakeholder follow-up?
- How many years of experience and how recent is your experience in onboarding systems into an access-review platform such as Conductor One?
- How many years of experience and how recent is your experience with vendor risk, GRC, security assessments, identity governance, user access reviews, and audit/control evidence?
www.LinkedIn.com/in/DianeKrehbiel