Overview

TITLE: TPRM / User Access Review Analyst

DURATION: Contract 9-12 months, possibly longer.

PAY: Market Rate

LOCATION: Remote/ Hybrid: these are 90% offsite (maybe 100% for some). Onsite is downtown Manhattan.

NOTE: All expenses paid by the client for travel, lodging and per-diem  

INDUSTRY: Investment firms for a financial-services cybersecurity engagement

CITIZENSHIP: Must be US Citizen or Legal/Permanent Resident Green Card

REQUIREMENTS: Clear written communication, experience, professionalism, and quality work are a must. Support an existing third-party risk management program and user access review workstream. Likely work includes vendor/security assessments, SOC 2 / ISO / HIPAA-style evidence review, control validation, risk writeups, stakeholder follow-up, and onboarding systems into an access-review platform such as Conductor One.

Strong fit: TPRM, vendor risk, GRC, security assessments, identity governance, user access reviews, and audit/control evidence.

Application questions – Part 1

  • Legal name and if you have a preferred or nickname:
  • Linked In:
  • Best contact info (Email, cell):
  • Citizenship (US, Legal/Permanent Resident Green Card, or other):
  • Availability:
  • Where you live: (City, St, Zip)
  • Willing to work 100% onsite, hybrid or remote:
  • Willing to relocate if necessary:
  • City, State, Zip and desired geographical work locations:
  • Active passport and willing to travel if necessary
  • Hourly/salary history and expectations:
  • Sizes of Staff overseen:
  • Budgetary Responsibility:
  • Hierarchy/Report to:
  • Education/Degrees/Active Certs:

 

JOB SCREENING QUESTIONS – Part 2 – Di@DKKDstaffing.com

Please answer next to each question.

  • How many years of experience and how recent is your experience with TPRM?
  • How many years of experience and how recent is your experience in Supporting an existing third-party risk management program and user access review workstream?
  • How many years of experience and how recent is your experience in vendor/security assessments, SOC 2 / ISO / HIPAA-style evidence review, control validation, risk writeups, and stakeholder follow-up?
  • How many years of experience and how recent is your experience in onboarding systems into an access-review platform such as Conductor One?
  • How many years of experience and how recent is your experience with vendor risk, GRC, security assessments, identity governance, user access reviews, and audit/control evidence?

 www.LinkedIn.com/in/DianeKrehbiel

Tagged as: Information Systems/ Technology, Security