Grc Analyst, Third-party Risk Management

Samsara Samsara · Enterprise · India · Remote · IT Security

Samsara is seeking a GRC Analyst to assess third-party risk and build automated workflows for their vendor risk management program. The role involves partnering with legal, procurement, and engineering teams to identify and mitigate vendor risks, and ensuring security reviews scale with company growth. Experience with GRC platforms and frameworks like NIST, SOC 2, and ISO 27001 is preferred, as is experience with AI assistance in workflow creation.

What you'd actually do

  1. Work with the local Senior Manager of Security Engineering to provide programmatic updates and communicate both program, third-party, and technical risk to the broader Information Security leadership team
  2. Drive automation and efficiency in the TPRM program through the use of third-parties, such as Zip and Vanta, and creating native solutions; ensuring security reviews and reassessments scale with company growth.
  3. Partner with Procurement, Legal, and Privacy to ensure vendor risks are identified, documented, and mitigated throughout the vendor lifecycle.
  4. Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices

Skills

Required

  • 3+ years of experience in the governance, risk, and compliance space
  • Experience implementing or maintaining vendor-risk programs
  • Experience performing security and maturity assessments
  • Supporting the creation or maintenance of risk registers, compliance inventories, and control mappings across internal and external systems
  • Ability to work with systems teams to collaboratively implement security controls across a diverse range of systems, such as Okta, Slack, Salesforce, and internal tooling
  • Professional experience coordinating and interacting with external auditors, internal engineering teams, business stakeholders, senior leadership, and security operations teams on procurement activities, audit controls and compliance requirements
  • Experience conducting vendor risk assessments, including reviewing security certifications, penetration tests, and policies.
  • Strong understanding of vendor integration risks and permission scoping across SaaS platforms (eg. Slack, Google Workspace, and Salesforce)
  • Ability to translate complex technical findings and requirements into clear business risks and requirements to non technical stakeholders.

Nice to have

  • Experience working with NIST Cybersecurity Framework profiles, SOC 2, ISO 27001, or similar frameworks
  • Experience creating workflows through automation and AI assitance
  • Experience working within common GRC and procurement platforms such as Zip and Vanta.
  • Experience managing high volumes of vendor requests and competing priorities.
  • Prior assessment experience in the Software-as-a-Service industry

What the JD emphasized

  • building automated workflows to support a scaling program
  • AI enabled workflows to scale the vendor risk program
  • Experience creating workflows through automation and AI assitance