Senior Analyst, Third Party Risk Management (remote Eligible - Costa Rica)

Smartsheet Smartsheet · Seattle · Costa Rica · Risk

This role focuses on Third Party Risk Management (TPRM) for a SaaS platform, involving end-to-end vendor assessments, ongoing monitoring, and evaluating security documentation. The analyst will drive program improvements, collaborate cross-functionally, and leverage AI tools for efficiency while ensuring accuracy and accountability. The role requires experience in risk frameworks, vendor security questionnaires, and translating technical findings into business language.

What you'd actually do

  1. Lead end-to-end Third Party Risk Assessments for new and existing vendors, including vendor tiering, scoping, questionnaire management, and findings documentation.
  2. Own the ongoing monitoring and tracking of vendor risk across Smartsheet's third-party portfolio, ensuring timely follow-up on remediation activities and risk acceptance decisions.
  3. Evaluate vendor security documentation including SOC 2 reports, penetration testing results, ISO certifications, and other control attestations — and translate findings into clear, actionable risk summaries for stakeholders.
  4. Drive process improvement initiatives within the TPRM program, identifying opportunities to scale and mature the program through better tooling, automation, and workflow design.
  5. Collaborate cross-functionally with Legal, Procurement, Information Security, Privacy, and business stakeholders to ensure vendor risk considerations are embedded in sourcing and renewal decisions.

Skills

Required

  • Third Party Risk Management
  • Vendor Risk Management
  • GRC
  • Information Security
  • Audit
  • Compliance
  • Risk Frameworks (NIST, ISO 27001, COSO, COBIT, AICPA SOC/TSP, PCI DSS)
  • Vendor Security Questionnaires (SIG, CSA CAIQ)
  • SOC 2 reports
  • Penetration testing summaries
  • Vendor security attestations
  • Cross-functional collaboration
  • Written and verbal communication skills in English
  • Critical thinking and judgment
  • Evaluating AI-generated content

Nice to have

  • Vendor risk management platforms (AuditBoard, Archer, OneTrust, ServiceNow GRC, Vanta, Coupa)
  • SaaS, cloud, or technology company environments
  • AI-assisted workflows in a GRC or compliance context
  • Audit processes support
  • Certifications (CISA, CRISC, CTPRP)
  • Operational risk experience

What the JD emphasized

  • must reside in Costa Rica
  • 5+ years of experience in third party risk management, vendor risk, GRC, information security, audit, or compliance — with direct experience conducting vendor or third-party risk assessments.