Jobiglo

No results.

Vendor Risk and GRC Analyst

Patrianna · Gibraltar

🇬🇧 English
SIG CAIQ ISO/IEC 27001:2022 ISO 31000 GDPR DORA

Job description

About the role

Patrianna is seeking a Vendor Risk and GRC Analyst to own the vendor and third‑party risk lifecycle while supporting the broader GRC programme across ISMS, privacy and compliance. The role is central to ensuring that suppliers meet security, legal and regulatory standards.

Key responsibilities

  • Manage the full vendor risk lifecycle: due diligence, security questionnaires, risk rating, contractual safeguards and ongoing monitoring.
  • Maintain the supplier register and drive reassessment cadence based on criticality.
  • Track fourth‑party dependencies and concentration risk, aligning oversight with DORA ICT third‑party requirements and ISO 27001 supplier controls.
  • Support policy maintenance, control mapping and evidence collection to keep the Statement of Applicability audit‑ready.
  • Execute risk assessments using an ISO 31000‑aligned methodology and contribute to RCSA workshops and remediation tracking.
  • Assist with RoPA maintenance, DPIAs and data subject requests, focusing on processor and controller arrangements.
  • Prepare third‑party risk materials for governance committees and keep registers accurate and visible.

Required profile

  • Proven track record in GRC, IT audit, vendor risk or information security with hands‑on third‑party risk responsibility.
  • Practical experience running vendor due diligence, security questionnaires (SIG, CAIQ or equivalent) and contractual risk review.
  • Working knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, GDPR processor obligations; familiarity with DORA third‑party requirements is a plus.
  • Independent thinker who understands the rationale behind controls and can propose improvements.
  • Pragmatic compliance mindset, viewing GRC as a business enabler.

Required skills

  • SIG security questionnaire framework
  • CAIQ security questionnaire framework
  • ISO/IEC 27001:2022
  • ISO 31000
  • GDPR processor obligations
  • DORA third‑party requirements

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Patrianna.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 1 week from now

27 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Patrianna

Gibraltar