Senior TPRM Analyst at Evolution Cloud Services (EVOCS). . Location: Denver, Colorado. EVOCS OVERVIEW. . EVOCS was founded with a clear purpose: to help businesses operate more effectively, solve complex challenges, and create opportunities for growth through practical expertise and technology solutions.. . As an IT consulting firm, we work with our clients to understand their needs, identify the right technologies, and deliver solutions that improve performance and support their business objectives.. Today, EVOCS is a trusted technology partner to a growing number of organizations and industry leaders. Our team combines technical expertise, business understanding, and a commitment to quality to deliver effective solutions and build lasting client relationships based on responsiveness, consistency, and results.. Senior TPRM Analyst. . 🎯 . Role Overview. As a Senior TPRM Analyst, you are the experienced hand on the third-party risk team. You own the complex vendor reviews — the cloud providers, MSPs, and critical technology vendors where a shallow assessment creates real exposure — and you are the person escalations land on when a finding is contested or a risk needs to be accepted at the leadership level.. . You are also the one who writes what goes up. Executive-ready risk summaries, escalation memos, and risk acceptance recommendations come from you, and they need to be right the first time. This is a senior individual contributor role: depth of judgment, not headcount, is what makes you effective here.. . We are hiring two Senior TPRM Analysts.. . 🧩 What You Will Do. . Vendor Risk Assessment and Due Diligence. - Own end-to-end risk assessments for the highest-criticality third parties, including cloud service providers, managed service providers, and critical technology vendors. - Read SOC 2 Type II reports and ISO 27001 certificates for what they actually say — scope carve-outs, excluded systems, qualified opinions, exceptions in the testing results, and complementary user entity controls — rather than confirming that a document exists. - Evaluate control evidence, penetration test summaries, remediation plans, and security questionnaire responses, and challenge answers that do not hold up. - Set inherent and residual risk ratings, define compensating controls, and track remediation commitments to closure. - Assess vendor security posture in context: data classification, access model, integration depth, and business criticality. . Fourth-Party and Supply Chain Analysis. - Map fourth-party and subcontractor dependencies behind critical vendors, including where the work is actually performed. - Analyze vendor concentration risk and identify single points of failure across the third-party portfolio. - Assess geopolitical and jurisdictional exposure, including offshore delivery locations, data residency, and sub-processor chains. - Incorporate security ratings and continuous monitoring signals into ongoing vendor risk views, and separate real signal from noise. . Escalation, Reporting, and Governance. - Serve as the escalation point for contested findings, vendor pushback, and time-pressured reviews tied to contract or go-live deadlines. - Write executive-ready risk summaries that state the risk, the business impact, and the recommendation in language leadership can act on. - Run risk acceptance conversations with senior business, technology, and procurement stakeholders — documenting the decision, the owner, and the expiration. - Present third-party risk posture, trends, and exceptions to governance forums and senior leadership. - Support and improve the TPRM program itself: assessment standards, tiering criteria, evidence requirements, and playbooks that raise the floor for the whole team. - Mentor junior analysts on evidence review, write-up quality, and stakeholder handling. . 🧠 What You Will Bring. The top candidate will have the following qualifications:. - 7+ years of experience in cybersecurity, risk, audit, or compliance. - At least 5 of those years in third-party risk management or vendor risk specifically. - Demonstrated experience assessing cloud providers, MSPs, and critical technology vendors — not only routine or low-criticality suppliers. - Fluency reading SOC 2 reports and ISO 27001 certifications, including the ability to identify scope carve-outs, qualified opinions, and control exceptions. - Fourth-party and supply chain risk analysis: vendor concentration, criticality tiering, geopolitical exposure, and subcontractor dependencies. - Proven ability to write executive-ready risk summaries for senior audiences. - Experience leading escalation and risk acceptance conversations with senior stakeholders, including holding a position under pressure. - Working knowledge of common control frameworks — NIST CSF, NIST 800-53, ISO 27001/27002, CIS — and how they map to vendor assessments. - Strong interpersonal and communication skills — this role involves frequent interaction with vendors and internal stakeholders via email, calls, and meetings . . Key Skills and Competencies. - Third-party and vendor risk assessment. - Audit report and control evidence analysis. - Fourth-party and supply chain risk. - Executive risk communication and reporting. - Risk acceptance and exception governance. - Stakeholder management and escalation handling. . Ideally you have…. - Certifications that matter here: CTPRP or CTPRA especially, along with CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor. - Hands-on platform experience with ProcessUnity, ServiceNow GRC, or Archer. - Working experience with security ratings tools such as SecurityScorecard, BitSight, RiskRecon, or Black Kite. - Exposure to regulated environments and the vendor oversight expectations that come with them. - Experience contributing to TPRM program design, not only executing assessments. . #LI-Remote. Pay Range for jobs in the US.. Pay Range. $90. - . $105. . USD. 👥 Our Values. . We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.. . The values we live by:. . . Customer-centric Solutions. . Innovation & Excellence. . Integrity & Transparency. . Data-driven Decision Making. . . 📝 Need to Know. . The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.. . All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Senior TPRM Analyst at Evolution Cloud Services (EVOCS)