Talent.com
Third-Party Risk Management (TPRM) Analyst
Third-Party Risk Management (TPRM) AnalystSaronic • San Diego, CA, United States
Third-Party Risk Management (TPRM) Analyst

Third-Party Risk Management (TPRM) Analyst

Saronic • San Diego, CA, United States
1 day ago
Job type
  • Permanent
Job description

Saronic Technologies is a leader in revolutionizing defense autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations for the Department of Defense (DoD) through autonomous and intelligent platforms.

We are seeking a Third-Party Risk Management Analyst to join our Governance, Risk, and Compliance (GRC) team supporting a defense and aerospace organization. In this role, you will be responsible for evaluating, managing, and mitigating risks associated with third-party vendors, suppliers, and service providers. You will work closely with the Business Units, Procurement, Security, Legal, IT, Supply Chain, and Compliance teams to ensure our third parties comply withNIST SP 800-171, DFARS 252.204-7012, CMMC, and ITAR / EAR obligationsand meet contractual requirements.

This position is ideal for a professional with 3-5 years of experience in third-party risk management, vendor due diligence, or related cybersecurity compliance functions who thrives in a dynamic, mission-driven environment.This role contributes directly to safeguarding sensitive defense data, maintaining compliance across the third-party ecosystem, and strengthening supply chain resilience.

Responsibilities

  • Conduct inherent and residual risk assessments of third parties based on data classification, service criticality, geographic exposure, and regulatory obligations.
  • Perform due diligence reviews, including security and compliance questionnaires, evidence validation, and documentation of control effectiveness.
  • Partner with Business Units, Procurement, Legal, Information Security, and Compliance to ensure timely onboarding, risk evaluation, and remediation tracking to closure and follow-up validation.
  • Support continuous monitoring activities, including periodic risk assessments, sanctions screening, and adverse-media reviews across the vendor lifecycle.
  • Monitor and analyze third-party performance, incidents, and risk indicators to identify emerging risk and trends.
  • Collaborate with cross-functional teams to ensure adherence to defense-specific standards and regulatory frameworks (e.g., NIST SP 800-171, DFARS, CMMC, ITAR).
  • Support the design and enhancement of TPRM workflows, including process automation and data-driven risk analytics.
  • Assist in developing and maintaining the third-party inventory, ensuring all vendor profiles, tier classifications, and risk ratings are accurately captured, continuously updated, and aligned with program governance requirements.
  • Create and maintainexecutive dashboards and risk reports summarizing vendor posture, risk trends, and remediation progress for leadership.
  • Assist in regulatory, customer, and internal audits, ensuring third-party documentation and evidence meetdefense-sector and compliance requirements.

Required Qualifications

  • Bachelor's degree in business administration, risk management, information security, cybersecurity, or related discipline (or equivalent work experience).
  • 3-5 years of hands-on experience in third-party risk management, supply chain risk management (SCRM), cybersecurity governance, or compliance.
  • Working knowledge of defense and federal regulatory frameworks, including NIST SP 800-171, DFARS 252.204-7012, CMMC Levels 1-2, ITAR / EAR, ISO 27001, and SOC 2.
  • Demonstrated experience performing vendor risk assessments, evaluating due diligence evidence, documenting findings, and tracking remediation through closure.
  • Solid understanding of information security principles, data protection requirements, and control frameworks relevant to defense supply chains.
  • Proven project management and coordination skills, with the ability to manage multiple concurrent assessments in a deadline-driven environment.
  • Strong written and verbal communication skills, including the ability to translate technical risks into business-level insights and recommendations for leadership.
  • Proficient in Microsoft 365, Excel-based risk scoring models, and GRC / TPRM platforms (e.g., ServiceNow, Archer, ProcessUnity, OneTrust).
  • Strong analytical and critical-thinking skills, with the ability to identify and assess emerging risks proactively.
  • Excellent interpersonal and communication skills, with the ability to collaborate effectively across business units, technical teams, and leadership levels.
  • High attention to detail with strong organizational and time-management abilities.
  • Proven ability to prioritize tasks and manage competing deadlines in a fast-paced, mission-critical environment.
  • Strong sense of ethics, confidentiality, and commitment to national security compliance.
  • This role requires the ability to obtain and maintain a security clearance
  • Preferred Qualifications

  • Experience working in or supporting defenseor government contracting environments.
  • Familiarity with SCRM (supply chain risk management) principles and continuous monitoring practices.
  • Experience with vendor lifecycle management and related legal and contract management processes.
  • Prior experience supporting vendor risk program audits or readiness reviews.
  • Understanding of export compliance and U.S. Person verification requirements under ITAR / EAR.
  • Relevant professional certification(s) such as CTPRP (Certified Third-Party Risk Professional), CRVPM, CTPRA (Certified Third-Party Risk Assessor), C3PRMP (Certified Third-Party Risk Management Professional), CRISC (Certified in Risk and Information Systems Control), or CCP (CMMC Certified Professional).
  • Physical Demands

  • Prolonged periods of sitting and computer work
  • Occasional standing and walking within the office
  • Manual dexterity to operate computers and office equipment
  • Visual acuity to read screens and documents
  • Occasional reaching or lifting up to 20 pounds (e.g., equipment or supplies)
  • Benefits :

    Medical Insurance : Comprehensive health insurance plans covering a range of services

    Saronic pays 100% of the premium for employees and 80% for dependents

    Dental and Vision Insurance : Coverage for routine dental check-ups, orthodontics, and vision care

    Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents

    Time Off : Generous PTO and Holidays

    Parental Leave : Paid maternity and paternity leave to support new parents

    Competitive Salary : Industry-standard salaries with opportunities for performance-based bonuses

    Retirement Plan : 401(k) plan

    Stock Options : Equity options to give employees a stake in the company's success

    Life and Disability Insurance : Basic life insurance and short- and long-term disability coverage

    Pet Insurance : Discounted pet insurance options including 24 / 7 Telehealth helpline

    Additional Perks : Free lunch benefit and unlimited free drinks and snacks in the office

    This role requires access to export-controlled information or items that require "U.S. Person" status. As defined by U.S. law, individuals who are any one of the following are considered to be a "U.S. Person" : (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).

    Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.

    Create a job alert for this search

    Risk Management Analyst • San Diego, CA, United States

    Related jobs
    Customs and Border Protection Officer - Experienced - Location incentives

    Customs and Border Protection Officer - Experienced - Location incentives

    U.S. Customs and Border Protection • Tecate, CA
    Full-time
    Customs and Border Protection Officer (CBPO).Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of high...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Engineer III • •

    Cybersecurity Engineer III • •

    SimVentions, Inc - Glassdoor 4.6 • Santee, CA, US
    Full-time
    SimVentions, consistently voted one Virginia's Best Places to Work, is looking for an experienced cybersecurity professional to join our team! As a Cybersecurity Engineer III, you will play a key r...Show more
    Last updated: 1 day ago • Promoted
    Customs and Border Protection Officer - Experienced

    Customs and Border Protection Officer - Experienced

    U.S. Customs and Border Protection • Tecate, CA, United States
    Full-time
    Customs and Border Protection Officer (CBPO).Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of high...Show more
    Last updated: 30+ days ago • Promoted
    GSOC Security Analyst / Physical Security Risk Analyst

    GSOC Security Analyst / Physical Security Risk Analyst

    Viasat • Carlsbad, CA, United States
    Full-time
    At Viasat, we're on a mission to deliver connections with the capacity to change the world.For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries arou...Show more
    Last updated: 30+ days ago • Promoted
    Sr. Compensation Analyst, Temporary

    Sr. Compensation Analyst, Temporary

    Viasat • Carlsbad, CA, United States
    Full-time
    At Viasat, we're on a mission to deliver connections with the capacity to change the world.For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries arou...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Engineer - PTO, Paid Holidays & Paid Leave

    Cybersecurity Engineer - PTO, Paid Holidays & Paid Leave

    SimVentions, Inc - Glassdoor 4.6 • Encinitas, CA, US
    Full-time
    SimVentions, consistently voted one Virginia's Best Places to Work, is looking for an experienced cybersecurity professional to join our team! As a Cybersecurity Engineer III, you will play a key r...Show more
    Last updated: 1 day ago • Promoted
    Customs and Border Protection Officer - Entry Level

    Customs and Border Protection Officer - Entry Level

    U.S. Customs and Border Protection • Tecate, CA, United States
    Full-time
    Customs and Border Protection Officer (CBPO).Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of high...Show more
    Last updated: 30+ days ago • Promoted
    Lead SOX Risk Advisor

    Lead SOX Risk Advisor

    California Staffing • San Diego, CA, US
    Full-time
    Come join Intuit as a Lead SOX Risk Advisor within the SOX Risk and Compliance Organization (SRCO).SRCO is a newly established function, in the Controllership, Assurance and Operations organization...Show more
    Last updated: 3 days ago • Promoted
    Director of Risk Management

    Director of Risk Management

    Family Health Centers of San Diego • San Diego, CA, United States
    Full-time
    Family Health Centers of San Diego.Family Health Centers of San Diego (FHCSD) is passionate about providing exceptional health care to all, especially underserved communities.Founded over 50 years ...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Engineer lll - Industry leading benefits

    Cybersecurity Engineer lll - Industry leading benefits

    SimVentions, Inc - Glassdoor 4.6 • Santee, CA, US
    Full-time
    SimVentions, consistently voted one Virginia's Best Places to Work, is looking for an experienced cybersecurity professional to join our team! As a Cybersecurity Engineer III, you will play a key r...Show more
    Last updated: 1 day ago • Promoted
    Cyber Security Risk Management Engineer

    Cyber Security Risk Management Engineer

    Viasat • Carlsbad, CA, United States
    Full-time
    At Viasat, we're on a mission to deliver connections with the capacity to change the world.For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries arou...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Engineer - Competitive 401(k) programs

    Cybersecurity Engineer - Competitive 401(k) programs

    SimVentions, Inc - Glassdoor 4.6 • Coronado, CA, US
    Full-time
    SimVentions, consistently voted one Virginia's Best Places to Work, is looking for an experienced cybersecurity professional to join our team! As a Cybersecurity Engineer III, you will play a key r...Show more
    Last updated: 1 day ago • Promoted
    Border Patrol Agent - Experienced - Up to 30k Sign On Bonus

    Border Patrol Agent - Experienced - Up to 30k Sign On Bonus

    U.S. Customs and Border Protection • Alpine, CA, United States
    Full-time
    Border Patrol Agent (BPA) - Experienced (GL-9 GS-11).Check out these higher-salaried federal law enforcement opportunities with the U. Your current or prior law enforcement experience may qualify yo...Show more
    Last updated: 30+ days ago • Promoted
    Customs and Border Protection Officer - Entry Level - Location incentives

    Customs and Border Protection Officer - Entry Level - Location incentives

    U.S. Customs and Border Protection • Tecate, CA
    Full-time
    Customs and Border Protection Officer (CBPO).Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of high...Show more
    Last updated: 30+ days ago • Promoted
    Strategic PMO Managed Services - Senior Analyst

    Strategic PMO Managed Services - Senior Analyst

    PwC • San Diego, CA, United States
    Full-time
    At PwC, our people in project portfolio management focus on optimising project portfolios to drive strategic business outcomes. These individuals oversee project selection, prioritisation, and resou...Show more
    Last updated: 4 days ago • Promoted
    Treasury and Risk Analyst

    Treasury and Risk Analyst

    Viasat • Carlsbad, CA, United States
    Full-time
    At Viasat, we're on a mission to deliver connections with the capacity to change the world.For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries arou...Show more
    Last updated: 15 days ago • Promoted
    Border Patrol Agent - Entry Level - Up to 30k Sign On Bonus

    Border Patrol Agent - Entry Level - Up to 30k Sign On Bonus

    U.S. Customs and Border Protection • Descanso, CA, United States
    Full-time
    Border Patrol Agent (BPA) GL-5 / 7 grade levels.IMPORTANT NOTICE : Duty assignments available at the time of offer may include the Southwest Border, including prioritized locations.Border Patrol deter...Show more
    Last updated: 30+ days ago • Promoted
    Analyst, Management-Mid

    Analyst, Management-Mid

    International Executive Service Corps • San Diego, CA, United States
    Full-time
    SEA 21, NAVSEA’s Director of Surface Ship Maintenance, Modernization, and Sustainment is seeking professional support services (PSS) to support the Government's existing organization, personnel, kn...Show more
    Last updated: 1 day ago • Promoted