Remote | Security & Vendor Risk Specialist — $85–$105/hour

24-Mag

  • New York, New York
  • 9 days ago
  • Remote

    Highlights

    Selected professionals will review simulated compliance evidence, identify subtle security and scope issues, assess data-handling risks, and develop detailed evaluation rubrics reflecting how experienced security reviewers assess new vendors and contract renewals. We are sharing a specialised part-time consulting opportunity for senior security and vendor-risk professionals with extensive experience in third-party risk management, SOC 2 review, security questionnaires, penetration-test evidence, and supplier security assessments.

    Numbers & Facts

    LocationNew York, New York (
    Remote
    )
    Website4-mag.com/privacy-policy

    Description

    We are sharing a specialised part-time consulting opportunity for senior security and vendor-risk professionals with extensive experience in third-party risk management, SOC 2 review, security questionnaires, penetration-test evidence, and supplier security assessments.

    This role supports an advanced AI initiative focused on creating realistic simulations of enterprise procurement and vendor-security workflows. Selected professionals will review simulated compliance evidence, identify subtle security and scope issues, assess data-handling risks, and develop detailed evaluation rubrics reflecting how experienced security reviewers assess new vendors and contract renewals.

    Key Responsibilities

    Vendor Security Review

    • Review simulated vendor SOC 2 reports, security questionnaires, and penetration-test evidence
    • Evaluate vendor documentation against defined buyer security standards
    • Assess whether submitted evidence adequately supports stated security controls
    • Identify missing documentation, control gaps, inconsistencies, and unsupported claims
    • Produce clear recommendations for approval, remediation, escalation, or rejection

    Compliance Evidence Assessment

    • Review SOC 2 scope, reporting periods, control coverage, exceptions, and auditor conclusions
    • Identify scope mismatches between vendor services and assessed systems
    • Detect expired or insufficient bridge letters and gaps between reporting periods
    • Evaluate whether penetration-test evidence is current, relevant, and appropriately scoped
    • Assess the quality and completeness of supporting compliance materials

    Data Handling & Sub-Processor Risk

    • Evaluate how vendors collect, access, process, store, and transfer sensitive data
    • Assess risks associated with sub-processors, hosting providers, and downstream service partners
    • Review data residency, retention, deletion, access-control, and encryption considerations
    • Identify security concerns requiring additional due diligence or contractual safeguards
    • Evaluate vendor responses within realistic procurement and renewal contexts

    Rubric & Reference Response Development

    • Author detailed, step-level rubrics for vendor-security review tasks
    • Develop high-quality reference responses reflecting experienced professional judgment
    • Define evaluation criteria for evidence quality, control effectiveness, data risk, and approval readiness
    • Distinguish minor documentation issues from material security deficiencies
    • Refine scoring standards to support consistent assessment across reviewers

    Ideal Profile

    Strong candidates may have:

    • At least 8 years of professional experience in security review, vendor risk management, third-party risk, or information security
    • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
    • Strong understanding of vendor due diligence and third-party security assessment processes
    • Experience identifying control gaps, evidence limitations, and scope inconsistencies
    • Familiarity with data-handling, privacy, sub-processor, and supply-chain security risks
    • Excellent written communication and structured analytical skills
    • Comfort producing detailed rubric-style feedback and defensible review conclusions
    • Ability to work independently within a remote and asynchronous environment

    Educational Background

    • A degree in cybersecurity, information systems, computer science, risk management, business, or a related discipline may be helpful
    • Professional certifications such as CISSP, CISA, CISM, CRISC, or comparable credentials may strengthen an application
    • Formal training in third-party risk management, security assurance, or compliance assessment may also be valuable
    • Equivalent senior-level professional experience in vendor security or third-party risk may be considered

    Nice to Have

    • CISSP, CISA, CISM, CRISC, or another relevant security certification
    • Experience within a formal third-party risk management programme
    • Background in SaaS, cloud, technology, or enterprise vendor assessments
    • Familiarity with security frameworks such as ISO 27001, NIST, or similar standards
    • Experience reviewing penetration-test reports and remediation evidence
    • Knowledge of procurement, contract-renewal, and vendor-onboarding workflows
    • Prior task-writing, rubric-authoring, quality-review, or AI training-data experience
    • Experience collaborating with procurement, legal, privacy, compliance, and IT teams

    Why This Opportunity

    • Apply senior vendor-security expertise to realistic, high-impact evaluation work
    • Shape how advanced AI systems understand third-party security and risk-review workflows
    • Work across SOC 2 reports, security questionnaires, penetration tests, and data-risk assessments
    • Develop evaluation rubrics and reference responses grounded in real-world professional judgment
    • Participate in flexible remote work with competitive hourly compensation

    Contract Details

    • Independent contractor role
    • Fully remote with flexible scheduling
    • Competitive rates between $85–$105 per hour depending on expertise and project scope
    • Weekly payments via Stripe or Wise
    • Work may include vendor-security review, compliance-evidence assessment, rubric development, reference-response creation, and simulation auditing
    • Projects may be extended, shortened, or adjusted depending on scope and performance
    • Work will not involve access to confidential or proprietary information from any employer, client, or institution

    About the Platform

    This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

    By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.

    Similar Jobs