RequirementsMust have:· 2–3 years of experience in GRC, IT audit, information security, or third-party risk support roles (internship or entry-level professional experience acceptable). · Basic understanding of vendor risk assessment concepts and security due diligence documentation (policies, certifications, audit reports).
Nice to have:· Exposure to — or coursework/training in — SIG questionnaires or similar standardized security questionnaires is a plus, not mandatory.· Comfortable with structured, high-volume administrative and coordination work (tracking, correspondence, documentation review).· General exposure to IRM/GRC platforms is a plus; not required. Willingness and aptitude to learn Radian's NAVEX/EBX environment is expected.
- Responsabilities:
- Evaluate and assess the security measures and controls implemented within an organization's information systems and infrastructure.
- Ensure that the organization's cybersecurity practices are aligned with established security standards, policies, regulations, and industry best practices.
- Conduct thorough reviews of the organization's security posture to identify vulnerabilities, assess risks, and provide recommendations for improvement.
- Collaborate with internal teams to implement corrective and preventive measures and ensure compliance with established security policies.