Technical Risk Management Professional
Job Summary
Our client is seeking an experienced Third-Party Risk Management / Technical Risk Management professional to join their team. This is a contract opportunity for a hands-on risk professional who can independently manage the vendor risk lifecycle, maintain and analyze an enterprise technical risk register, perform technical and quantitative risk assessments, and translate technical findings into business-relevant risk. The ideal candidate will have strong experience with vendor risk assessments, risk quantification methodologies such as FAIR, security frameworks, and technical risk analysis, while being comfortable operating independently with minimal oversight.
Contract Details
- Contract type and duration: Contract, approximately 1 year
- Contract dates: 10/19/2026 – 10/15/2027
- Work location: Remote – US
- Onsite, hybrid or remote expectations: Fully Remote
Core Responsibilities
- Own and operate the Technical Risk Management program end-to-end, including maintaining the enterprise risk register and driving risk identification, analysis, ownership, and closure
- Manage the Third-Party Risk Management lifecycle for assigned vendors, including intake, inherent-risk tiering, security questionnaire review, evidence/documentation review, and risk scoring
- Apply structured risk quantification methods such as FAIR or similar methodologies to assess and prioritize vendor and technical risks in financial or business-impact terms
- Perform technical risk analysis across infrastructure, applications, and vendor architecture findings
- Translate technical control gaps and findings into clear, business-relevant risk statements
- Partner with security engineering and GRC stakeholders to evaluate architecture diagrams, scan results, control configurations, and other technical evidence
- Track vendor findings and remediation commitments through closure and escalate stalled items as needed
- Monitor existing vendors for material changes in risk posture, including breach disclosures, control changes, and subprocessor changes
- Prepare and present risk and TPRM reporting, metrics, and updates for internal stakeholders and leadership
- Operate independently using established TPRM and risk management processes while exercising judgment on prioritization and escalation
Required Skills/Experience (Must-Haves)
- 5+ years of hands-on experience managing third-party/vendor risk assessments
- 3+ years of experience in technical or quantitative risk management
- Strong experience with vendor intake, inherent-risk tiering, security questionnaires, documentation/evidence review, and risk scoring
- Experience applying FAIR or similar risk quantification methodologies
- Experience independently owning and maintaining a risk register or risk management program
- Strong technical fluency with infrastructure, application, and vendor architecture and security documentation
- Ability to critically evaluate security controls and determine whether they address the underlying risk
- Working knowledge of common security frameworks including SOC 2, ISO 27001, and NIST CSF
- Strong organizational skills and ability to manage a high-volume caseload of vendor assessments and risk register items
- Excellent written and verbal communication skills for vendor-facing correspondence, technical findings, and leadership-level reporting
Preferred Skills/Experience (Nice-to-Haves)
- Experience working in a SaaS or technology company’s TPRM or Technical Risk Management function
- Formal training or certification in FAIR / Open FAIR
- Familiarity with GRC or TPRM tools such as OneTrust, Vanta, Archer, ServiceNow GRC, or similar platforms
- CISSP, CISA, or CRISC certification
- Experience with enterprise-level technical risk analysis and risk quantification
- Third-Party Risk Management and Technical Risk Management expertise
Key Competencies & Behaviors
- Strong technical analysis and risk assessment skills
- Ability to translate technical findings into business-relevant risk
- Strong risk quantification, prioritization, and decision-making skills
- Ability to independently own and operate risk management programs
- Strong vendor management and stakeholder collaboration skills
- Excellent organizational skills and follow-through
- Effective written, verbal, and leadership communication
- Proactive problem-solving and escalation management
- Ability to work independently with minimal oversight
Work Environment
- Location: Remote – US
- Onsite, Hybrid or Remote: Fully Remote
- Work schedule: Monday–Friday, 40 hours per week
- Collaboration with security engineering, GRC, vendors, and internal stakeholders
- Personal laptop required
Compensation & Benefits
- Pay Range: The approximate pay range for this position is between $38.00 and $55.00. Please note that the pay range provided is a good faith estimate. Final compensation may vary based on factors including but not limited to background, knowledge, skills, and location. We comply with local wage minimums.
- Medical, Dental, & Vision Insurance Plans
- Employee-Owned Profit Sharing (ESOP)
- 401K offered
About KellyMitchell
At KellyMitchell, our culture is world class. We’re movers and shakers! We don’t mind a bit of friendly competition, and we reward hard work with unlimited potential for growth. This is an exciting opportunity to join a company known for innovative solutions and unsurpassed customer service. We're passionate about helping companies solve their biggest IT staffing & project solutions challenges. As an employee-owned, women-led organization serving Fortune 500 companies nationwide, we deliver expert service at a moment's notice.
Marketing Disclosure
By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from KellyMitchell and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP to opt out. You can access our privacy policy at https://www.careers.kellymitchell.com/privacy-policy.
[143304]