waypointjobs

KMC Solutions Inc

XTN-3E78732 | SECURITY ANALYST – PRODUCT & VENDOR

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

We are seeking a Security Analyst to support the organization’s Third-Party Risk Management (TPRM) program, with a primary focus on application and security architecture reviews of external vendors and SaaS providers.

This role sits at the intersection of security architecture, vendor assessment, and GRC reporting. The analyst will evaluate vendor-provided documentation, analyze cloud-based technology stacks, and produce structured security assessment outputs that feed directly into the GRC team’s formal risk reporting process.

A key part of this role involves working with incomplete or unclear vendor documentation and performing independent research (including OSINT techniques) to accurately understand vendor architectures and security posture.

Health Insurance/HMO

Enjoy unlimited MadMax Coffee

Diverse learning & growth opportunities

Accessible Cloud HR platform (Sprout)

Above standard leaves

Key Responsibilities

Perform detailed security architecture and application reviews of third-party vendors, SaaS platforms, and external services.

Request and evaluate vendor documentation such as:

Architecture diagrams

Security practices and policies

Compliance reports (SOC 2, ISO 27001, etc.)

Penetration test summaries

Data flow and integration diagrams

Use a standardized internal assessment framework to evaluate expected controls and determine vendor risk levels.

Translate technical findings into a structured document used by the GRC team for formal risk reporting.

Conduct independent research and OSINT analysis when vendor documentation is incomplete or missing.

Assess a wide variety of modern and niche cloud-based technology stacks.

Communicate directly with vendors to clarify architecture, controls, and security posture.

Collaborate primarily with GRC and occasionally with Procurement and Engineering during vendor evaluations.

Manage multiple concurrent vendor assessments with minimal supervision.

Required Skills & Experience

3+ years’ experience in any of the following:

Security analysis

Security architecture review

Application security

Third-party/vendor risk management

Cloud security assessment

Strong ability to interpret:

Architecture diagrams

Security documentation

Data flows and system integrations

Familiarity with cloud-based and SaaS technology stacks.

Experience evaluating vendor security posture against defined security control requirements.

Strong analytical, research, and documentation skills.

Comfortable working with ambiguous or incomplete information.

Self-motivated and able to work independently across multiple assessments.

Highly Preferred

Experience in Third-Party Risk Management (TPRM) or Supply Chain Risk Management.

Experience performing security reviews for SaaS or cloud vendors.

Familiarity with OSINT techniques for technology and architecture research.

Exposure to GRC processes and risk reporting.

Key Traits for Success

Naturally curious and investigative mindset.

Comfortable navigating unfamiliar technologies and niche stacks.

Detail-oriented with strong written communication skills.

Able to translate technical architecture into risk language for GRC reporting.

Proactive, independent, and highly organized.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job