Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Vendor Risk Consultant image - Rise Careers
Job details

Vendor Risk Consultant

About SecurityScorecard:

SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. 

Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.”  SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital.

About the Role

SecurityScorecard’s MAX team delivers vendor risk management services on behalf of customers. Our MAX team is growing and we are seeking a Vendor Risk Consultant to join our team and help us manage and mitigate risks associated with our customers’ vendors. This is an exciting opportunity to work alongside some of the largest companies in the world and make a significant impact on their business by ensuring that their information is held securely by their vendors. 

What You’ll Do:

  • Conduct risk assessments of customers’ potential and existing vendors to identify and mitigate potential risks.
  • Monitor and track vendor risk profiles and regularly report on potential and existing risks to customers and vendors.
  • Stay informed about current security threats and industry standards to continuously improve vendor risk management strategies.
  • Develop and maintain strong relationships with vendors to ensure ongoing compliance with security requirements.
  • Develop and maintain strong relationships with customers to help them understand the risks posed by their vendors.
  • Continuously assess the effectiveness of our customers’ vendor risk management programs, and provide advice and guidance on how to enhance the effectiveness.
  • Assess new and emerging cybersecurity findings identified by SecurityScorecard, and provide analysis and insight to vendors on how these impact their cybersecurity posture and how to mitigate and remediate these findings.

What We need you to have: 

  • 5+ years of professional cybersecurity consulting experience, or similar. 
  • Outstanding communication skills, and the ability to explain complex cybersecurity and vendor risk management concepts to non-technical audiences.
  • Strong understanding of cybersecurity concepts, technologies, and best practices.
  • Data analysis skills, using Microsoft Excel or similar, and common scripting languages, such as Python, to analyze complex data and provide trends and patterns.
  • Demonstrated ability to manage multiple client accounts simultaneously, prioritize tasks, and meet deadlines.
  • Work independently and collaboratively in a fast-paced, dynamic environment.
  • At least one certification in the following list is desired: CEH, GSLC, GCPM, GSTRT, GCCC, GSNA, CISSP, CISM, CISA or CRISC.
  • Experience conducting cybersecurity assessments and audits is desired.
  • Previous experience in vendor risk management is desired, but not required.

Benefits:

Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more!

The estimated total compensation range for this position is $120,000 - $148,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. 

SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. 

We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io.

Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. 

SecurityScorecard does not accept unsolicited resumes from employment agencies.  Please note that we do not provide immigration sponsorship for this position.   #LI-DNI

SecurityScorecard Glassdoor Company Review
3.4 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
SecurityScorecard DE&I Review
3.6 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of SecurityScorecard
SecurityScorecard CEO photo
Aleksandr Yampolskiy
Approve of CEO

Average salary estimate

$134000 / YEARLY (est.)
min
max
$120000K
$148000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Vendor Risk Consultant, SecurityScorecard

Are you a cybersecurity enthusiast looking to make your mark? Look no further! SecurityScorecard is on the hunt for a Vendor Risk Consultant to join our dynamic MAX team, dedicated to delivering top-notch vendor risk management services to our esteemed customers. With over 12 million companies rated and a track record of excellence, we're leaders in cybersecurity ratings and need someone like you to help manage and mitigate risks associated with our clients' vendors. In this thrilling role, you'll conduct risk assessments of potential and existing vendors, monitor risk profiles, and ensure compliance with the latest security requirements. You'll also develop strong relationships with both vendors and customers, guiding them through the complex landscape of cybersecurity threats. If you've got a knack for analyzing data, explaining complex concepts in an understandable way, and you're excited about working alongside some of the biggest names in various industries, this position could be a perfect fit for you! At SecurityScorecard, we value collaboration and independence, making sure our team has the flexibility to thrive in a fast-paced environment. Plus, with a range of benefits and a commitment to equal opportunity, we can't wait to see how you can help us continue to innovate and lead in the cybersecurity field. Join us on this exciting journey and be a part of something impactful!

Frequently Asked Questions (FAQs) for Vendor Risk Consultant Role at SecurityScorecard
What are the main responsibilities of a Vendor Risk Consultant at SecurityScorecard?

As a Vendor Risk Consultant at SecurityScorecard, your primary responsibilities will include conducting risk assessments on potential and current vendors, monitoring vendor risk profiles, developing relationships with vendors, and providing crucial insights into cybersecurity threats. Additionally, you'll guide our customers in enhancing their vendor risk management strategies.

Join Rise to see the full answer
What qualifications do I need to apply for the Vendor Risk Consultant position at SecurityScorecard?

Candidates applying for the Vendor Risk Consultant role at SecurityScorecard should have at least 5 years of professional cybersecurity consulting experience, strong communication skills, and a solid understanding of cybersecurity technologies. It's also desirable to have at least one relevant certification, such as CISSP or CISM.

Join Rise to see the full answer
How does SecurityScorecard support the career growth of a Vendor Risk Consultant?

At SecurityScorecard, we invest in the growth of our Vendor Risk Consultants by offering continuous learning opportunities, mentorship support, and access to training resources. We believe in empowering our team to stay updated with the latest in cybersecurity and vendor risk management.

Join Rise to see the full answer
What makes SecurityScorecard a great place to work for Vendor Risk Consultants?

SecurityScorecard has been recognized by Inc Magazine and Crain’s NY for our stellar workplace culture, and we've also been named one of the World’s Most Innovative Companies. This commitment to a positive work environment, coupled with competitive salaries and comprehensive benefits, makes us a great place for Vendor Risk Consultants.

Join Rise to see the full answer
What kind of companies will I work with as a Vendor Risk Consultant at SecurityScorecard?

As a Vendor Risk Consultant at SecurityScorecard, you'll collaborate with a wide array of clients, including some of the largest corporations across various industries. You'll play a crucial role in helping these organizations manage their vendor-related cybersecurity risks.

Join Rise to see the full answer
Common Interview Questions for Vendor Risk Consultant
Can you describe your experience with vendor risk assessments?

To answer effectively, provide specific examples of risk assessments you've conducted, detailing the methods you used and the outcomes. Emphasize your analytical skills and how you communicated findings to stakeholders.

Join Rise to see the full answer
How do you stay informed about the latest cybersecurity threats?

Discuss your strategies for keeping up-to-date, such as following cybersecurity news outlets, participating in webinars, or attending industry conferences. Highlight your commitment to continuous learning in the cybersecurity space.

Join Rise to see the full answer
What is your approach to building relationships with vendors?

You should discuss the importance of trust and communication in your approach. Provide examples of how you’ve successfully managed vendor relationships and ensured compliance with security standards.

Join Rise to see the full answer
How do you prioritize multiple vendor risk assessments?

Explain your time management strategies, such as using project management tools, prioritization techniques, and collaborating with teammates to ensure timely completion of assessments.

Join Rise to see the full answer
Describe a time you identified a significant risk with a vendor. What did you do?

Share a specific story demonstrating your analytical skills and problem-solving abilities. Highlight how you communicated the risk and worked with stakeholders to mitigate the issue.

Join Rise to see the full answer
What certifications do you hold that are relevant to vendor risk management?

List your relevant certifications and explain how they enhance your qualification for the Vendor Risk Consultant role. Tie them back to skills needed in cybersecurity and risk management.

Join Rise to see the full answer
Can you give an example of how you've improved a vendor risk management program?

Discuss a specific situation where you identified weaknesses in a program and implemented changes that led to improved risk identification or vendor compliance.

Join Rise to see the full answer
How would you explain complex cybersecurity concepts to a non-technical audience?

Emphasize your communication skills. Provide an example of a complex concept you previously explained, outlining the techniques you used to make it understandable for a non-technical audience.

Join Rise to see the full answer
What tools or technologies do you use for data analysis?

Mention specific tools you’re familiar with, such as Microsoft Excel or Python. Explain how you've used them for data analysis in a vendor risk management context.

Join Rise to see the full answer
Why do you want to work as a Vendor Risk Consultant at SecurityScorecard?

Express your passion for cybersecurity and interest in SecurityScorecard’s mission. Highlight the company’s culture, recognition, or impact in the industry as motivations for wanting to join the team.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join SecurityScorecard as a Customer Success Manager and help enterprise clients transform their security risk management.

Photo of the Rise User
SecurityScorecard Remote Hybrid (Metro NY) 1 day per week in office
Posted 2 days ago

Step into the pivotal role of Senior Director of Product Management at SecurityScorecard and drive the strategy for cutting-edge cybersecurity solutions.

Photo of the Rise User
Posted 17 hours ago

Join LexisNexis Legal & Professional as a Field Solutions Consultant, where you'll leverage your legal expertise to foster client relationships and drive product usage.

Photo of the Rise User
Turner and Townsend Hybrid Moncks Corner, SC 29461, USA
Posted 11 days ago

As a Contract Administrator at Turner & Townsend, you'll play a critical role in managing contracts and vendor relationships for exciting construction projects.

Photo of the Rise User

Join AECOM as a Transportation Planning Assistant to actively engage in community outreach and data analysis for transportation innovations.

Photo of the Rise User

CSIS is looking for an enthusiastic Program Coordinator to support their Energy Security and Climate Change initiatives with a focus on event coordination and communications.

Join Total Life as a Remote Therapist in Arizona to support seniors through virtual therapy sessions.

Photo of the Rise User
Infystrat Remote No location specified
Posted 8 days ago

Join InfyStrat as a Business Analyst to leverage your analytical skills in a dynamic team focused on innovation and improvement.

Mindrift is on the lookout for a Freelance Material Science Expert to help shape AI technologies through specialized expertise.

Drees & Sommer SE Remote Bundesallee 39-40a, 10717 Berlin, Deutschland
Posted 7 days ago

As a Senior Consultant at macom, you'll lead regional market strategies while leveraging your expertise in IT and media technology.

Our mission is to make the world a safer place by transforming the way organizations understand, improve, and communicate cybersecurity risk to their boards, employees, and vendors.

23 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
February 21, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Akron just viewed Customer Support Representative at ProVia
Photo of the Rise User
Someone from OH, Alliance just viewed Store Representative - Mid-Shift at Serv-U-Success
Photo of the Rise User
Someone from OH, Eastlake just viewed (REMOTE) Account Executive at Trellis
Photo of the Rise User
Someone from OH, Elyria just viewed Security Officer - Factory Patrol at Allied Universal
Photo of the Rise User
Someone from OH, Cincinnati just viewed Staff Software Test Engineer, Platform at Clari
Photo of the Rise User
Someone from OH, Perrysburg just viewed Sourcing Leader, Minerals & Cullet at Owens Corning
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog