Skip to content
The board
Job
FinanceEngineering

Third-Party Risk Management Analyst

Samsara · IT Security

Pay
$110,670–$167,400/yr
Where
Remote - US
Posted
Sep 3

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara, we are helping improve the safety, efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP, these industries are the infrastructure of our planet, including agriculture, construction, field services, transportation, and manufacturing — and we are excited to help digitally transform their operations at scale.

Working at Samsara means you’ll help define the future of physical operations and be on a team that’s shaping an exciting array of product solutions, including Video-Based Safety, Vehicle Telematics, Apps and Driver Workflows, and Equipment Monitori…

What you'd do

  • Lead end-to-end third-party security risk assessments — using both qualitative and quantitative methods — for Samsara's vendors and partners, and recommend risk ratings and tiering in line with Samsara's Vendor Risk Management Policy.
  • Own the vendor reassessment cadence and track remediation of any security gaps throughout the full lifecycle of the vendor.
  • Partner with Legal, Procurement, and system/relationship owners to review vendor contracts and onboarding requests submitted through Zip, ensuring security requirements (e.g. incident notification, data training, compliance, etc.) are in place before a vendor goes live.
  • Escalate unresolved vendor risk to Security leadership, legal, procurement, and business owners as necessary.
  • Support internal and external audits of the vendor risk program (e.g. ISO, SOC, FedRAMP).
  • Build and maintain the metrics, dashboards, and reporting that give Security leadership visibility into Samsara's third-party risk posture and program performance.
  • Support the GRC team's efforts to bring automation and AI-enabled tools into vendor risk workflows, such as using AI to triage vendor security questionnaires, flag high-risk contract terms, and incorporate industry learnings into the lifecycle.
  • Mentor junior TPRM resource(s) to ensure Samsara’s TPRM program is matching the pace of innovation and velocity of Samsara.
  • Champion, role model, and embed Samsara's cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices.

What they want

  • 5+ years of experience in third-party/vendor risk management, GRC, or information security compliance.
  • Experience using automation, scripting, or low-code workflows to help scale a vendor risk program.
  • Hands-on experience running vendor security assessments and administering a vendor tiering program.
  • Experience partnering with Legal and Procurement on vendor contract security and privacy terms (e.g., Security addendums, DPAs, etc.).
  • Must reside in the US, outside the San Francisco Bay Area, New York City, and Washington, D.C. metro areas.
  • Familiarity with implementing and/or operating a risk assessment framework such as NIST CSF, ISO 27001, or SOC 2.
  • Experience with a GRC or vendor risk management platform (e.g., Vanta, ServiceNow, OneTrust, Archer, or similar).
  • A relevant certification such as CTPRP, CISA, CRISC, or CISSP.