Job Openings Remote | Security & Vendor Risk Specialist — $85–$105/hour

About the job Remote | Security & Vendor Risk Specialist — $85–$105/hour

We are sharing a specialised part-time consulting opportunity for senior security and vendor-risk professionals with extensive experience in third-party risk management, SOC 2 review, security questionnaires, penetration-test evidence, and supplier security assessments.

This role supports an advanced AI initiative focused on creating realistic simulations of enterprise procurement and vendor-security workflows. Selected professionals will review simulated compliance evidence, identify subtle security and scope issues, assess data-handling risks, and develop detailed evaluation rubrics reflecting how experienced security reviewers assess new vendors and contract renewals.

Key Responsibilities

Vendor Security Review

  • Review simulated vendor SOC 2 reports, security questionnaires, and penetration-test evidence
  • Evaluate vendor documentation against defined buyer security standards
  • Assess whether submitted evidence adequately supports stated security controls
  • Identify missing documentation, control gaps, inconsistencies, and unsupported claims
  • Produce clear recommendations for approval, remediation, escalation, or rejection

Compliance Evidence Assessment

  • Review SOC 2 scope, reporting periods, control coverage, exceptions, and auditor conclusions
  • Identify scope mismatches between vendor services and assessed systems
  • Detect expired or insufficient bridge letters and gaps between reporting periods
  • Evaluate whether penetration-test evidence is current, relevant, and appropriately scoped
  • Assess the quality and completeness of supporting compliance materials

Data Handling & Sub-Processor Risk

  • Evaluate how vendors collect, access, process, store, and transfer sensitive data
  • Assess risks associated with sub-processors, hosting providers, and downstream service partners
  • Review data residency, retention, deletion, access-control, and encryption considerations
  • Identify security concerns requiring additional due diligence or contractual safeguards
  • Evaluate vendor responses within realistic procurement and renewal contexts

Rubric & Reference Response Development

  • Author detailed, step-level rubrics for vendor-security review tasks
  • Develop high-quality reference responses reflecting experienced professional judgment
  • Define evaluation criteria for evidence quality, control effectiveness, data risk, and approval readiness
  • Distinguish minor documentation issues from material security deficiencies
  • Refine scoring standards to support consistent assessment across reviewers

Ideal Profile

Strong candidates may have:

  • At least 8 years of professional experience in security review, vendor risk management, third-party risk, or information security
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
  • Strong understanding of vendor due diligence and third-party security assessment processes
  • Experience identifying control gaps, evidence limitations, and scope inconsistencies
  • Familiarity with data-handling, privacy, sub-processor, and supply-chain security risks
  • Excellent written communication and structured analytical skills
  • Comfort producing detailed rubric-style feedback and defensible review conclusions
  • Ability to work independently within a remote and asynchronous environment

Educational Background

  • A degree in cybersecurity, information systems, computer science, risk management, business, or a related discipline may be helpful
  • Professional certifications such as CISSP, CISA, CISM, CRISC, or comparable credentials may strengthen an application
  • Formal training in third-party risk management, security assurance, or compliance assessment may also be valuable
  • Equivalent senior-level professional experience in vendor security or third-party risk may be considered

Nice to Have

  • CISSP, CISA, CISM, CRISC, or another relevant security certification
  • Experience within a formal third-party risk management programme
  • Background in SaaS, cloud, technology, or enterprise vendor assessments
  • Familiarity with security frameworks such as ISO 27001, NIST, or similar standards
  • Experience reviewing penetration-test reports and remediation evidence
  • Knowledge of procurement, contract-renewal, and vendor-onboarding workflows
  • Prior task-writing, rubric-authoring, quality-review, or AI training-data experience
  • Experience collaborating with procurement, legal, privacy, compliance, and IT teams

Why This Opportunity

  • Apply senior vendor-security expertise to realistic, high-impact evaluation work
  • Shape how advanced AI systems understand third-party security and risk-review workflows
  • Work across SOC 2 reports, security questionnaires, penetration tests, and data-risk assessments
  • Develop evaluation rubrics and reference responses grounded in real-world professional judgment
  • Participate in flexible remote work with competitive hourly compensation

Contract Details

  • Independent contractor role
  • Fully remote with flexible scheduling
  • Competitive rates between $85–$105 per hour depending on expertise and project scope
  • Weekly payments via Stripe or Wise
  • Work may include vendor-security review, compliance-evidence assessment, rubric development, reference-response creation, and simulation auditing
  • Projects may be extended, shortened, or adjusted depending on scope and performance
  • Work will not involve access to confidential or proprietary information from any employer, client, or institution

About the Platform

This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.