About the job Remote | Security & Vendor Risk Specialist — $85–$105/hour
We are sharing a specialised part-time consulting opportunity for senior security and vendor-risk professionals with extensive experience in third-party risk management, SOC 2 review, security questionnaires, penetration-test evidence, and supplier security assessments.
This role supports an advanced AI initiative focused on creating realistic simulations of enterprise procurement and vendor-security workflows. Selected professionals will review simulated compliance evidence, identify subtle security and scope issues, assess data-handling risks, and develop detailed evaluation rubrics reflecting how experienced security reviewers assess new vendors and contract renewals.
Key Responsibilities
Vendor Security Review
- Review simulated vendor SOC 2 reports, security questionnaires, and penetration-test evidence
- Evaluate vendor documentation against defined buyer security standards
- Assess whether submitted evidence adequately supports stated security controls
- Identify missing documentation, control gaps, inconsistencies, and unsupported claims
- Produce clear recommendations for approval, remediation, escalation, or rejection
Compliance Evidence Assessment
- Review SOC 2 scope, reporting periods, control coverage, exceptions, and auditor conclusions
- Identify scope mismatches between vendor services and assessed systems
- Detect expired or insufficient bridge letters and gaps between reporting periods
- Evaluate whether penetration-test evidence is current, relevant, and appropriately scoped
- Assess the quality and completeness of supporting compliance materials
Data Handling & Sub-Processor Risk
- Evaluate how vendors collect, access, process, store, and transfer sensitive data
- Assess risks associated with sub-processors, hosting providers, and downstream service partners
- Review data residency, retention, deletion, access-control, and encryption considerations
- Identify security concerns requiring additional due diligence or contractual safeguards
- Evaluate vendor responses within realistic procurement and renewal contexts
Rubric & Reference Response Development
- Author detailed, step-level rubrics for vendor-security review tasks
- Develop high-quality reference responses reflecting experienced professional judgment
- Define evaluation criteria for evidence quality, control effectiveness, data risk, and approval readiness
- Distinguish minor documentation issues from material security deficiencies
- Refine scoring standards to support consistent assessment across reviewers
Ideal Profile
Strong candidates may have:
- At least 8 years of professional experience in security review, vendor risk management, third-party risk, or information security
- Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
- Strong understanding of vendor due diligence and third-party security assessment processes
- Experience identifying control gaps, evidence limitations, and scope inconsistencies
- Familiarity with data-handling, privacy, sub-processor, and supply-chain security risks
- Excellent written communication and structured analytical skills
- Comfort producing detailed rubric-style feedback and defensible review conclusions
- Ability to work independently within a remote and asynchronous environment
Educational Background
- A degree in cybersecurity, information systems, computer science, risk management, business, or a related discipline may be helpful
- Professional certifications such as CISSP, CISA, CISM, CRISC, or comparable credentials may strengthen an application
- Formal training in third-party risk management, security assurance, or compliance assessment may also be valuable
- Equivalent senior-level professional experience in vendor security or third-party risk may be considered
Nice to Have
- CISSP, CISA, CISM, CRISC, or another relevant security certification
- Experience within a formal third-party risk management programme
- Background in SaaS, cloud, technology, or enterprise vendor assessments
- Familiarity with security frameworks such as ISO 27001, NIST, or similar standards
- Experience reviewing penetration-test reports and remediation evidence
- Knowledge of procurement, contract-renewal, and vendor-onboarding workflows
- Prior task-writing, rubric-authoring, quality-review, or AI training-data experience
- Experience collaborating with procurement, legal, privacy, compliance, and IT teams
Why This Opportunity
- Apply senior vendor-security expertise to realistic, high-impact evaluation work
- Shape how advanced AI systems understand third-party security and risk-review workflows
- Work across SOC 2 reports, security questionnaires, penetration tests, and data-risk assessments
- Develop evaluation rubrics and reference responses grounded in real-world professional judgment
- Participate in flexible remote work with competitive hourly compensation
Contract Details
- Independent contractor role
- Fully remote with flexible scheduling
- Competitive rates between $85–$105 per hour depending on expertise and project scope
- Weekly payments via Stripe or Wise
- Work may include vendor-security review, compliance-evidence assessment, rubric development, reference-response creation, and simulation auditing
- Projects may be extended, shortened, or adjusted depending on scope and performance
- Work will not involve access to confidential or proprietary information from any employer, client, or institution
About the Platform
This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.
By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.