Logo for 24-MAG

Remote | Security & Vendor Risk Specialist — $85–$105/hour

Role overview

Qualifications

  • At least 8 years of professional experience in security review, vendor risk management, third-party risk, or information security
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
  • Strong understanding of vendor due diligence and third-party security assessment processes
  • Excellent written communication and structured analytical skills

Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and penetration-test evidence
  • Identify missing documentation, control gaps, inconsistencies, and unsupported claims
  • Evaluate how vendors collect, access, process, store, and transfer sensitive data
  • Author detailed, step-level rubrics for vendor-security review tasks

About the company

24-MAG logo

24-MAG

Company details

Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

We are sharing a specialised part-time consulting opportunity for senior security and vendor-risk professionals with extensive experience in third-party risk management, SOC 2 review, security questionnaires, penetration-test evidence, and supplier security assessments.

This role supports an advanced AI initiative focused on creating realistic simulations of enterprise procurement and vendor-security workflows. Selected professionals will review simulated compliance evidence, identify subtle security and scope issues, assess data-handling risks, and develop detailed evaluation rubrics reflecting how experienced security reviewers assess new vendors and contract renewals.

Key Responsibilities

Vendor Security Review

  • Review simulated vendor SOC 2 reports, security questionnaires, and penetration-test evidence
  • Evaluate vendor documentation against defined buyer security standards
  • Assess whether submitted evidence adequately supports stated security controls
  • Identify missing documentation, control gaps, inconsistencies, and unsupported claims
  • Produce clear recommendations for approval, remediation, escalation, or rejection

Compliance Evidence Assessment

  • Review SOC 2 scope, reporting periods, control coverage, exceptions, and auditor conclusions
  • Identify scope mismatches between vendor services and assessed systems
  • Detect expired or insufficient bridge letters and gaps between reporting periods
  • Evaluate whether penetration-test evidence is current, relevant, and appropriately scoped
  • Assess the quality and completeness of supporting compliance materials

Data Handling & Sub-Processor Risk

  • Evaluate how vendors collect, access, process, store, and transfer sensitive data
  • Assess risks associated with sub-processors, hosting providers, and downstream service partners
  • Review data residency, retention, deletion, access-control, and encryption considerations
  • Identify security concerns requiring additional due diligence or contractual safeguards
  • Evaluate vendor responses within realistic procurement and renewal contexts

Rubric & Reference Response Development

  • Author detailed, step-level rubrics for vendor-security review tasks
  • Develop high-quality reference responses reflecting experienced professional judgment
  • Define evaluation criteria for evidence quality, control effectiveness, data risk, and approval readiness
  • Distinguish minor documentation issues from material security deficiencies
  • Refine scoring standards to support consistent assessment across reviewers

Ideal Profile

Strong candidates may have:

  • At least 8 years of professional experience in security review, vendor risk management, third-party risk, or information security
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
  • Strong understanding of vendor due diligence and third-party security assessment processes
  • Experience identifying control gaps, evidence limitations, and scope inconsistencies
  • Familiarity with data-handling, privacy, sub-processor, and supply-chain security risks
  • Excellent written communication and structured analytical skills
  • Comfort producing detailed rubric-style feedback and defensible review conclusions
  • Ability to work independently within a remote and asynchronous environment

Educational Background

  • A degree in cybersecurity, information systems, computer science, risk management, business, or a related discipline may be helpful
  • Professional certifications such as CISSP, CISA, CISM, CRISC, or comparable credentials may strengthen an application
  • Formal training in third-party risk management, security assurance, or compliance assessment may also be valuable
  • Equivalent senior-level professional experience in vendor security or third-party risk may be considered

Nice to Have

  • CISSP, CISA, CISM, CRISC, or another relevant security certification
  • Experience within a formal third-party risk management programme
  • Background in SaaS, cloud, technology, or enterprise vendor assessments
  • Familiarity with security frameworks such as ISO 27001, NIST, or similar standards
  • Experience reviewing penetration-test reports and remediation evidence
  • Knowledge of procurement, contract-renewal, and vendor-onboarding workflows
  • Prior task-writing, rubric-authoring, quality-review, or AI training-data experience
  • Experience collaborating with procurement, legal, privacy, compliance, and IT teams

Why This Opportunity

  • Apply senior vendor-security expertise to realistic, high-impact evaluation work
  • Shape how advanced AI systems understand third-party security and risk-review workflows
  • Work across SOC 2 reports, security questionnaires, penetration tests, and data-risk assessments
  • Develop evaluation rubrics and reference responses grounded in real-world professional judgment
  • Participate in flexible remote work with competitive hourly compensation

Contract Details

  • Independent contractor role
  • Fully remote with flexible scheduling
  • Competitive rates between $85–$105 per hour depending on expertise and project scope
  • Weekly payments via Stripe or Wise
  • Work may include vendor-security review, compliance-evidence assessment, rubric development, reference-response creation, and simulation auditing
  • Projects may be extended, shortened, or adjusted depending on scope and performance
  • Work will not involve access to confidential or proprietary information from any employer, client, or institution

About the Platform

This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk Management Specialist Related jobs

Other jobs at 24-MAG

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.