We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Sr. TPRM Security Analyst

MultiPlan
$135,000 - $145,000
401(k)
United States, Virginia, McLean
7900 Tysons One Place (Show on map)
Aug 20, 2026

JOB SUMMARY: This role will support leadership in the Third-Party Risk Management (TPRM) aspects of Claritev's GRC program, with emphasis on vendor security risk assessments, vendor onboarding and due diligence, ongoing monitoring, deficiency management, and third-party risk reporting. Working closely with Procurement, Legal, Compliance, Privacy, IT, and business stakeholders, this position will be responsible for executing and maturing core TPRM processes, improving the scalability and consistency of vendor risk evaluations, and strengthening the organization's ability to identify, assess, treat, and monitor risks introduced by third-party relationships. This role requires the ability to engage in deep technical discussions with vendors and internal engineering teams, including evaluation of system architecture, data flows, and control implementations within complex environments.

JOB ROLES AND RESPONSIBILITIES:

  • Serve as a trusted advisor and subject matter expert, providing third-party risk management and security governance support to Procurement, IT, and business stakeholders throughout the vendor lifecycle.
  • Support the GRC leader in executing strategy and multi-year roadmaps to mature Claritev's TPRM program.
  • Collaborate with security, IT, procurement, privacy, legal, compliance, and business stakeholders to develop standards and processes that protect the confidentiality, integrity, and availability of Claritev data in third-party environments.
  • Own and execute core TPRM workflows and tooling, including vendor intake and risk tiering, security risk assessment (SRA) scoping, evidence collection, assessment execution, deficiency tracking, risk acceptance, and risk escalation processes.
  • Conduct in-depth security risk assessments of third-party vendors, including evaluation of system architectures, data flows, authentication mechanisms, encryption implementations, network segmentation, and cloud security controls.
  • Lead technical discussions with vendor engineering and security teams to validate architectural design, control effectiveness, and alignment with Claritev security requirements.
  • Review and analyze vendor-provided documentation, including SOC reports, penetration test results, security policies, and completed questionnaires, to assess inherent and residual risk.
  • Identify control gaps and deficiencies, document findings, and coordinate remediation activities or risk acceptance decisions with business stakeholders.
  • Track and manage third-party remediation plans through closure, ensuring timely follow-up, appropriate documentation, and audit readiness.
  • Support ongoing monitoring of third-party risk, including reassessments, periodic reviews, and integration of continuous monitoring tools and threat intelligence sources.
  • Build and maintain consistent assessment methodologies and templates to improve efficiency, quality, and defensibility of vendor risk evaluations.
  • Assist with audits and reviews of TPRM processes to evaluate control effectiveness, document findings, and track remediation activities through closure.
  • Develop and maintain metrics, reporting, and dashboards that communicate third-party risk exposure, assessment volume, deficiency trends, SLA performance, and program effectiveness.
  • Coordinate with the Risk Management team to ensure material third-party risks are escalated into the enterprise risk register and reporting framework.
  • Partner with Procurement to ensure alignment between vendor onboarding workflows and TPRM requirements, including integration with procurement systems and contract lifecycle events.
  • Continuously identify opportunities to improve TPRM processes, automation, and tooling within platforms such as Onspring.
  • Collaborate, coordinate, and communicate effectively across disciplines and departments, and demonstrate the Company's Core Competencies and values held within.
  • The position responsibilities outlined above are in no way to be construed as all encompassing. Other duties, responsibilities, and qualifications may be required and/or assigned as necessary.

REQUIREMENTS (Education, Experience, and Training):

  • At least 5+ years' experience directly in cybersecurity or information security GRC, with a demonstrated track record of leading complex projects in at least two of the following areas: third-party risk management, vendor risk assessments, compliance operations, control assurance, or audit support.
  • Strong technical background is required, with the ability to interpret and evaluate system architecture diagrams, application data flows, and infrastructure designs across cloud and on-prem environments.
  • Hands-on or practical experience in one or more technical domains such as cloud engineering, network security, application security, or systems engineering.
  • Demonstrated ability to engage in detailed technical discussions with engineers and architects regarding control implementation and security design decisions.
  • Strong working knowledge of cloud architectures (e.g., AWS, Azure), including identity models, network design, data protection mechanisms, and shared responsibility considerations.
  • A deep understanding of third-party risk assessment methodologies and frameworks, including NIST CSF, HITRUST, HIPAA, SOC 2, ISO 27001, and related security and privacy requirements.
  • Strong knowledge and experience with the TPRM lifecycle, including vendor intake, tiering, due diligence, risk assessment execution, deficiency management, remediation tracking, and ongoing monitoring.
  • Experience reviewing and interpreting vendor security artifacts such as SOC reports, penetration tests, security policies, and questionnaire responses.
  • Experience building and maintaining TPRM reporting, dashboards, and program metrics that support executive-level decision-making.
  • Strong knowledge of control frameworks, risk identification and assessment techniques, and remediation tracking processes as applied to third-party environments.
  • Functional knowledge of information security domains, industry standards, and best practices, along with the ability to identify and recommend process improvements and automation opportunities.
  • Previous experience with GRC solutions such as Onspring, Archer, Lockpath, LogicGate, or similar platforms; hands-on workflow and reporting configuration experience preferred.
  • Experience collaborating with cross-functional stakeholders such as Procurement, Legal, Compliance, Privacy, Internal Audit, and IT.
  • CISSP, CISA, CISM, CRISC, or similar certifications are a plus.
  • Ability to maintain confidentiality of information and exercise sound judgment when handling sensitive matters.
  • Ability to work independently as well as within a team, communicate effectively with technical and non-technical stakeholders, and influence decisions through clear recommendations.
  • Ability to organize, prioritize, and coordinate multiple work activities, adapt to changing priorities, and meet target deadlines.
  • Ability to travel as needed to Company locations and third-party locations within the US.
  • Individual in this position must be able to work in a standard office environment which requires sitting and viewing monitor(s) for extended periods of time, operating standard office equipment such as, but not limited to, a keyboard, copier, and telephone.

COMPENSATION:

The salary range for this position is $135k - $145K. Specific offers take into account a candidate's education, experience and skills, as well as the candidate's work location and internal equity. This position is also eligible for health insurance, 401k and bonus opportunity.

#LI-MZ1

Why Claritev?

Healthcare is complex. We help make it clearer.

At Claritev, you'll do work that matters. Together, we're helping make healthcare more transparent and affordable for all through the power of data, technology, and expertise. We offer meaningful opportunities to grow your career, collaborate with talented colleagues, and make an impact on the clients and communities we serve. If you're looking for purpose, growth, and a team that succeeds together, you'll find it here.

What Guides Us

At Claritev, innovation, agility, and a focus on results drive our success. We embrace bold thinking, work as one team, take ownership, and strive for excellence in everything we do - creating meaningful impact for our clients, communities, and each other.

Applied = 0

(web-77cf7d65c7-bbl8f)