Vendor Risk Assessment Junior Analyst Intern

Aviso de fuente externaen Outsourcing Services International | OSI

GENERAL DESCRIPTION The Vendor Risk Assessment Analyst is responsible for supporting Lightedge’s thirdparty/vendor risk management process by evaluating prospective and existing vendors f...

Fuente externa - sin verificarhace 6 díasVigente hasta: 26 oct 2026

Salario

No especificado

Ubicación

Antiguo Cuscatlán, El Salvador

Tipo de empleo

Tiempo completo

Modalidad

No especificado

Vendor Risk Assessment Junior Analyst Intern

Antiguo Cuscatlán, El Salvador

Descripción del empleo

GENERAL DESCRIPTION The Vendor Risk Assessment Analyst is responsible for supporting Lightedge’s thirdparty/vendor risk management process by evaluating prospective and existing vendors for security, privacy, compliance, artificial intelligence (AI), and other business risks. This role coordinates with internal Lightedge stakeholders and external vendors to gather required information and documentation, classify vendors according to risk, perform vendor research and due diligence, analyze audit and compliance reports, identify potential risks or gaps, and route vendors through the appropriate review and approval processes. The ideal candidate is highly organized, analytical, comfortable working across multiple teams, and able to manage vendor assessments from initial intake through approval and follow-up.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Vendor Intake and Risk Classification Coordinate with internal Lightedge contacts to gather preliminary information regarding vendors, proposed services, data access, system access, business criticality, and other potential risk factors. Review vendor use cases and available information to determine the appropriate vendor risk classification. Apply established risk criteria to determine the level of due diligence and documentation required for each vendor.
Vendor Due Diligence and Research Conduct independent research on vendors to identify security, privacy, operational, financial, reputational, regulatory, and other relevant risk factors. Research publicly reported security incidents, data breaches, regulatory actions, litigation, vulnerabilities, and other events that may affect the vendor's risk profile. Document research findings and escalate material concerns for additional review. Maintain clear records supporting vendor risk classifications and assessment conclusions. Review vendor responses to security, privacy, and AI-related questionnaires. Coordinate additional review when vendor activities present elevated privacy, AI, security, or compliance risks.
Compliance and Audit Report Review Obtain appropriate security and compliance documentation from vendors based on their risk classification, including applicable SOC reports, ISO certifications, penetration testing summaries, COIs, attestations, and other supporting documentation. Analyze audit reports for exceptions, control deficiencies, qualified opinions, complementary user entity controls, subservice organization considerations, and other findings relevant to LightEdge. Identify gaps between the vendor's documented controls and LightEdge's requirements.
Vendor Coordination Communicate directly with vendors to request questionnaires, audit reports, certifications, policies, and other required due diligence documentation. Follow up with vendors regarding incomplete submissions, unanswered questions, identified risks, or missing documentation.
Internal Review and Approval Route vendors to the appropriate LightEdge teams for review and approval based on identified risks and established processes. Coordinate with Information Security, Legal, Compliance, Procurement, business owners, and other stakeholders as appropriate. Follow up with internal stakeholders and vendors as necessary to move assessments through completion. Maintain accurate records of assessment activities, findings, approvals, and supporting documentation.
REQUIREMENTS
Experience reviewing security, privacy, compliance, or third-party risk questionnaires preferred. Familiarity with vendor risk management, third-party risk management, information security, privacy, compliance, or audit concepts preferred. Familiarity with SOC 1 and SOC 2 reports, ISO 27001, PCI DSS, and other common security or compliance frameworks preferred. Privacy and AI risk awareness. Audit report analysis.
QUALIFICATIONS
Strong analytical, research, and organizational skills. Ability to evaluate information from multiple sources and identify potential risk factors. Strong written and verbal communication skills. Ability to communicate effectively with internal stakeholders, technical teams, business teams, and external vendors. Strong attention to detail and ability to maintain accurate documentation and recordkeeping. Ability to manage multiple vendor assessments and competing priorities simultaneously. Cross-functional coordination. Time and workload management.

¿Es tuya esta vacante?

Reclámala gratis y recibe candidatos con video en CazVid.

Empleos similares