What are the responsibilities and job description for the Security Engineer position at 24 Seven Talent?
Position Summary
We are seeking an experienced Third Party Risk / Vendor Security Consultant to support a strategic Vendor Connection initiative. This role will focus on improving how vendor access to the enterprise environment is identified, documented, governed, and standardized.
The consultant will work closely with cybersecurity, third-party risk, and business stakeholders to inventory existing vendor connections, establish secure access patterns, improve vendor access governance, and support implementation of standardized provisioning processes.
This is an execution-focused role ideal for candidates with experience in Third Party Risk Management (TPRM), identity and access governance, vendor security, and network access reviews.
Key Responsibilities
- Document and inventory existing vendor connection methods across the enterprise.
- Analyze vendor access and associate existing connections with appropriate vendor engagements.
- Support data cleanup efforts to improve visibility into vendor connectivity.
- Help define and operationalize standardized vendor access provisioning patterns.
- Partner with cybersecurity and Third Party Risk teams to implement secure vendor access processes.
- Support adoption of new vendor onboarding and access governance procedures.
- Review vendor network access and validate alignment with established security standards.
- Document secure connection patterns including VPN, API integrations, remote access, direct network connectivity, and other approved connection methods.
- Collaborate with project leadership to provide status updates and meet project milestones.
- Produce clear documentation and process artifacts supporting long-term vendor access governance.
Required Skills
Must Have
- Experience supporting Third Party Risk Management (TPRM) programs.
- Knowledge of vendor security assessments and vendor risk concepts.
- Experience reviewing and documenting vendor network connectivity.
- Security access management experience.
- Network access review experience.
- Strong documentation and process improvement skills.
- Experience working with cross-functional cybersecurity and infrastructure teams.
- Ability to organize large volumes of data and improve data quality.
- Strong communication and stakeholder management skills.
Preferred
- Identity and Access Management (IAM) exposure.
- Privileged Access Management (PAM) familiarity.
- Knowledge of least privilege, multi-factor authentication (MFA), and access governance best practices.
- Experience creating security standards or operational playbooks.
- Experience supporting large enterprise cybersecurity initiatives.
- Retail or Fortune 500 enterprise experience.
Required Experience
- 5 years supporting Third Party Risk, Vendor Security, Cybersecurity Governance, or Information Security.
- Experience documenting technical processes and operational procedures.
- Experience collaborating with cybersecurity, infrastructure, networking, and business stakeholders.
- Experience working within structured project environments and meeting defined deliverables.
Technical Environment
Candidates should have experience or familiarity with:
- Third Party Risk Management (TPRM)
- Vendor Security
- Security Access Management
- Identity & Access Governance
- Network Access Reviews
- VPN Connectivity
- API Integrations
- Remote Access Technologies
- Enterprise Security Controls
- Process Documentation
Ideal Candidate
The ideal consultant is highly organized, process-oriented, and comfortable working at the intersection of cybersecurity, vendor management, and operational governance. They are experienced in documenting technical environments, improving operational processes, and partnering with cross-functional teams to implement secure, scalable vendor access practices.
Supplier Submission Notes
Please submit candidates who demonstrate:
- Direct experience supporting Third Party Risk or Vendor Security initiatives.
- Hands-on experience with vendor access governance and network access reviews.
- Strong documentation and process improvement capabilities.
- Experience collaborating with cybersecurity, infrastructure, and business stakeholders.
- Excellent communication skills and the ability to drive work independently in a large enterprise environment.