What are the responsibilities and job description for the Supplier Risk Management Assessor position at PTR Global?
π¨ W2 Contract Opportunity | Supplier Risk Management (SRM) Assessor | Financial/Mortgage | Hybrid β McLean, VA
π Location: McLean, VA (Hybrid β Tuesday through Thursday Onsite)
π’ Schedule: Hybrid | Full-time onsite if converted
π Job Type: W2 Contract (Contract-to-Hire Potential)
β³ Duration: 6 Months
π« No C2C | No Sponsorship
A leading financial/mortgage organization is seeking an experienced Supplier Risk Management (SRM) Assessor to support enterprise Third-Party Vendor Risk Management (TPRM) initiatives. This role is ideal for professionals with strong risk assessment, IT audit, and SOC report review experience who thrive in a fast-paced, highly regulated environment.
Key Responsibilities
- Conduct end-to-end supplier/vendor risk assessments across technology, privacy, security, resiliency, and operational risk domains.
- Review and evaluate SOC 1 and SOC 2 Type II reports to validate vendor control environments.
- Collect, analyze, and assess vendor documentation to identify risks and recommend remediation plans.
- Partner with vendors and internal stakeholders to drive timely completion of risk assessments.
- Document findings, communicate risk recommendations, and escalate issues when necessary.
- Manage multiple vendor assessments while meeting established SLAs and deadlines.
- Support enterprise third-party risk governance and continuous process improvement initiatives.
Required Qualifications
β 5 years of experience in Third-Party Vendor Risk Management (TPRM), IT Risk, Risk Assessment, or IT Audit
β Strong experience reviewing SOC 1 & SOC 2 Type II reports
β Experience conducting vendor/supplier risk assessments and evaluating control effectiveness
β Excellent analytical, communication, documentation, and stakeholder management skills
β Ability to manage multiple priorities in a fast-paced enterprise environment
Preferred Qualifications
β Financial Services or Mortgage industry experience
β Large enterprise risk management experience
β Supply Chain Risk or Compliance background
β Experience with ProcessUnity
β Professional certifications such as CISA, CISM, CIA, or CRISC
What We're Looking For
The ideal candidate has:
- Strong Third-Party Vendor Risk Management experience.
- Hands-on expertise reviewing SOC 1 & SOC 2 Type II reports.
- IT Audit or Risk Assessment background.
- Excellent communication and project management skills.
- Experience working with enterprise vendors and cross-functional stakeholders.
Note: This role does not involve financial statement or vendor financial health reviews. Candidates with only cybersecurity experience and no vendor risk assessment experience are unlikely to be a fit.
Interview Process
π Shortlisting Deadline: July 31
π₯οΈ Round 1: 45-minute MS Teams Video Interview
π’ Round 2: 45-minute Onsite Interview
π Interview Week: August 5
π© Interested? Please send your updated resume along with:
- Current Location
- Work Authorization (W2 only)
- Years of TPRM / IT Audit / Risk Assessment experience
- Experience reviewing SOC 1 & SOC 2 Type II reports
- Financial Services or Mortgage experience
- ProcessUnity experience (if applicable)
- Relevant Certifications (CISA, CISM, CIA, CRISC)
- Earliest Availability