Third-Party Risk Management (TPRM) Analyst
Job Description
CoreWeave is a specialized cloud provider, delivering a massive scale of GPU compute resources on top of the industry’s fastest and most flexible infrastructure. CoreWeave builds cloud solutions for compute intensive use cases — VFX and rendering, machine learning and AI, batch processing, and Pixel Streaming — that are up to 35 times faster and 80% less expensive than the large, generalized public clouds. Learn more at www.coreweave.com.
About the role:
CoreWeave is searching for a Third-Party Risk Management (TPRM) Analyst to build and maintain a robust TPRM program. A lot of your time will be spent on evaluating the risk that new vendors or third-parties may introduce, creating mitigation plans to minimize third-party risk, socializing contractual requirements to internal stakeholders, being the liaison between Sales/Customer Success & IT/Security, and completing TPRM questionnaires. Please note that this role is based in our Roseland, NJ office. A closer look at what you’ll be doing in this role:Â
- Review CoreWeave’s TPRM program and advise on best practicesÂ
- Own the business and vendor risk process from end-to-end; manage the entirety of the vendor lifecycle, including internal policies/documentation, vendor risk classification, due diligence, contract negotiation, ongoing monitoring, and termination processes
- Review the existing vendors within CoreWeave’s ecosystem and risk-rate the vendors
- Coordinate the collection of required security assessment artifacts (e.g., privacy policies, compliance documentation, incident response plan, disaster recovery/business continuity plan, audited financial statements) from vendorsÂ
- Complete the formal written risk assessment of vendors while identifying mitigation strategies to lower inherent and residual risk based on risks identified and business unit requirements
- Own the periodic review of vendors based on their inherited Third-Party Risk to be in alignment with governance, risk and compliance requirements
- Prepare and monitor the status of each vendor risk assessment (software, data center landlords, etc.) and communicate the status with key stakeholders on a regular basis
- Update and document due diligence tracking with real time status and escalate issues and concerns (e.g., oversight deficiencies, program concerns, and open risk items)
- Own and update control evidence related to TPRM within the Drata compliance platform
- Own the development and deployment of CoreWeave’s Whistic Profiles
- Implement program processes into TPRM tools (Whistic), to assist with task automation
- Support the sales department in completing customer TPRM questionnaires and being the point of contact for security, governance and IT related inquiries
- Establish good peer relationships and foster collaboration with stakeholders
- Familiarize and own the contractual agreements to ensure identified risks comply with our policies and procedures, legal, and regulatory requirements, and financial control guidelines
- Travel to different CoreWeave sites (domestically and internationally) as-needed to conduct risk assessments
Wondering if you’re a good fit? We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams – even if you aren't a 100% skill or experience match. Here are some qualities we’ve found compatible with our team. If a portion of this resonates with you, we’d love to talk.Â
- You’re an expert in risk management. You’ve got 3-5 years of experience or related knowledge of Third-Party Risk Management methodologies and regulatory guidance and or risk management, preferably within the technology industry.
- You have project and/or program management experience.
- You’re experienced with conducting independent security risk assessments.
- You’ve got great negotiation skills (both internally and externally), and can communicate clearly and compellingly.
- Your written communication skills are strong enough to present to senior leadership, and our multiple stakeholders (internal and external).Â
- You have a deep understanding of and experience with information security, business continuity, compliance, financial analysis, legal, and audit
- You’re a self-starter, take initiative and perform in an agile, fast-paced technical and business environment; you like to tinker and figure things out.
- You’re a problem solver, and have a good handle on how to prioritize and manage your time.
Why CoreWeave?
At CoreWeave, we work hard, have fun, and move fast! We’re in an exciting stage of hyper-growth that you will not want to miss out on. We’re not afraid of a little chaos, and we’re constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:Â
- Be Curious at your Core
- Act like an Owner
- Empower Employees
- Deliver Best In-Class Client ExperienceÂ
- Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and provides the opportunity to develop innovative solutions to complex problems. As we get set for take off, the growth opportunities within the organization are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us!Â
Benefits
We offer a competitive salary and benefits, including:
- Medical, dental and vision insurance - 100% paid for the employee
- Life InsuranceÂ
- Short and long-term disability insuranceÂ
- Flexible Spending Account
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our offices
- Weekly massages in NJ office
- A casual work environment
- Work culture focused on innovative disruption
California Consumer Privacy Act - California applicants only
CoreWeave is an equal opportunity employer, committed to our diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.
Explore More
Date Posted
08/15/2023
Views
4
Similar Jobs
Senior Pricing Analyst - Cencora
Views in the last 30 days - 0
Cencora formerly known as AmerisourceBergen is a leading global pharmaceutical solutions organization They are currently experiencing rapid growth in ...
View DetailsSenior Product Analyst - FinCrime Platform - WISE
Views in the last 30 days - 0
Wise is seeking a Senior Product Analyst for its FinCrime Platform The role involves driving analytics efforts in the Financial Crime Platform product...
View DetailsSenior Data Analyst - Customer Experience - WISE
Views in the last 30 days - 0
Wise is a global technology company aiming to revolutionize international money transfers by offering minimal fees maximum ease and full speed They ar...
View DetailsLead Data Analyst - Mitigation - WISE
Views in the last 30 days - 0
Wise is a global technology company seeking an Operations Analyst with 4 years of experience in analytics particularly in operational team analytics T...
View DetailsSoftware Architecture Engineering and Cloud Computing Engineer - The Aerospace Corporation
Views in the last 30 days - 0
The Aerospace Corporation is seeking a Senior Project Engineer with expertise in software architecture engineering and cloud computing The role involv...
View DetailsSoftware Engineering Manager - Cargill
Views in the last 30 days - 0
The Software Engineering Manager job involves setting goals for a team responsible for software project development and delivery ensuring quality stan...
View Details