FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Third-Party Risk Analyst
Clio - Cloud-Based Legal Technology. Review vendor security documentation, including SOC 2 reports, penetration test summaries, security whitepapers, AI disclosures, and questionnaire responses .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in vendor risk management, security compliance, and privacy assessments, with a strong ability to evaluate documentation and identify risks. Proficient in maintaining audit-ready documentation and collaborating with cross-functional teams to ensure compliance with security standards.
Highest-signal resume keywords
Vendor Risk ManagementSecurity ComplianceDocumentation ReviewData Privacy Impact Assessment (DPIA)Third-Party Audit Artifacts
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
SOC 2 ReportsAccess ControlsEncryptionData ClassificationData ResidencySecurity DocumentationPrivacy DocumentationRisk AssessmentGRCVendor Management
Soft Skills
Critical ThinkingOrganizational SkillsWritten CommunicationIndependenceCollaboration
Tools & Technologies
GRC ToolsVendor Management Tooling
Certifications & Qualifications
CISACIPP/CIPMCTPRPCompTIA Security+
Industry Keywords
ISO 27001PCI DSSGDPRCCPAThird-Party Risk Management (TPRM)
About the role
Key responsibilities & impact- Review vendor security documentation, including SOC 2 reports, penetration test summaries, security whitepapers, AI disclosures, and questionnaire responses
- Determine whether vendors meet Clio's required security and privacy level
- Review App Marketplace integration submissions and evaluate partners' security and privacy documentation
- Flag exceptions that could put customer data or Clio's brand at risk
- Identify vendors or integrations processing confidential or sensitive data and triage them for Data Privacy Impact Assessment (DPIA)
- Partner with Privacy/Compliance on privacy reviews
- Escalate identified risks for risk acceptance and present them to appropriate stakeholders
- Track submissions, request missing artifacts, respond to comments, and coordinate handoffs to IT, Legal, and executive sign-off
- Document review findings, decisions, identified risks, and recommendations in an audit-ready manner
- Maintain the third-party risk registry
- Support vendor renewals and reassessments
- Keep review criteria and runbooks accurate and flag outdated or unclear processes
Requirements
What you’ll need- 2–4 years of hands-on experience in a security, compliance, GRC, vendor risk, or procurement review role
- Working familiarity with third-party audit artifacts, including reading and reviewing SOC 2 reports
- Understanding of core security and privacy concepts, including access controls, encryption, data classification, data residency, and security and privacy documentation tiers
- Demonstrated ability to review documentation critically and separate real risk from noise
- Comfort working within an established review process and contributing to its improvement
- Clear, evidence-first written communication
- Ability to determine when to work independently and when to involve a subject matter expert
- Strong organizational skills for managing multiple reviews
- Preferred: ability to identify documentation gaps and suggest compensating controls
- Preferred: previous experience with GRC, TPRM, or vendor management tooling
- Preferred: exposure to SOC 2, ISO 27001, PCI DSS, or GDPR/CCPA concepts in an audit context
- Preferred: experience with GDPR, CCPA, DPIAs and/or privacy impact assessments
- Preferred: CISA, CIPP/CIPM, CTPRP, CompTIA Security+, or equivalent certification
Benefits
Comp & perks- Competitive, equitable salary
- Top-tier health benefits, dental, and vision insurance
- Hybrid work environment
- Flexible time off policy, with an encouraged 20 days off per year
- $2000 annual counseling benefit
- RRSP matching and RESP contribution
- Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years
- Accessibility accommodations during the recruitment process