Vendor Risk Specialist - Fully Remote | Upto $110/hr
mercor · Remote — Mexico
Remote
Sign in and upload your CV to see how well you match this job.
Sign inJob overview
- Location
- Remote — Mexico
- Workplace
- Remote
- Employment type
- Contract / freelance
- Experience level
- Senior
- Date posted
- Oct 10, 2026
- Last checked at the source
- Oct 11, 2026
- Job source
- via Himalayas
Requirements
• 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
• Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
• Strong written communication skills; comfortable producing structured, rubric-style feedback.
Skills
- Communication
Visa and relocation
The posting doesn't mention visa sponsorship. Check the original posting or ask the company.
The posting doesn't mention relocation.
Job description
About the job
Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.
Position: Security Expert
Type:Contract
Compensation:$90–$110/hour
Location:Remote
Role Responsibilities
• Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard.
• Catch scope mismatches and lapsed bridge letters that a surface-level review would miss.
• Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal.
• Assess data-handling and sub-processor risk for vendors touching sensitive data.
• Work independently and asynchronously to meet deadlines while improving AI model performance.
Qualifications
Must-Have
• 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
• Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
• Strong written communication skills; comfortable producing structured, rubric-style feedback.
Preferred
• Relevant security certification, such as CISSP or CISA.
• Prior task-writing, rubric-authoring, or AI-training data experience.
Application Process (Takes 20–30 mins to complete)
• Upload resume
• AI interview based on your resume
• Submit form
Resources & Support
• For details about the interview process and platform information, please check:
• For any help or support, reach out to:
PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
Originally posted on Himalayas
Vendor-Risk-Management, Third-Party-Risk-Management, Security-Compliance, Risk-Assessment-Specialist, Security-Review, Vendor-Risk-Analyst, Remote-Risk-Management-Specialist, Remote-Risk-Management-Analyst, Vendor-Risk-Manager, Remote-Risk-Assessment-Specialist
Apply on the original site ↗Job source: via Himalayas
GetGlobalJob is not the employer or a recruiting agency. You apply on the original publisher's site: always check the posting before sharing your details, and never pay for a job.
Check your fit for this job
Create your free account and upload your CV to see how well you match this job and which skills you're missing.