Source description
About the role
Role Overview: As a Risk Specialist at Pinnacle Group, your main responsibility will be to support third-party IT risk management and technology vendor assessment activities. You will focus on evaluating technology vendors from an IT risk perspective, supporting audit readiness, and ensuring alignment with established security, compliance, and governance standards. Your role will also involve interacting with third-party auditors, vendors, and internal stakeholders to gather information and respond to assessment requests. Additionally, you will collaborate with cross-functional teams to improve risk assessment processes and support audit readiness. This position offers you the opportunity to grow into a future leadership role within the risk function. Key Responsibilities: - Perform third-party risk assessments and vendor assessments focusing on technology, security, and IT control environments. - Evaluate vendor risk posture by reviewing documentation, controls, processes, and responses to security and compliance questionnaires. - Support the organization's third-party risk management program by identifying gaps, documenting findings, and recommending remediation actions. - Interface with third-party auditors, vendors, and internal stakeholders to gather information and respond to assessment requests. - Review and interpret ISO, SOC, and related compliance documentation to assess alignment with organizational risk requirements. - Assist in responding to third-party questionnaires on behalf of the client, ensuring accurate, complete, and professionally documented responses. - Maintain organized assessment records, supporting materials, and risk documentation according to internal policies and procedures. - Collaborate with cross-functional teams to improve risk assessment processes, strengthen vendor oversight, and support audit readiness. - Demonstrate the ability to take on increasing responsibility and grow into a future leadership role within the risk function. Qualifications Required: - Experience performing IT assessments from a risk perspective, particularly related to third-party risk management and technology vendor assessments. - Strong knowledge of ISO and SOC frameworks, reports, controls, and related compliance expectations. - Experience interfacing with third-party auditors and responding to third-party risk or security questionnaires. - Ability to assess technology vendors, identify risk concerns, document findings, and communicate recommendations clearly. - Strong written and verbal communication skills, collaborating effectively with auditors, vendors, and internal stakeholders. - Demonstrated potential to grow into a leadership role, including ownership mindset, sound judgment, and influencing process improvements. - Preferred experience with SaaS environments and AI-driven assessment processes. - Preferred experience using Drata or similar compliance and risk management platforms. Role Overview: As a Risk Specialist at Pinnacle Group, your main responsibility will be to support third-party IT risk management and technology vendor assessment activities. You will focus on evaluating technology vendors from an IT risk perspective, supporting audit readiness, and ensuring alignment with established security, compliance, and governance standards. Your role will also involve interacting with third-party auditors, vendors, and internal stakeholders to gather information and respond to assessment requests. Additionally, you will collaborate with cross-functional teams to improve risk assessment processes and support audit readiness. This position offers you the opportunity to grow into a future leadership role within the risk function. Key Responsibilities: - Perform third-party risk assessments and vendor assessments focusing on technology, security, and IT control environments. - Evaluate vendor risk posture by reviewing documentation, controls, processes, and responses to security and compliance questionnaires. - Support the organization's third-party risk management program by identifying gaps, documenting findings, and recommending remediation actions. - Interface with third-party auditors, vendors, and internal stakeholders to gather information and respond to assessment requests. - Review and interpret ISO, SOC, and related compliance documentation to assess alignment with organizational risk requirements. - Assist in responding to third-party questionnaires on behalf of the client, ensuring accurate, complete, and professionally documented responses. - Maintain organized assessment records, supporting materials, and risk documentation according to internal policies and procedures. - Collaborate with cross-functional teams to improve risk assessment processes, strengthen vendor oversight, and support audit readiness. - Demonstrate the ability to take on increasing responsibility and grow into a future leadership role within the risk function. Qualifications Required: - Experience perfo
More at LinkedIn