Vendor Risk Specialist

Mercor
San Francisco, CA
Job Description
Role Overview

As a Vendor Risk Specialist, you will review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard. You will catch scope mismatches and lapsed bridge letters that a surface-level review would miss. You will also assess data-handling and sub-processor risk for vendors touching sensitive data.

What You Will Do

Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence. Catch scope mismatches and lapsed bridge letters. Assess data-handling and sub-processor risk for vendors touching sensitive data.

Why It Might Be a Fit

You will work independently and asynchronously to meet deadlines while improving AI model performance. You will have hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence. You will also have strong written communication skills and be comfortable producing structured, rubric-style feedback.

Requirements

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM)
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
  • Strong written communication skills; comfortable producing structured, rubric-style feedback
]]>