SlipstreamJobsFresh Startup & VC-Backed Jobs

Third-Party Risk Management Analyst

Samsara - Remote - Remote - posted 2026-09-03

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Samsara (NYSE: IOT) is the pioneer of the Connected Operations Cloud, a platform enabling organizations to harness IoT data for actionable insights across physical operations including agriculture, construction, field services, transportation, and manufacturing. As a Third-Party Risk Management Analyst, you will own the complete lifecycle of security risk assessments for Samsara's critical vendors and partners. This role sits within the Governance, Risk, and Compliance team and is central to keeping the organization and customers safe. Key responsibilities include: - Lead end-to-end third-party security risk assessments using qualitative and quantitative methods, recommending risk ratings and tiering aligned with company policy - Own vendor reassessment cadence and track remediation of security gaps throughout the vendor lifecycle - Partner with Legal, Procurement, and system owners to review vendor contracts and onboarding requests, ensuring security requirements are met before vendors go live - Escalate unresolved vendor risks to Security leadership, legal, procurement, and business owners as needed - Support internal and external audits of the vendor risk program (ISO, SOC, FedRAMP) - Build and maintain metrics, dashboards, and reporting for Security leadership visibility into third-party risk posture - Support GRC team efforts to bring automation and AI-enabled tools into vendor risk workflows, including AI triage of security questionnaires and contract term flagging - Mentor junior TPRM resources to ensure the program scales with company innovation and velocity - Champion and embed Samsara's cultural principles as the company scales globally Minimum qualifications: 5+ years in third-party/vendor risk management, GRC, or information security compliance. Hands-on experience using automation, scripting, or low-code workflows to scale vendor risk programs. Experience running vendor security assessments and familiarity with frameworks like NIST, ISO 27001, or SOC 2. This is a remote position open to US-based candidates, excluding San Francisco Bay Area, NYC Metro Area, and Washington D.C. Metro Area.

Similar roles