This one is closed
Live roles like this one
-
D
15h ago
IT Governance Senior Specialist
SiFi United States
- D 21h ago
- C 21h ago
- C 21h ago
See every "Vendor Risk Specialist" role →
Get new “Vendor Risk Specialist” roles by email
One email a day with what is new in "Vendor Risk Specialist". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 39/100, which is an F. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Pay transparency 12 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
- Remote clarity 8 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Corroboration 5 / 10 Whether more than one source carries this listing.
- Freshness 4 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Role specificity 0 / 10 Whether the listing is tagged well enough to tell what the role actually is.
-10 Ghost-job penalty — Deducted for signals that this posting may not be a real, currently-open role — staleness, repeated relisting, or talent-pool language.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
About the job
Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.
Position: Security Expert
Type:Contract
Compensation:$90–$110/hour
Location:Remote
Role Responsibilities
- Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard.
- Catch scope mismatches and lapsed bridge letters that a surface-level review would miss.
- Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal.
- Assess data-handling and sub-processor risk for vendors touching sensitive data.
- Work independently and asynchronously to meet deadlines while improving AI model performance.
Qualifications
Must-Have
- 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
- Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
- Strong written communication skills; comfortable producing structured, rubric-style feedback.
Preferred
- Relevant security certification, such as CISSP or CISA.
- Prior task-writing, rubric-authoring, or AI-training data experience.
Application Process (Takes 20–30 mins to complete)
- Upload resume
- AI interview based on your resume
- Submit form
Resources & Support
- For details about the interview process and platform information, please check:
- For any help or support, reach out to:
PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
Originally posted on Himalayas
Apply for this role Opens himalayas.app — the link as listed; we have not yet verified it is the employer's own page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 15 Aug 2026 Himalayas first sighting
Seen on 1 board over 0 days.