Remote

MAG 24 LLC
New York, NY, United States
24 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$176,800.0 - $218,400.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Software as a Service Cyber Security Information Systems Data Processing Test Scripts Information Technology Data Management

Job description

We are sharing a specialised part-time consulting opportunity for senior security and vendor-risk professionals with extensive experience in third-party risk management, SOC 2 review, security questionnaires, penetration-test evidence, and supplier security assessments. This role supports an advanced AI initiative focused on creating realistic simulations of enterprise procurement and vendor-security workflows. Selected professionals will review simulated compliance evidence, identify subtle security and scope issues, assess data-handling risks, and develop detailed evaluation rubrics reflecting how experienced security reviewers assess new vendors and contract renewals., Vendor Security Review

  • Review simulated vendor SOC 2 reports, security questionnaires, and penetration-test evidence
  • Evaluate vendor documentation against defined buyer security standards
  • Assess whether submitted evidence adequately supports stated security controls
  • Identify missing documentation, control gaps, inconsistencies, and unsupported claims
  • Produce clear recommendations for approval, remediation, escalation, or rejection

Compliance Evidence Assessment

  • Review SOC 2 scope, reporting periods, control coverage, exceptions, and auditor conclusions
  • Identify scope mismatches between vendor services and assessed systems
  • Detect expired or insufficient bridge letters and gaps between reporting periods
  • Evaluate whether penetration-test evidence is current, relevant, and appropriately scoped
  • Assess the quality and completeness of supporting compliance materials

Data Handling & Sub-Processor Risk

  • Evaluate how vendors collect, access, process, store, and transfer sensitive data
  • Assess risks associated with sub-processors, hosting providers, and downstream service partners
  • Review data residency, retention, deletion, access-control, and encryption considerations
  • Identify security concerns requiring additional due diligence or contractual safeguards
  • Evaluate vendor responses within realistic procurement and renewal contexts

Rubric & Reference Response Development

  • Author detailed, step-level rubrics for vendor-security review tasks
  • Develop high-quality reference responses reflecting experienced professional judgment
  • Define evaluation criteria for evidence quality, control effectiveness, data risk, and approval readiness
  • Distinguish minor documentation issues from material security deficiencies
  • Refine scoring standards to support consistent assessment across reviewers, * Shape how advanced AI systems understand third-party security and risk-review workflows
  • Work across SOC 2 reports, security questionnaires, penetration tests, and data-risk assessments
  • Develop evaluation rubrics and reference responses grounded in real-world professional judgment
  • Participate in flexible remote work with competitive hourly compensation

Contract Details

  • Independent contractor role
  • Fully remote with flexible scheduling
  • Competitive rates between $85-$105 per hour depending on expertise and project scope
  • Weekly payments via Stripe or Wise
  • Work may include vendor-security review, compliance-evidence assessment, rubric development, reference-response creation, and simulation auditing
  • Projects may be extended, shortened, or adjusted depending on scope and performance
  • Work will not involve access to confidential or proprietary information from any employer, client, or institution

About the Platform This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams. By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: .

Requirements

  • At least 8 years of professional experience in security review, vendor risk management, third-party risk, or information security
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
  • Strong understanding of vendor due diligence and third-party security assessment processes
  • Experience identifying control gaps, evidence limitations, and scope inconsistencies
  • Familiarity with data-handling, privacy, sub-processor, and supply-chain security risks
  • Excellent written communication and structured analytical skills
  • Comfort producing detailed rubric-style feedback and defensible review conclusions
  • Ability to work independently within a remote and asynchronous environment

Educational Background

  • A degree in cybersecurity, information systems, computer science, risk management, business, or a related discipline may be helpful
  • Professional certifications such as CISSP, CISA, CISM, CRISC, or comparable credentials may strengthen an application
  • Formal training in third-party risk management, security assurance, or compliance assessment may also be valuable
  • Equivalent senior-level professional experience in vendor security or third-party risk may be considered

Nice to Have

  • CISSP, CISA, CISM, CRISC, or another relevant security certification
  • Experience within a formal third-party risk management programme
  • Background in SaaS, cloud, technology, or enterprise vendor assessments
  • Familiarity with security frameworks such as ISO 27001, NIST, or similar standards
  • Experience reviewing penetration-test reports and remediation evidence
  • Knowledge of procurement, contract-renewal, and vendor-onboarding workflows
  • Prior task-writing, rubric-authoring, quality-review, or AI training-data experience
  • Experience collaborating with procurement, legal, privacy, compliance, and IT teams

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · World Congress 2021

1:31 min

Managing self-healed test scripts safely within continuous integration

Andrei Nutas Andrei Nutas · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:10 min

Defining stream data processing versus standard event processing

Soroosh Khodami Soroosh Khodami · World Congress 2024

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

2:04 min

Evaluating non-deterministic AI models with offline testing

Julia Kasper · Coffee With Developers

Videos

See all

Related articles

See all