> Markdown version of [/jobs/ext/2042867-remote](https://www.wearedevelopers.com/jobs/ext/2042867-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Remote - **Company:** MAG 24 LLC - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $176,800.0 - $218,400.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software as a Service, Cyber Security, Information Systems, Data Processing, Test Scripts, Information Technology, Data Management - **Published:** August 13, 2026 - **Apply:** https://www.careerjet.com/jobad/us8618bf6c2fd67dc790a1276ad70230c1 ## About the Role * At least 8 years of professional experience in security review, vendor risk management, third-party risk, or information security * Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence * Strong understanding of vendor due diligence and third-party security assessment processes * Experience identifying control gaps, evidence limitations, and scope inconsistencies * Familiarity with data-handling, privacy, sub-processor, and supply-chain security risks * Excellent written communication and structured analytical skills * Comfort producing detailed rubric-style feedback and defensible review conclusions * Ability to work independently within a remote and asynchronous environment Educational Background * A degree in cybersecurity, information systems, computer science, risk management, business, or a related discipline may be helpful * Professional certifications such as CISSP, CISA, CISM, CRISC, or comparable credentials may strengthen an application * Formal training in third-party risk management, security assurance, or compliance assessment may also be valuable * Equivalent senior-level professional experience in vendor security or third-party risk may be considered Nice to Have * CISSP, CISA, CISM, CRISC, or another relevant security certification * Experience within a formal third-party risk management programme * Background in SaaS, cloud, technology, or enterprise vendor assessments * Familiarity with security frameworks such as ISO 27001, NIST, or similar standards * Experience reviewing penetration-test reports and remediation evidence * Knowledge of procurement, contract-renewal, and vendor-onboarding workflows * Prior task-writing, rubric-authoring, quality-review, or AI training-data experience * Experience collaborating with procurement, legal, privacy, compliance, and IT teams ## Description We are sharing a specialised part-time consulting opportunity for senior security and vendor-risk professionals with extensive experience in third-party risk management, SOC 2 review, security questionnaires, penetration-test evidence, and supplier security assessments. This role supports an advanced AI initiative focused on creating realistic simulations of enterprise procurement and vendor-security workflows. Selected professionals will review simulated compliance evidence, identify subtle security and scope issues, assess data-handling risks, and develop detailed evaluation rubrics reflecting how experienced security reviewers assess new vendors and contract renewals., Vendor Security Review * Review simulated vendor SOC 2 reports, security questionnaires, and penetration-test evidence * Evaluate vendor documentation against defined buyer security standards * Assess whether submitted evidence adequately supports stated security controls * Identify missing documentation, control gaps, inconsistencies, and unsupported claims * Produce clear recommendations for approval, remediation, escalation, or rejection Compliance Evidence Assessment * Review SOC 2 scope, reporting periods, control coverage, exceptions, and auditor conclusions * Identify scope mismatches between vendor services and assessed systems * Detect expired or insufficient bridge letters and gaps between reporting periods * Evaluate whether penetration-test evidence is current, relevant, and appropriately scoped * Assess the quality and completeness of supporting compliance materials Data Handling & Sub-Processor Risk * Evaluate how vendors collect, access, process, store, and transfer sensitive data * Assess risks associated with sub-processors, hosting providers, and downstream service partners * Review data residency, retention, deletion, access-control, and encryption considerations * Identify security concerns requiring additional due diligence or contractual safeguards * Evaluate vendor responses within realistic procurement and renewal contexts Rubric & Reference Response Development * Author detailed, step-level rubrics for vendor-security review tasks * Develop high-quality reference responses reflecting experienced professional judgment * Define evaluation criteria for evidence quality, control effectiveness, data risk, and approval readiness * Distinguish minor documentation issues from material security deficiencies * Refine scoring standards to support consistent assessment across reviewers, * Shape how advanced AI systems understand third-party security and risk-review workflows * Work across SOC 2 reports, security questionnaires, penetration tests, and data-risk assessments * Develop evaluation rubrics and reference responses grounded in real-world professional judgment * Participate in flexible remote work with competitive hourly compensation Contract Details * Independent contractor role * Fully remote with flexible scheduling * Competitive rates between $85-$105 per hour depending on expertise and project scope * Weekly payments via Stripe or Wise * Work may include vendor-security review, compliance-evidence assessment, rubric development, reference-response creation, and simulation auditing * Projects may be extended, shortened, or adjusted depending on scope and performance * Work will not involve access to confidential or proprietary information from any employer, client, or institution About the Platform This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams. By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: . ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Are Classical Automation Frameworks Dead? How AI Agents Are Transforming QA](https://www.wearedevelopers.com/videos/100243-are-classical-automation-frameworks-dead-how-ai-agents-are-transforming-qa) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Implementing continuous delivery in a data processing pipeline](https://www.wearedevelopers.com/videos/73-implementing-continuous-delivery-in-a-data-processing-pipeline) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Mastering Remote Work: Tips for Developers](https://www.wearedevelopers.com/magazine/558-mastering-remote-work-tips-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers)