Sr. Risk Analyst - Vendor Risk Assessment (VRA)
Sentinellabs · Costa Rica · 2026-08-04
About this role
Our Purpose
At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.
About Us
SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.
Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.
What Are We Looking For?
We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.
As a Senior Risk Analyst, Vendor Risk Assessment, you will be tasked with bringing technically grounded expertise to SentinelOne's Information Security GRC team. You will go beyond compliance knowledge to understand how systems work, how threats materialize, and how to evaluate vendor security controls with a critical technical eye. You will operate independently on assigned workstreams and apply hands-on IT and cybersecurity knowledge to assess risk accurately and credibly across a diverse vendor portfolio.
What Will You Do?
Primary responsibilities include:
• Conduct end-to-end vendor assessments with the ability to go beyond questionnaire responses by evaluating SOC 2 reports, penetration test findings, vulnerability disclosures, network architecture diagrams, encryption practices, and access control configurations; identify technical control gaps and translate them into actionable, risk-prioritized remediation plans.
• Review and interpret vendor-provided technical documentation, including system architecture diagrams, data flow maps, hardening standards, patch management practices, and incident response capabilities; apply knowledge of common IT environments (cloud, SaaS, on-prem, hybrid) to contextualize vendor risk accurately.
• Map vendor technical controls to ISO 27001, SSAE 18/SOC 2, SOX ITGC, GDPR, NIST CSF/SP 800-53, and SentinelOne's internal security policies; identify gaps where technical implementation falls short of framework requirements and drive closure with vendors.
• Own Vendor Risk Assessment workstreams and short to mid-term project objectives independently; track remediation activities to completion, validate technical evidence of fixes, and escalate unresolved risk to management with clear business impact framing.
• Partner with IT, Engineering, Legal, and Procurement teams to gather technical context and align on risk tolerance; communicate findings clearly to both technical teams and non-technical stakeholders by translating risk into business impact.
• Stay current on the evolving threat landscape, including cloud misconfigurations, supply chain attacks, and third-party data exposure risks, and apply this awareness to refine assessment criteria; begin mentoring junior analysts on technical evaluation methods and VRA tooling.
• Actively apply AI tools to automate repetitive VRA workflows, accelerate vendor assessments, generate reporting, and surface risk insights faster; be prepared to share concrete examples of how you have used AI to automate tasks, improve reporting, or solve real problems in your work.
What Skills and Knowledge Will You Bring?
Ideal candidates will have:
Skills asked for
- cybersecurity
- go
- aws
- azure
- gcp
- rest
Similar jobs
- Risk Analyst - Vendor Risk Assessment (VRA)Sentinellabs · Costa Rica
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.