Full-Time

Third Party Risk Management

Tprm, Analyst

Confirmed live in the last 24 hours

CoreWeave

CoreWeave

501-1,000 employees

Cloud provider for GPU-accelerated workloads

Data & Analytics
Enterprise Software
AI & Machine Learning

Compensation Overview

$80k - $100kAnnually

Mid

Livingston, NJ, USA + 3 more

More locations: New York, NY, USA | Bellevue, WA, USA | Sunnyvale, CA, USA

Hybrid workplace; in-office presence required.

Category
Cybersecurity
IT & Security
Required Skills
JIRA
Requirements
  • Experience conducting third-party risk assessments to identify, document, and mitigate potential risks a third party may introduce
  • Strong experience utilizing Jira to track and prioritize incoming vendor requests
  • Ability to conduct vendor Business Impact Analysis (BIA) and Data Privacy assessments
  • Minimum of 3-5 years of work experience in IT/Security Compliance/Audit function (or equivalent)
  • Educational Qualification: Bachelor's in Information Security, Computer Science, or related degree; Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) Certification or equivalent
  • Proven experience in compliance, risk, business continuity, and/or IT security program management
  • Familiarity with data privacy regulations and standards (ISO 27701, GDPR, etc.)
  • Excellent written communications to internal and external audiences, including senior leadership
  • Experience collaborating with cross-functional teams, including legal, procurement, engineering, infrastructure, security, etc.
  • Ability to succeed in a team environment or work as an individual contributor
  • In-depth knowledge of the security and compliance standards/regulations, specifically SOX, SOC 2, ISO 27001, ISO 27701, NIST 800-53, NIST CSF, FedRAMP, GDPR, PCI DSS and HIPAA
  • Understanding of concepts related to information security domains such as Cloud Computing, Data Privacy, Physical Security, Identity and Access Management, Encryption, Vulnerability Management, Incident Response, etc.
Responsibilities
  • Complete third-party risk assessments for all new vendors
  • Ensure third-party risk assessments include an in-depth Business Impact Analysis (BIA) and Data Protection Impact Assessment (DPIA), supporting BCP/DR and Privacy programs
  • Continually reevaluate vendors based on their criticality level to identify/document any changes that may impact our risk exposure, data privacy, mitigation strategies, etc.
  • Coordinate the collection of required security assessment artifacts (e.g., audit reports, privacy policies, compliance documentation, incident response plan, disaster recovery/business continuity plans, etc.) from (new and existing) vendors periodically
  • Triage assessments that require technical reviews to Security Engineering
  • Prepare and monitor the status of each vendor risk assessment (software, data center landlords, etc.) and communicate the status with key stakeholders regularly
  • Update and document due diligence tracking with real-time status and escalate issues and concerns (e.g., oversight deficiencies, program concerns, and open risk items)
  • Own and update control evidence related to TPRM to ensure readiness for internal assessments and external audits
  • Document program processes and procedures to ensure all updates to the TPRM program are captured and accessible to relevant parties
  • Support the sales department in completing customer TPRM questionnaires and being the point of contact for security, governance and IT-related inquiries
  • Support technical writing team with public-facing due diligence documentation and customer-facing Trust Center

CoreWeave provides cloud computing services that focus on GPU-accelerated workloads, which are essential for tasks requiring high computational power like Generative AI, Machine Learning, and VFX rendering. Their services allow clients to access powerful computing resources without needing to invest in expensive hardware, operating on a pay-as-you-go model. This flexibility is particularly beneficial for tech companies, film studios, and enterprises that need scalable solutions. CoreWeave's infrastructure is built on a bare metal serverless Kubernetes platform, which enhances performance while minimizing operational burdens for clients. By offering a variety of NVIDIA GPUs, they enable clients to optimize performance and costs based on their specific needs. The goal of CoreWeave is to provide efficient and scalable cloud computing resources tailored to industries that demand high-performance computing.

Company Stage

N/A

Total Funding

$2.3B

Headquarters

New York City, New York

Founded

2017

Growth & Insights
Headcount

6 month growth

53%

1 year growth

174%

2 year growth

842%
Simplify Jobs

Simplify's Take

What believers are saying

  • Securing $1.1 billion in funding positions CoreWeave for aggressive growth and innovation in the AI and HPC sectors.
  • The appointment of former AWS executive Chetan Kapoor as Chief Product Officer brings valuable expertise and leadership to drive product strategy during a hypergrowth phase.
  • CoreWeave's $2.2 billion investment in European data centers demonstrates their commitment to expanding global reach and meeting surging demand for AI infrastructure.

What critics are saying

  • The competitive landscape with giants like AWS launching high-core instances could pressure CoreWeave to continuously innovate to maintain its edge.
  • Rapid expansion, including significant investments in new data centers, could strain resources and operational capabilities.

What makes CoreWeave unique

  • CoreWeave specializes in GPU-accelerated workloads, setting it apart from general cloud service providers like AWS and Azure.
  • Their fully managed, bare metal serverless Kubernetes platform offers high performance with reduced operational burden, a unique selling point in the cloud computing market.
  • CoreWeave's strategic partnerships, such as with Bloom Energy for on-site power generation, enhance their infrastructure's reliability and sustainability.

Help us improve and share your feedback! Did you find this helpful?