10 Oct
|
Clio
|
British Columbia
10 Oct
Clio
British Columbia
Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.
We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice .
Summary: About the Team Third-Party Risk Management (TPRM) is responsible for making sure the outside parties Clio relies on, including software vendors, service providers, and platform integrators it lists in the App Marketplace, meet Clio's bar for security and privacy before they touch Clio or customer data. We sit inside the vendor lifecycle as the security compliance review phase of Procurement, after intake and in parallel with Legal and IT. We work closely with IT, Privacy, Legal, and the App Ecosystem team to deliver strong, documented, defensible assessments of security posture and risk.
About the Role As a Third-Party Risk Analyst, you are the person who reads the security documentation and advises on the risk of third-party relationships. You own the day-to-day execution of the security review phase, working through vendor submissions, reviewing SOC 2 and penetration test reports, checking data handling against our requirements, and reviewing the security and privacy submissions of partners applying to list in Clio's App Marketplace. When the third party's criticality is higher, you step up the documentation criteria and adapt. You apply an established set of criteria commensurate with the service provided, surface real risk from paperwork, and keep reviews moving.
You don't need to have seen every framework or every control, but you need to know what a good answer looks like, what questions to ask when something's missing, and when to elevate rather than wave something through.
What You'll Do Review vendor security documentation submitted through the intake process, including SOC 2 reports, penetration test summaries, security whitepapers, AI disclosures, and questionnaire responses, and determine whether the vendor meets Clio's required level of security and privacy
Review App Marketplace integration submissions and evaluate the security and privacy documentation of integration partners applying to list on Clio. Flag exceptions that could put customer data or Clio's brand at risk before a partner is added to the marketplace
Triage for privacy review by identifying when a vendor or integration will process confidential or sensitive data and route it into a Data Privacy Impact Assessment (DPIA), partnering with Privacy/Compliance
Escalate for risk acceptance when a risk is identified in the review process. Document and present it to the appropriate stakeholder for decision making
Move reviews through the workflow by tracking submissions, requesting missing artifacts from requesters and vendors, responding to comments, and handing off cleanly to IT, Legal, and executive sign-off
Document your findings and decisions. Record what you reviewed, what you found, the risks identified, and your recommendation so the rationale is reusable and audit-ready
Maintain the third-party risk registry
Support renewals and reassessments by re-reviewing vendors on renewal or change of scope
Keep the review criteria and runbooks accurate.
Follow the established process and flag when a checklist, threshold, or template is out of date or unclear
What You Bring Required
2-4 years of hands-on experience in a security, compliance, GRC, vendor risk, or procurement review role
Working familiarity with third-party audit artifacts. You've read SOC 2 reports and know how to review them and extract a deeper understanding
Understanding of core security and privacy concepts, including access controls, encryption, data classification, data residency, and what different tiers of security and privacy documentation look like
Demonstrated ability to review documentation critically and separate real risk from noise
Comfort working within an established review process and contributing to its improvementClear, evidence-first written communication
Knows when to figure something out independently and when to pull in a subject matter expert
Strong organizational skills. You keep multiple reviews moving without losing track of what's waiting on whom
Preferred You are able to see the gaps in documentation and suggest compensating controls where applicable
Previous experience with GRC, TPRM, or vendor management tooling
Exposure to SOC 2, ISO 27001, PCI DSS, or GDPR/CCPA concepts in an audit context
Experience with GDPR, CCPA, DPIAs and/or privacy impact assessments
CISA, CIPP/CIPM, CTPRP, CompTIA Security+, or equivalent certification
What Makes You a Outstanding Fit You take full ownership of your review queue, communicate effective, and are able to balance competing priorities
You're curious about why a control matters, not just whether a box is checked
You have an intuition for looking beyond the presented facts and noticing emerging patterns across
#J-18808-Ljbffr
📌 Third-Party Risk Analyst (British Columbia)
🏢 Clio
📍 British Columbia