Vendor Cyber Risk Analyst
When to Use
- Run TPRM intake — new vendor requests, renewals, scope changes, offboarding risk
- Tier vendors by data, access, criticality, substitutability, and concentration
- Analyze security questionnaires (SIG, CAIQ, custom) — consistency, gaps, scoring
- Review evidence and attestations — SOC 2, ISO 27001, pen test letters, trust centers
- Operate continuous monitoring — breach feeds, rating changes, cert expiry, news
- Assess concentration and fourth-party (subprocessor) exposure
- Track remediation — findings, owners, due dates, re-assessment triggers
- Produce vendor risk reports for procurement, security, and executive audiences
When NOT to Use
- M&A, investment, or deal-team diligence packs →
cyber-diligence-governance
- Enterprise risk register, FAIR models, or risk appetite without vendor ops →
security-risk-analyst
- GRC program scope, audit prep, or org-wide compliance attestation →
compliance-specialist
- Deploy IAM, federation, PAM, or cloud IAM policies →
iam-specialist, information-security-engineer
- Define CISO strategy, board operating model, or crisis exec comms →
chief-information-security-officer
- Physical supply chain, logistics, inventory, or OEM sourcing →
supply-chain-manager
- Broad security architecture, IR program, or pentest governance →
cybersecurity
- Execute pentests or validate exploits →
penetration-tester
- Negotiate contract redlines or legal interpretation →
commercial-counsel
Related skills
| Need |
Skill |
| M&A/investment diligence and IC cyber packs |
cyber-diligence-governance |
| Enterprise risk register, treatment, FAIR framing |
security-risk-analyst |
| GRC program, audit prep, questionnaire response library |
compliance-specialist |
| IAM federation, access reviews, PAM implementation |
iam-specialist |
| SIEM/EDR, guardrails, technical remediation |
information-security-engineer |
| Executive security strategy and board posture |
chief-information-security-officer |
| Physical/logistics supply chain and sourcing |
supply-chain-manager |
| Enterprise security program and IR policy |
cybersecurity |
Core Workflows
1. Intake and tiering
Capture vendor context, data flows, integrations, and business owner. Assign tier and assessment depth before deep review.
See references/tprm_intake_and_tiering.md.
2. Questionnaire analysis
Map responses to control themes, flag inconsistencies, score gaps, and define evidence asks.
See references/questionnaire_scoring.md.
3. Evidence and attestation review
Validate SOC/ISO scope, bridge letters, pen test coverage, subprocessors, and incident history.
See references/evidence_and_attestation_review.md.
4. Continuous monitoring and incidents
Monitor rating changes, public incidents, cert expiry, and contract events; trigger re-assessment.
See references/continuous_monitoring_and_incidents.md.
5. Reporting and remediation
Track findings to closure; report tier distribution, top risks, concentration, and renewal pipeline.
See references/vendor_risk_reporting.md.
Outputs
- Vendor tier memo — tier, rationale, assessment depth, cadence
- Assessment summary — findings by severity, evidence gaps, residual vendor risk
- Remediation tracker — owner, due date, status, re-test trigger
- Executive / procurement pack — heat map, concentration, incidents, renewals due
- Fourth-party / subprocessor register — inherited risk for T1 vendors
Principles
- Tier before depth — match questionnaire and evidence to inherent risk
- Evidence over assertions — require attestations for material claims
- Separate cyber vendor risk from deal diligence — use
cyber-diligence-governance for transaction-only packs
- Feed the enterprise register — align with
security-risk-analyst without duplicating program ownership
- No legal advice — provide risk tier and required clause themes; escalate terms to counsel
When to load references
| Topic |
Reference |
| Role boundaries |
references/vendor_cyber_risk_analyst_scope.md |
| Intake and tiering |
references/tprm_intake_and_tiering.md |
| Questionnaire scoring |
references/questionnaire_scoring.md |
| Evidence and attestations |
references/evidence_and_attestation_review.md |
| Monitoring and incidents |
references/continuous_monitoring_and_incidents.md |
| Reporting and remediation |
references/vendor_risk_reporting.md |
1---2name: vendor-cyber-risk-analyst3description: Guides third-party and vendor cyber risk—TPRM intake and tiering, security questionnaire analysis and scoring, evidence and attestation review (SOC 2, ISO 27001, pen test summaries), continuous vendor monitoring, concentration and fourth-party risk, remediation tracking, and executive or procurement risk reporting. Use for vendor security assessments, SIG/CAIQ/custom questionnaire review, vendor tiering, inherent vendor cyber risk, vendor incident or breach impact, subprocessors and fourth parties, vendor risk dashboards, or TPRM program operations—not M&A or investment deal diligence only (cyber-diligence-governance), enterprise risk register and FAIR scoring without vendor ops focus (security-risk-analyst), GRC audit program and attestation prep (compliance-specialist), hands-on IAM or cloud policy implementation (iam-specialist, information-security-engineer), physical logistics and OEM supply chain (supply-chain-manager), or broad security program strategy (cybersecurity).4---56# Vendor Cyber Risk Analyst78## When to Use910- Run **TPRM intake** — new vendor requests, renewals, scope changes, offboarding risk11- **Tier vendors** by data, access, criticality, substitutability, and concentration12- **Analyze security questionnaires** (SIG, CAIQ, custom) — consistency, gaps, scoring13- Review **evidence and attestations** — SOC 2, ISO 27001, pen test letters, trust centers14- Operate **continuous monitoring** — breach feeds, rating changes, cert expiry, news15- Assess **concentration and fourth-party** (subprocessor) exposure16- Track **remediation** — findings, owners, due dates, re-assessment triggers17- Produce **vendor risk reports** for procurement, security, and executive audiences1819## When NOT to Use2021- M&A, investment, or deal-team diligence packs → `cyber-diligence-governance`22- Enterprise risk register, FAIR models, or risk appetite without vendor ops → `security-risk-analyst`23- GRC program scope, audit prep, or org-wide compliance attestation → `compliance-specialist`24- Deploy IAM, federation, PAM, or cloud IAM policies → `iam-specialist`, `information-security-engineer`25- Define CISO strategy, board operating model, or crisis exec comms → `chief-information-security-officer`26- Physical supply chain, logistics, inventory, or OEM sourcing → `supply-chain-manager`27- Broad security architecture, IR program, or pentest governance → `cybersecurity`28- Execute pentests or validate exploits → `penetration-tester`29- Negotiate contract redlines or legal interpretation → `commercial-counsel`3031## Related skills3233| Need | Skill |34|---|---|35| M&A/investment diligence and IC cyber packs | `cyber-diligence-governance` |36| Enterprise risk register, treatment, FAIR framing | `security-risk-analyst` |37| GRC program, audit prep, questionnaire response library | `compliance-specialist` |38| IAM federation, access reviews, PAM implementation | `iam-specialist` |39| SIEM/EDR, guardrails, technical remediation | `information-security-engineer` |40| Executive security strategy and board posture | `chief-information-security-officer` |41| Physical/logistics supply chain and sourcing | `supply-chain-manager` |42| Enterprise security program and IR policy | `cybersecurity` |4344## Core Workflows4546### 1. Intake and tiering4748Capture vendor context, data flows, integrations, and business owner. Assign tier and assessment depth before deep review.4950**See `references/tprm_intake_and_tiering.md`.**5152### 2. Questionnaire analysis5354Map responses to control themes, flag inconsistencies, score gaps, and define evidence asks.5556**See `references/questionnaire_scoring.md`.**5758### 3. Evidence and attestation review5960Validate SOC/ISO scope, bridge letters, pen test coverage, subprocessors, and incident history.6162**See `references/evidence_and_attestation_review.md`.**6364### 4. Continuous monitoring and incidents6566Monitor rating changes, public incidents, cert expiry, and contract events; trigger re-assessment.6768**See `references/continuous_monitoring_and_incidents.md`.**6970### 5. Reporting and remediation7172Track findings to closure; report tier distribution, top risks, concentration, and renewal pipeline.7374**See `references/vendor_risk_reporting.md`.**7576## Outputs7778- **Vendor tier memo** — tier, rationale, assessment depth, cadence79- **Assessment summary** — findings by severity, evidence gaps, residual vendor risk80- **Remediation tracker** — owner, due date, status, re-test trigger81- **Executive / procurement pack** — heat map, concentration, incidents, renewals due82- **Fourth-party / subprocessor register** — inherited risk for T1 vendors8384## Principles8586- **Tier before depth** — match questionnaire and evidence to inherent risk87- **Evidence over assertions** — require attestations for material claims88- **Separate cyber vendor risk from deal diligence** — use `cyber-diligence-governance` for transaction-only packs89- **Feed the enterprise register** — align with `security-risk-analyst` without duplicating program ownership90- **No legal advice** — provide risk tier and required clause themes; escalate terms to counsel9192## When to load references9394| Topic | Reference |95|---|---|96| Role boundaries | `references/vendor_cyber_risk_analyst_scope.md` |97| Intake and tiering | `references/tprm_intake_and_tiering.md` |98| Questionnaire scoring | `references/questionnaire_scoring.md` |99| Evidence and attestations | `references/evidence_and_attestation_review.md` |100| Monitoring and incidents | `references/continuous_monitoring_and_incidents.md` |101| Reporting and remediation | `references/vendor_risk_reporting.md` |