Senior Analyst, Third Party Risk Management
- Posted 8 days ago
- Be among the first 10 applicants
Job Description
We've signed up to an ambitious journey. Join us!
As Arrive, we guide customers and communities towards brighter futures and more livable cities, it isn't a challenge just anyone could take on. Luckily, we have something to help us make it happen. Our people and our values. We Arrive Curious, Focused and Together. Just as our entire brand is inspired by the North Star, the shining light leading travelers to their destinations since time began, our values guide us. They help us be at our best. For our customers. For the cities and communities we serve. For ourselves. As a global team, we are transforming urban mobility. Let's grow better, together.
We are seeking a Senior TPRM Analyst to support and strengthen Arrive's global Third Party Risk Management program. Reporting to the TPRM Lead, this role will execute third-party risk assessments, evaluate vendor security controls, track remediation, and ensure lifecycle risk governance across our vendor ecosystem.
This role combines strong security fundamentals, risk assessment capability, and stakeholder engagement skills in a global, fast-paced environment.
Key Responsibilities
Third-Party Risk Assessments
Arrive, including brands like EasyPark, Flowbird, RingGo, ParkMobile and Parkopedia, is a leading global mobility platform. Present in over 90 countries and 20,000 cities, the company helps people and decision-makers make smarter decisions about urban mobility and ease the experience of travel worldwide. Arrive delivers a unique combination of the core ingredients to make cities more livable: from smart payments and optimized car parks to data-driven traffic reduction and support for reinvestment in public transport and green space. It's about more than function, it's about saving time and simplifying the experience of travel for everyone. Travel is more than a journey, it's how you Arrive.
As Arrive, we guide customers and communities towards brighter futures and more livable cities, it isn't a challenge just anyone could take on. Luckily, we have something to help us make it happen. Our people and our values. We Arrive Curious, Focused and Together. Just as our entire brand is inspired by the North Star, the shining light leading travelers to their destinations since time began, our values guide us. They help us be at our best. For our customers. For the cities and communities we serve. For ourselves. As a global team, we are transforming urban mobility. Let's grow better, together.
We are seeking a Senior TPRM Analyst to support and strengthen Arrive's global Third Party Risk Management program. Reporting to the TPRM Lead, this role will execute third-party risk assessments, evaluate vendor security controls, track remediation, and ensure lifecycle risk governance across our vendor ecosystem.
This role combines strong security fundamentals, risk assessment capability, and stakeholder engagement skills in a global, fast-paced environment.
Key Responsibilities
Third-Party Risk Assessments
- Conduct security and risk assessments for new and existing vendors (SaaS, cloud, fintech, service providers).
- Evaluate vendor questionnaires and validate evidence (ISO 27001, SOC 2, PCI DSS, GDPR controls).
- Perform inherent and residual risk scoring based on data sensitivity, access level, and vendor criticality.
- Document risk findings and recommend remediation actions.
- Review security documentation including policies, architecture diagrams, pen test summaries, and audit reports.
- Identify control gaps and collaborate with vendors to track remediation.
- Support enhanced due diligence for high-risk vendors.
- Assist in evaluating compensating controls where gaps exist.
- Support vendor onboarding, periodic reviews, and offboarding processes.
- Maintain vendor records and risk data within TPRM/GRC platforms.
- Assist in vendor segmentation, tiering, and monitoring.
- Ensure timely reassessment of critical vendors.
- Work closely with Procurement, Legal, Privacy, IT, and Business Owners.
- Support contract reviews for security clauses in coordination with Legal and TPRM Lead.
- Act as primary operational contact for vendors during assessments.
- Communicate risk findings in business-friendly language.
- Prepare structured risk summaries and remediation tracking reports.
- Contribute to KPI dashboards for third-party risk posture.
- Support ISO 27001, SOC, PCI DSS, and internal audit activities.
- Maintain documentation aligned with internal policies and regulatory standards.
- Contribute to improving TPRM templates, workflows, and playbooks.
- Stay updated on emerging third-party risks and supply-chain threats.
- Support automation initiatives within the TPRM lifecycle .
- 6–10 years of experience in Third Party Risk Management, GRC, IT Risk, or Information Security.
- Experience conducting vendor security assessments and due diligence.
- Strong understanding of ISO 27001, SOC 2, PCI DSS, and data protection fundamentals.
- Experience reviewing security documentation and audit artifacts.
- Ability to interpret vulnerability reports and pen test summaries.
- Experience working with GRC/TPRM tools (ServiceNow, OneTrust, Archer, Jira, etc.).
- Strong written and verbal communication skills.
- Experience supporting global or multi-region vendor ecosystems.
- Experience assessing SaaS and cloud vendors.
- Exposure to fintech, payments, or high-growth digital environments.
- Familiarity with NIS2 or European regulatory frameworks.
- Certifications such as ISO 27001 Foundation, CRISC, CISA, Security+, or similar.
- Experience working with large-scale vendor populations.
Arrive, including brands like EasyPark, Flowbird, RingGo, ParkMobile and Parkopedia, is a leading global mobility platform. Present in over 90 countries and 20,000 cities, the company helps people and decision-makers make smarter decisions about urban mobility and ease the experience of travel worldwide. Arrive delivers a unique combination of the core ingredients to make cities more livable: from smart payments and optimized car parks to data-driven traffic reduction and support for reinvestment in public transport and green space. It's about more than function, it's about saving time and simplifying the experience of travel for everyone. Travel is more than a journey, it's how you Arrive.
More Info
Key Skills
European regulatory frameworks
SOC 2
Data protection fundamentals
Vendor security assessments
NIS2



