Easy Apply
Easy Apply
Own vendor lifecycle risk assessments, review SOC2/ISO/pen-test reports, redline security and data agreements, engage vendors for remediation, monitor vendor posture, and collaborate with Procurement, Legal, Privacy, and Engineering.
About The Position
As Navan continues to scale globally, our ecosystem of vendors and partners grows with us. We are looking for a Third-Party Risk Analyst to join our Security & Compliance team. In this role, you will be the gatekeeper of our vendor lifecycle, ensuring that every third party—from software providers to Travel Management Companies (TMCs)—meets our rigorous security and privacy standards. You will sit at the intersection of Procurement, Legal, and Security, driving the risk assessment process and ensuring that Navan’s data remains protected across our entire supply chain.
What You’ll Do- Risk Assessment Ownership: Conduct comprehensive security and privacy risk assessments for new and existing third parties using procurement and GRC tools and partner with Security leadership to escalate high-risk vendors and support documented risk acceptance or remediation decision
- Vendor Due Diligence: Review SOC2 reports, ISO certifications, and penetration test summaries to identify potential vulnerabilities in a vendor’s posture.
- Contractual Redlining: Partner with Legal to review and redline Security Addendums and Data Processing Addendums (DPAs), ensuring vendors commit to Navan’s required security controls.
- Vendor Engagement: Lead the outreach to vendor security teams to clarify questionnaire responses, follow up on remediation items, and ensure compliance with our standards.
- TMC & Partner Management: Work closely with our Travel Management Companies to gather essential security documentation and manage the lifecycle of partner-specific risk reviews and contracts.
- Continuous Monitoring: Monitor the existing vendor landscape for security incidents, certification expirations, for security alerts, news of breaches, or changes in risk profiles, and trigger re-assessments when necessary.
- Cross-Fuctional Collaboration: You will work closely with Procurement, Legal, Privacy, and Engineering teams on third-party security and risk considerations throughout the vendor lifecycle
- Experience: 2–4 years in Third-Party Risk Management (TPRM), Vendor Risk, or IT Audit.
- Regulatory Knowledge: Familiarity with privacy frameworks (GDPR, CCPA) and security standards (SOC 2, ISO 27001).
- Procurement Savvy: Experience working within procurement workflows and using GRC or Vendor Management tools (e.g., OneTrust, Prevalent, or Vanta).
- Analytical Mindset: Ability to spot "red flags" in a vendor’s security documentation and translate those risks into business impact for internal stakeholders.
- Negotiation Skills: Comfortable holding vendors accountable and negotiating security terms in contracts.
- Organization: You can manage dozens of active vendor assessments simultaneously without losing track of deadlines or documentation gaps.
Top Skills
Ccpa
Gdpr
Iso 27001
Onetrust
Prevalent
Soc 2
Vanta
Similar Jobs at Navan
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Administer and integrate SaaS tools (Okta, Google Workspace, Slack, Zoom, Atlassian), manage IAM/SSO configurations, troubleshoot application issues, automate processes with scripting and iPaaS, maintain IT documentation, and support cross-team deployments and on-call incident response.
Top Skills:
Okta,Google Workspace,Slack,Zoom,Okta Workflows,Atlassian,Jira Service Desk,Jira Software,Workato,Zapier,Bettercloud,Sso,Swa,Saml,Jit,Scim,Oidc,Oauth,Rbac,Abac,Apis,Gam,Python,Bash,Powershell
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Serve as the customer-facing security and privacy subject-matter expert: respond to security questionnaires, review and redline security/privacy contract exhibits, maintain the Trust Center (SafeBase), use AI-assisted tools to automate questionnaire responses, collaborate with Privacy/Legal, and enable Sales with updated security materials.
Top Skills:
Safebase,Ai-Assisted Questionnaire Tools,Soc 2,Iso 27001,Nist,Gdpr,Ccpa
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
As a Manager, Travel Experience Consultant, you will lead a team, drive performance, enhance customer relationships, and implement operational improvements in the travel industry.
Top Skills:
Amadeus)Contact Center Applications (CalabrioCrm Applications (SalesforceGds Platforms (SabreTwilio)Workday)
What you need to know about the Kolkata Tech Scene
When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.


.png)