Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Expert based in Canada.
This contract role is an opportunity for an experienced security professional to apply deep expertise in third-party and vendor risk to the evaluation of AI-generated security assessments. You will review SOC 2 reports, security questionnaires, penetration-testing evidence, and related compliance materials against defined security standards. Your judgment will help identify subtle risks and inconsistencies that may be missed during surface-level reviews. You will also develop detailed evaluation rubrics and model responses that reflect how experienced security reviewers assess real-world requests. The role involves assessing data-handling practices and sub-processor risks for vendors managing sensitive information. You will work remotely and asynchronously, with a high degree of independence and a direct impact on improving AI model performance.
Accountabilities:
- Review simulated vendor SOC 2 reports, security questionnaires, penetration-testing evidence, and compliance documentation against established security standards.
- Identify scope mismatches, outdated documentation, lapsed bridge letters, and other issues that may be overlooked in high-level reviews.
- Assess vendor security posture and identify potential risks associated with data handling, access, and sub-processors.
- Create detailed, step-level evaluation rubrics that capture how an experienced security professional would assess a request, vendor, or renewal.
- Develop high-quality reference or “golden” responses to guide AI models toward accurate and security-conscious evaluations.
- Provide structured, actionable feedback that supports the improvement of AI-generated security assessments.
- Work independently and asynchronously while maintaining high standards of accuracy and meeting project deadlines.
Requirements:
- 8+ years of professional experience in security review, vendor risk management, third-party risk management (TPRM), or a closely related discipline.
- Hands-on experience reviewing SOC 2 reports, security questionnaires, penetration-testing evidence, and other security or compliance documentation.
- Strong understanding of vendor security assessments, third-party risk, data protection, and sub-processor risk.
- Excellent written communication skills, with the ability to produce clear, structured, and rubric-based feedback.
- Strong attention to detail and the ability to identify nuanced security gaps, inconsistencies, and documentation issues.
- Ability to apply professional judgment independently and work effectively in a remote, asynchronous environment.
- A relevant security certification, such as CISSP or CISA, is preferred.
- Previous experience with task writing, rubric development, AI training data, or similar evaluation work is an advantage.
Benefits:
- Competitive contract compensation of $90–$110 per hour
- Fully remote work environment.
- Flexible, asynchronous working structure.
- Opportunity to apply advanced security expertise to the development and evaluation of AI systems.
- Meaningful contribution to improving the accuracy and reliability of AI-generated security assessments.
- Independent work with the flexibility to manage assignments around agreed deadlines.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1