Role Overview
The Vendor Risk Management Intern will support the organization’s third-party risk management program by assisting with vendor due diligence, risk assessments, documentation, reporting, and ongoing monitoring activities. This role is designed for a college student seeking practical experience in cybersecurity, governance, risk, compliance, procurement, and vendor oversight.
Responsibilities
- Assist with vendor onboarding and due diligence activities, including collection and review of security, compliance, privacy, and business documentation.
- Support vendor risk assessments by helping evaluate questionnaires, SOC reports, insurance certificates, and data handling practices.
- Maintain accurate vendor records, assessment status, and remediation items in designated tracking tools.
- Help monitor vendor risk findings, open issues, and remediation plans to ensure timely closure.
- Prepare summaries, dashboards, and reports that communicate vendor risk status and trends to management.
- Coordinate with internal stakeholders such as Security, IT, Procurement, Legal, and Compliance.
- Research vendor risk management practices, cybersecurity frameworks, and regulatory expectations.
- Support process improvement efforts to streamline vendor assessment workflows and templates.
Requirements
- Currently enrolled in a college or university program, preferably in Cybersecurity, Information Technology, Risk Management, or a related field.
- Basic understanding of cybersecurity concepts, risk management principles, or compliance frameworks.
- Proficiency with Microsoft Office tools, especially Excel, Word, PowerPoint, and Outlook.
- Strong written and verbal communication skills.
Nice to Have
- Familiarity with third-party risk management or procurement processes.
- Exposure to frameworks such as SOC 2, ISO 27001, PCI DSS, or NIST.
- Experience organizing data and building spreadsheets.
Skills
- Cybersecurity
- Risk Management
- Compliance
- Microsoft Excel
- SOC 2