SonicJobs Logo
Left arrow iconBack to search

Sr. Technology Risk Analyst

Sungrow USA Corporation
Posted a month ago, valid for 12 days
Salary

$160,000 per year

Contract type

Contract

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Sungrow Americas is looking for a Senior Technology Risk Analyst to enhance its Risk Management program, focusing on vendor security assessments and compliance.
  • The ideal candidate should have strong experience in reviewing security documentation and collaborating with various stakeholders, with a minimum of 5 years of relevant experience.
  • Key responsibilities include executing the Third-Party Risk Management lifecycle, conducting security assessments, and maintaining accurate vendor risk records.
  • The position plays a crucial role in improving Sungrow's cybersecurity posture across various platforms and services supporting critical infrastructure operations.
  • The salary for this position is competitive, reflecting the candidate's experience and expertise in the field.

Senior Technology Risk Analyst

About Sungrow: 
Sungrow Power Supply Co., Ltd. (“Sungrow”) is a global leading PV inverter and ESS provider with 515 GW of power electronic converters installed worldwide as of December 2023. Founded in 1997 by University Professor Cao Renxian, Sungrow leads in the research and development of solar inverters with the largest dedicated R&D team in the industry and a broad product portfolio offering PV inverter solutions and ESS for utility-scale, commercial & industrial, and residential applications, as well as internationally recognized floating PV plant solutions, NEV driving solutions, EV charging solutions, and renewable hydrogen production systems. With a strong 27-year track record in the PV space, Sungrow products power in 170 countries and regions worldwide. For more information, visit: www.sungrowpower.com. 

The Position: 
Sungrow Americas is seeking a Senior Technology Risk Analyst to support the execution and continuous improvement of the organization's Risk Management program.

Working under the direction of the Third-Party Risk Management Lead and in partnership with the Governance, Risk & Compliance (GRC) Manager, this role is responsible for performing vendor security assessments, reviewing security evidence, validating third-party controls, coordinating remediation activities, and maintaining a mature, auditable vendor risk management program.

The ideal candidate possesses strong experience reviewing security documentation, collaborating across Procurement, Legal, IT, Engineering, Product Security, and business stakeholders, and translating complex technical findings into practical business risk.

This position plays a key role in strengthening Sungrow's cybersecurity posture across SaaS, cloud, operational technology (OT), software suppliers, manufacturing partners, and strategic service providers supporting critical infrastructure operations. 

Key Responsibilities

Third-Party Risk Operations

  • Execute Sungrow's Third-Party Risk Management lifecycle, including vendor onboarding, periodic reassessments, contract renewals, and offboarding.
  • Perform vendor intake reviews to determine inherent risk, business criticality, data sensitivity, connectivity, and regulatory impact. 
  • Maintain the enterprise vendor inventory, vendor classifications, and risk tiering methodology. 
  • Coordinate vendor assessment schedules and ensure timely completion of required reviews.

Security Assessments & Due Diligence

  • Conduct security assessments for software vendors, cloud providers, managed service providers, professional services firms, product suppliers, and strategic third parties. 
  • Review and evaluate: 
  • SOC 2 Type II reports 
  • ISO 27001 certifications 
  • Penetration test summaries 
  • Security questionnaires (SIG, CAIQ, custom) 
  • Security policies and standards 
  • Business Continuity and Disaster Recovery documentation 
  • Privacy and data protection controls 
  • Identify control gaps, residual risks, and recommended mitigation strategies. 
  • Validate vendor controls against Sungrow security requirements and applicable regulatory frameworks.

Continuous Monitoring & Risk Management

  • Monitor vendor security posture throughout the vendor lifecycle. 
  • Track remediation commitments and coordinate follow-up activities through closure. 
  • Monitor vendor certifications, attestations, and supporting documentation for expiration and renewal. 
  • Maintain accurate vendor risk records within the organization's GRC platform. 
  • Assist in identifying changes in vendor ownership, subcontractors, or security posture that may affect organizational risk. 

Governance & Customer Assurance

  • Maintain complete, accurate, and audit-ready documentation supporting Sungrow's Third-Party Risk Management program. 
  • Support customer security assessments by providing vendor assurance documentation and supporting evidence.
  • Prepare reports and operational metrics covering: 
  • Assessment completion 
  • Vendor inventory 
  • Remediation status 
  • Assessment aging 
  • High-risk vendors 
  • Outstanding exceptions 
  • Support internal audits, customer reviews, and regulatory inquiries. 

Contract & Procurement Support

  • Partner with Procurement and Legal during vendor onboarding and contract renewals. 
  • Review vendor security documentation supporting contractual security obligations. 
  • Validate vendor compliance with contractual security requirements including: 
  • Incident notification 
  • Encryption 
  • Access control 
  • Data protection 
  • Business continuity 
  • Audit rights 
  • Escalate material risks requiring management review. 

Business Continuity Support

Working alongside the Third-Party Risk Management Lead:

  • Review vendor Business Continuity and Disaster Recovery capabilities during security assessments. 
  • Maintain Business Impact Analysis (BIA) documentation related to critical third-party services. 



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.