The Role

You will own vendor security questionnaires end-to-end for multiple clients. You will sit inside client Slack channels, catch questionnaire and security review requests as they come in, triage them into ticketing systems, and get every one submitted accurately and on time.

This is not a copy-paste job. Every answer you send out represents a client's security program. You need to actually understand each client's systems, policies, and controls, and know when to pull in an expert instead of guessing.

What You Will Do

  • Live in client Slack channels: monitor security and sales channels across multiple clients, acknowledge new requests fast, and be the person clients know will handle it
  • Triage into ticketing systems: convert every request into a tracked ticket (Jira, Linear, or whatever the client uses), set priorities based on deal size and deadlines, and track each one to completion
  • Answer vendor security questionnaires: complete SIG, CAIQ, and custom questionnaires in spreadsheet and portal formats (OneTrust, Whistic, SecurityScorecard, and similar), with answers based on the client's actual policies, systems, and evidence
  • Learn client environments: read the policies and understand the architecture well enough to answer questions about SSO and MFA, endpoint management, encryption, backups, incident response, and vendor management without looking everything up
  • Maintain answer libraries: keep each client's questionnaire knowledge base current, fold new answers back in after every submission, and flag stale answers when a client's environment changes
  • Coordinate with SMEs: route questions you cannot answer confidently to our consultants or client engineers, track their responses, and translate them into clear questionnaire language
  • Spot patterns: if the same missing policy or control keeps hurting questionnaire answers, raise it to the account lead so it gets fixed at the source

What We Require

  • 2-4 years of hands-on experience completing vendor security questionnaires, in GRC/compliance, or in a security-adjacent customer-facing role
  • Direct questionnaire experience: you have completed real VSQs (SIG, CAIQ, or custom formats) for a company or clients, not just reviewed them
  • Working knowledge of security frameworks: SOC 2 and ISO 27001 at minimum. You should be able to read a questionnaire item, map it to a control, and know where the evidence lives
  • Technical literacy: you can accurately describe SSO/MFA, endpoint management, encryption at rest and in transit, cloud hosting basics, and backup/DR. You don't have to build these controls, but you do need to describe them accurately
  • Organization: you can run a queue of requests across multiple clients with hard deadlines and keep stakeholders informed without being asked
  • Judgment: you know the difference between an answer you can give confidently and one that needs an SME or carries contractual risk, and you ask rather than guess
  • Fast, clear written communication: Slack is your primary workspace. Your responses need to be quick, professional, and precise
  • Professional-level English: written and verbal. You will interact with US-based client teams and their prospects' security reviewers daily

What Sets You Apart

  • You've handled questionnaires at volume (dozens per month), not occasionally
  • You've worked with questionnaire automation and trust center tools (Conveyor, SafeBase, Vanta, Whistic, or similar)
  • You've built or maintained an answer library and kept it accurate as the environment changed
  • You've sat close to a sales cycle and understand that a questionnaire is often the last blocker between a client and a closed deal
  • You hold certifications like Security+, ISC2 CC, or equivalent (not required, but signals foundation)

How to Apply

Send an introduction and resume to:

In your introduction, tell us:

  1. What is the largest or most complex security questionnaire you've completed, and how did you approach it?
  2. How do you keep a queue of requests across multiple stakeholders from slipping?
  3. Tell us about a questionnaire item you didn't know how to answer. What did you do?

We don't need a cover letter. We need to understand how you think and what you've actually done.