About this role
Role Overview
Author and validate security-review tasks within high-fidelity simulated procurement workflows used to evaluate and train AI models for a spend-management product. The role focuses on applying experienced security reviewer judgment to simulated vendor evidence, creating step-level rubrics and golden responses, and ensuring realistic, security-focused scenarios for model training.
Key Responsibilities- Review simulated vendor SOC 2 reports, security questionnaires, and penetration test evidence against a buyer''s security standard
- Identify scope mismatches and lapsed bridge letters that a surface-level review would miss
- Author step-level rubrics and golden responses that capture how an experienced security reviewer would judge a request or renewal
- Assess data handling and sub-processor risk for vendors that touch sensitive data
- 8+ years of professional experience in security review, vendor risk management, or third-party risk management
- Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
- Strong written communication skills and comfort producing structured, rubric-style feedback
- Relevant security certification such as CISSP or CISA
- Prior experience writing tasks, authoring rubrics, or working with AI training data
- Location: Remote
- Engagement type: Hourly
- 90 to 110 per hour