--- title: 'Sr. Risk Analyst - Vendor Risk Assessment (VRA) at SentinelOne' canonical: 'https://feeny.ai/job/sr-risk-analyst-vendor-risk-assessment-vra-sentinelone-costa-rica-apgamtq9jkbk' type: 'job' last_seen: '2026-09-09' --- # Sr. Risk Analyst - Vendor Risk Assessment (VRA) at SentinelOne - **Company:** SentinelOne - **Location:** Costa Rica - **Posted:** 2026-07-10 - **Last confirmed live:** 2026-09-09 - **Apply:** https://www.sentinelone.com/jobs/?gh_jid=7777356003 ## Job description Our Purpose At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here. ## About Us SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters. Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity. What Are We Looking For? We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes. As a Senior Risk Analyst, Vendor Risk Assessment, you will be tasked with bringing technically grounded expertise to SentinelOne's Information Security GRC team. You will go beyond compliance knowledge to understand how systems work, how threats materialize, and how to evaluate vendor security controls with a critical technical eye. You will operate independently on assigned workstreams and apply hands-on IT and cybersecurity knowledge to assess risk accurately and credibly across a diverse vendor portfolio. What Will You Do? Primary responsibilities include: - Conduct end-to-end vendor assessments with the ability to go beyond questionnaire responses by evaluating SOC 2 reports, penetration test findings, vulnerability disclosures, network architecture diagrams, encryption practices, and access control configurations; identify technical control gaps and translate them into actionable, risk-prioritized remediation plans. - Review and interpret vendor-provided technical documentation, including system architecture diagrams, data flow maps, hardening standards, patch management practices, and incident response capabilities; apply knowledge of common IT environments (cloud, SaaS, on-prem, hybrid) to contextualize vendor risk accurately. - Map vendor technical controls to ISO 27001, SSAE 18/SOC 2, SOX ITGC, GDPR, NIST CSF/SP 800-53, and SentinelOne's internal security policies; identify gaps where technical implementation falls short of framework requirements and drive closure with vendors. - Own Vendor Risk Assessment workstreams and short to mid-term project objectives independently; track remediation activities to completion, validate technical evidence of fixes, and escalate unresolved risk to management with clear business impact framing. - Partner with IT, Engineering, Legal, and Procurement teams to gather technical context and align on risk tolerance; communicate findings clearly to both technical teams and non-technical stakeholders by translating risk into business impact. - Stay current on the evolving threat landscape, including cloud misconfigurations, supply chain attacks, and third-party data exposure risks, and apply this awareness to refine assessment criteria; begin mentoring junior analysts on technical evaluation methods and VRA tooling. - Actively apply AI tools to automate repetitive VRA workflows, accelerate vendor assessments, generate reporting, and surface risk insights faster; be prepared to share concrete examples of how you have used AI to automate tasks, improve reporting, or solve real problems in your work. What Skills and Knowledge Will You Bring? Ideal candidates will have: - 6 or more years of experience in information security, IT risk, vendor/third-party risk management, or GRC, with hands-on experience assessing vendors across a range of technical environments and approximately 75 to 150 vendor assessments completed; prior experience in an IT, systems, or security engineering role is a strong plus. - Solid understanding of core IT and security domains including network security (firewalls, segmentation, VPNs, DNS), cloud platforms and shared responsibility models (AWS, Azure, GCP), Identity and Access Management (SSO, MFA, privileged access), endpoint security, patch management and vulnerability management, data protection and encryption (at rest and in transit) and DLP, logging, monitoring and SIEM concepts, and secure SDLC and application security fundamentals. - Working knowledge of ISO 27001, SOC 2 (SSAE 18), NIST CSF/SP 800-53, SOX ITGC, GDPR, and CCPA. - Bachelor's degree in Computer Science, Information Technology, Information Security, Cybersecurity, or a related technical field, or equivalent demonstrated experience. - Preferred certifications include CISA, CISM, CISSP, CompTIA Security+, ISO 27001 Lead Auditor/Implementer, CCSK, AWS/Azure Security Specialty, or equivalent. Why SentinelOne? AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place. We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family: Equity & Rewards - Restricted Stock Units (RSUs) - Employee Stock Purchase Plan (ESPP) Time Off & Wellbeing - Competitive leave benefits - Gender-neutral parental leave Insurance & Financial Security - Private medical, dental, and vision insurance Work Perks & Flexibility - Global home office allowance - Internet or mobile phone allowance - Hybrid work model with flexible hours Wellness & Lifestyle - Wellness programs Growth & Community - In-office lunch program SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. SentinelOne participates in the E-Verify Program for all U.S. based roles. ## About SentinelOne ## Company Overview - **One-liner**: SentinelOne provides an AI-native autonomous security platform that unifies endpoint, cloud, and identity protection to help defenders stay ahead of cyber threats. - **Entity Type**: Public (NYSE: S) - **Headquarters**: Mountain View, California, USA - **Founded**: 2013 - **Founders**: Tomer Weingarten (CEO, Co-Founder), Almog Cohen (Co-Founder) ## Core Business - **Primary industry**: Cybersecurity (Endpoint Protection, Cloud Security, Identity Security, AI Security) - **Target customers**: B2B, Global 2000 enterprises, including four of the Fortune 10 and hundreds of the Fortune 500 - **Mission or purpose statement**: “To give the advantage to those who secure our future” – with a vision of “A Safer Future for Humanity” ## Products & Services - **[Singularity Platform]**: AI-driven autonomous security platform that unifies prevention, detection, response, remediation, and forensics across endpoint, cloud, and identity environments. Type: SaaS / Platform. - **[Purple AI]**: Security AI assistant that helps analysts investigate, hunt threats, and automate workflows. Type: SaaS / AI tool. - **[Cloud Security]**: Cloud workload protection, Cloud Detection and Response (CDR), and Kubernetes security. Type: SaaS. - **[Identity Security]**: Protection against identity-based attacks, including AD forgery, lateral movement, and credential theft. Type: SaaS. ## Market Standing - **Valuation/Market Cap**: Not provided in search results; refer to public financial data (NYSE: S). - **Key Metric**: Annual revenue not stated in provided materials; latest known revenue (FY2025) ~$725M (source not in search results). Total employees: 2,830 (from Built In, 2025). - **Notable Investors/Partners**: No specific investors listed (public company). Key partners include leading Global 2000 enterprises, Gartner (named a Leader in 2026 Magic Quadrant for Endpoint Protection Platforms for six consecutive years). - **Growth Signals**: 12 offices worldwide; recognized as a Fortune Best Place to Work in Tech (2024, 2025); Fortune Future Fifty company; Great Place to Work certified in 17+ countries; growing remote and in-office headcount. ## Competitive Advantages - **AI-native architecture**: Started with AI at the core, not bolted on – enables autonomous, machine-speed detection and response. - **Unified platform**: Covers endpoint, cloud, identity, and AI security in a single agent and console, reducing complexity for security teams. - **Industry validation**: Named a Leader in Gartner Magic Quadrant for six consecutive years; trusted by some of the world’s largest organizations. - **Autonomous response**: Fully automated remediation, reducing manual intervention and mean time to respond (MTTR). ## Strategic Focus - **Current priorities**: Expanding the Purple AI assistant, deepening cloud and identity protection, and enabling real-time, cross-platform autonomous defense at scale. - **Direction**: Build the operating model for AI-era security – where machines scale and humans guide – to give defenders a persistent advantage. ## Why Work Here - **Culture**: Core values – Accountability, Relentlessness, Ingenuity, Trust, Community, OneSentinel. Emphasizes inclusion, innovation, and customer-first mindset. - **Work environment**: Flexible – many roles offer remote options (US-Remote listed), with physical offices in 12 locations globally for those who prefer on-site. - **Perks & benefits**: Industry-leading compensation; 16 weeks gender-neutral parental leave; unlimited PTO; medical/dental/vision; gym reimbursement; mental health & mindfulness programs; stock programs (RSUs, ESPP); 401(k); legal assistance; apprenticeship programs. - **Growth opportunities**: Job training, conferences, talent development; early-career internships and apprenticeship programs; diverse employee resource groups. - **Recognition**: Fortune Best Places to Work in Tech (2024, 2025); Fortune Future Fifty; Best Place to Work for Parents; Great Place to Work certified across multiple countries. ## Sources 1. [SentinelOne Careers](https://www.sentinelone.com/careers/) 2. [SentinelOne Company Page](https://www.sentinelone.com/company/) 3. [SentinelOne Homepage](https://www.sentinelone.com/) 4. [SentinelOne Open Positions](https://www.sentinelone.com/jobs/) 5. [Built In – SentinelOne Profile](https://builtin.com/company/sentinelone) 6. [Greenhouse Careers Portal](https://job-boards.greenhouse.io/sentinellabs) ## Other roles at SentinelOne - [Staff FE/Full-stack Engineer (React/TS, Python) - SOC Automation](https://feeny.ai/job/staff-fe-full-stack-engineer-react-ts-python-soc-automation-sentinelone-brno-99qxahz7vggm) — Brno, Czech Republic - [Staff FE/Full-stack Engineer (React/TS, Python) - SOC Automation](https://feeny.ai/job/staff-fe-full-stack-engineer-react-ts-python-soc-automation-sentinelone-czech-f5kkg3wgagzd) — Czech Republic - [Staff FE/Full-stack Engineer (React/TS, Python) - SOC Automation](https://feeny.ai/job/staff-fe-full-stack-engineer-react-ts-python-soc-automation-sentinelone-slovakia-g0bjx18fmyrs) — Slovakia - [Staff FE/Full-stack Engineer (React/TS, Python) - SOC Automation](https://feeny.ai/job/staff-fe-full-stack-engineer-react-ts-python-soc-automation-sentinelone-prague-rs26gt0fjnca) — Prague, Czech Republic - [Sr. Application Security Engineer](https://feeny.ai/job/sr-application-security-engineer-sentinelone-united-states-a3633tqt1eb1) — United States - [Sr. Threat Hunter](https://feeny.ai/job/sr-threat-hunter-sentinelone-united-states-p9x6t0nze1tm) — United States - [Senior Growth Operations Specialist, Technical](https://feeny.ai/job/senior-growth-operations-specialist-technical-sentinelone-costa-rica-qnqsjz1a7h3a) — Costa Rica - [Senior Growth Operations Specialist, Commercial](https://feeny.ai/job/senior-growth-operations-specialist-commercial-sentinelone-costa-rica-cmxwn04pjpeg) — Costa Rica - [Staff Solutions Engineer (DACH)](https://feeny.ai/job/staff-solutions-engineer-dach-sentinelone-germany-5rx5zxey1sx8) — Germany - [Senior Solutions Engineer (DACH)](https://feeny.ai/job/senior-solutions-engineer-dach-sentinelone-germany-zppan52zw576) — Germany