Build a Tiered Vendor-Security Review Program, Validated by a 12-Vendor Pilot
Overview
What this challenge is about.
Build a Tiered Vendor-Security Review Program, Validated by a 12-Vendor Pilot. Intermediate challenge in strategy. Developing strategies for real business pr...
The Brief
What you'll do, and what you'll demonstrate.
Build a tiered third-party-risk program a two-person security team can run, and prove it works by scoring twelve vendors against documented evidence and reporting the top five risks to the board.
This is not a case study exercise. It is the work a consultant does when a client needs a recommendation backed by evidence. That distinction matters to every hiring manager who has seen candidates recite Porter's Five Forces and none who have built a recommendation a client would actually pay for.
When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."
Earning criteria — what you'll demonstrate
- Translate data-type, integration-depth, downtime-impact, and regulatory factors into objective vendor risk tiers.
- Read a SOC 2 report summary and a data-processing-agreement excerpt to extract decision-relevant evidence.
- Design a repeatable scoring rubric that produces consistent results across reviewers.
- Communicate vendor risk and concentration to a non-technical board audience.
- Right-size a governance program to the staffing reality of a two-person security team.
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Third Party Risk
Apply third party risk to solve real industry problems and demonstrate production-level capability.
- Security Governance
Apply security governance to solve real industry problems and demonstrate production-level capability.
- Compliance
Apply compliance to solve real industry problems and demonstrate production-level capability.
- Risk Management
Identify, assess, and mitigate risks across business operations and projects.
- Stakeholder Communication
Apply stakeholder communication to solve real industry problems and demonstrate production-level capability.
- Remediation Planning
Apply remediation planning to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Third-Party Risk Analyst
This challenge mirrors the core analyst loop: classify vendors, collect evidence, score consistently, and report. You leave with a working tiering model and a scored pilot that demonstrates you can run a vendor-risk program end to end with limited staffing.
This challenge sharpens
- third-party-risk
- risk-management
- compliance
Security Governance Engineer
Designing an operable program playbook and intake process maps directly to building governance that engineering teams will actually follow. You practice turning SOC 2 and GDPR obligations into lightweight, repeatable controls.
This challenge sharpens
- security-governance
- compliance
- remediation-planning
Compliance Program Manager
The board summary and remediation plan rehearse the communication and prioritization a program manager owns, translating vendor risk into decisions an executive audience can approve and fund.
This challenge sharpens
- compliance
- stakeholder-communication
- remediation-planning