Summary
The Third-Party Risk Management Manager leads and enhances the company's third-party risk program. The role oversees vendor risk assessments, monitoring, reporting, and program improvement in partnership with business and control functions.
Responsibilities
- Manage daily execution and governance of the TPRM program, including policies, procedures, metrics, and process improvements.
- Lead vendor risk assessments and review security documentation, identifying risks and recommending remediation.
- Coordinate risk acceptance, escalations, audits, and regulatory inquiries with internal stakeholders.
- Develop executive dashboards and reporting on vendor risk, remediation, and program performance.
- Manage and mentor analysts or consultants and maintain quality standards for assessments.
Requirements
- Bachelor's degree in information security, cybersecurity, information technology, business administration, risk management, or a related field.
- 7+ years of experience in information security, IT risk management, cybersecurity, compliance, internal audit, or third-party risk management.
- 3+ years of experience managing TPRM programs or teams.
- Experience evaluating security controls and standards such as ISO 27001, NIST, SOC 1, SOC 2, PCI DSS, and privacy regulations.
- Strong vendor risk analysis, stakeholder communication, reporting, and executive presentation skills.
- Experience with GRC or TPRM platforms; relevant professional certifications are preferred.