
Manager, Third-Party Risk Management – TPRM
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Oversee daily operations of the Third-Party Risk Management (TPRM) process, encompassing vendor discovery, risk categorization, due diligence, onboarding, ongoing monitoring, remediation, and exit strategies.
• Manage the vendor inventory, policies, assessment criteria, and service standards for DoorDash, Wolt, and Deliveroo.
• Conduct evaluations of vendors associated with critical systems, including identity platforms, production cloud services, source code and CI/CD processes, and sensitive data platforms.
• Analyze architecture, data flows, permissions, and evidence of controls.
• Implement threat modeling techniques to identify potential compromise paths and outline requirements for access control, isolation, secrets management, encryption, logging, and revocation.
• Collaborate with vendors, Legal, Privacy, Procurement, and system owners to establish mitigation plans and security contract terms.
• Confirm remediation efforts and document acceptance of residual risks, access removal, and data handling at the time of termination.
• Address supplier dependencies, concentration risks, recovery capabilities, and readiness for exit.
• Define the vision and strategy for an AI-driven TPRM function.
• Develop and test workflows for evidence collection, identification of control gaps, drafting assessments, and coordinating follow-ups.
• Assess the requirements for configuration, purchasing, or development in collaboration with Security Engineering, IT, and platform owners.
• Manage the TPRM framework for third-party AI and agentic services.
• Recruit, mentor, and directly oversee TPRM professionals and GRC direct reports based in the US.
• Provide GRC support during US business hours and act as an escalation point for the Global Head of GRC.
• Facilitate stakeholder discussions and coordinate GRC contributions to incidents, audits, and urgent business decisions.
• Report on critical system vulnerabilities, overdue remediation, exception aging, assessment quality, and review turnaround times to leadership and auditors.
• Assess improvements in AI and automation while translating significant risks into business implications.
• Minimum of 6 years of progressive experience in technical third-party risk, security risk, or security engineering.
• Extensive hands-on experience in leading complex vendor assessments and managing a TPRM program.
• Proven track record of enhancing risk management practices within a technology-focused environment.
• Experience in leading distributed teams and coordinating efforts across various GRC specialties.
• Background in evaluating enterprise integrations and identifying potential failure modes.
• Proficient knowledge of SAML/OIDC federation, OAuth scopes and tokens, SCIM provisioning, APIs, service accounts, cloud IAM, network boundaries, and data flows.
• Strong skills in assurance and control testing.
• Capability to assess SOC 2 Type II scope, exceptions, subservice organizations, and customer responsibilities.
• Proficient in interpreting penetration test results and evidence from ISO 27001 or PCI DSS assessments.
• Familiarity with AI-native approaches, including the use of AI-assisted workflows.
• Experience in implementing or enhancing TPRM/GRC platforms and automating workflows.
• Practical understanding of APIs and integration methodologies.
• Ability to define requirements, work with structured data, and collaborate with engineers.
• Hands-on experience with cloud and SaaS security, managing privileged supplier or BPO access, data protection, incident response, and recovery processes.
• Proficient in applying security frameworks and threat modeling to vendor deployments.
• Knowledge of AI-related risks including data usage, tool permissions, and prompt injection issues.
• Experience in representing a security or GRC leader and making decisions within the scope of delegated authority.
• Strong communication skills for interactions with engineers, Legal, Procurement, and business leaders.
• Based in the United States, preferably in the Eastern or Central time zones.
• Core working hours aligned with US business requirements.
• Equity grants
• 401(k) plan with employer matching
• 16 weeks of paid parental leave
• Wellness benefits
• Commuter benefits match
• Paid time off
• Paid sick leave
• Medical, dental, and vision benefits
• 11 paid holidays
• Disability insurance
• Basic life insurance
• Family-forming assistance
• Mental health program
• Flexible paid time off/vacation for salaried roles
• 80 hours of paid sick time per year for salaried roles
• Premium healthcare
• Wellness expense reimbursement
AAA
TransUnion
RTX
Get handpicked remote jobs straight to your inbox weekly.