Search by job, company or skills

Third Party RIsk management consultant

Early Applicant
  • Posted 24 days ago
  • Be among the first 10 applicants

Job Description

  • Lead the execution and continuous improvement of the Third-Party Risk Management lifecycle, including on boarding assessments, ongoing monitoring, risk reviews, and exit management.
  • Oversee the development and implementation of TPRM policies, frameworks, and procedures, aligned with regulatory standards such as NIST, ISO 27001, SOC 2, GDPR, DORA, and PCI DSS.
  • Conduct and review inherent and residual risk assessments for new and existing vendors across multiple risk domains (information security, compliance, financial, operational, etc.).
  • Collaborate with procurement, legal, IT, business units, and compliance teams to integrate TPRM into sourcing and contract processes.
  • Drive the automation and scalability of the TPRM program through use of GRC platforms (e.g., ServiceNow, Archer, ProcessUnity, OneTrust).
  • Manage third-party due diligence questionnaires (DDQs), control gap analysis, and track remediation efforts for identified issues.
  • Prepare and deliver executive-level reporting and dashboards related to vendor risk posture, risk acceptance, and compliance status.
  • Stay current on emerging regulatory requirements, supply chain risks, and third-party threats to inform program strategy.
  • Support internal/external audits and regulatory reviews involving vendor risk management.

 

  • 10–12 years of professional experience in Third-Party Risk Management, IT Risk, InfoSec, Audit, or related GRC functions.
  • In-depth understanding of third-party risk domains, including cybersecurity, data privacy, business continuity, and compliance.
  • Experience developing or managing TPRM frameworks and governance structures across global enterprises.
  • Hands-on experience with TPRM tools such as ServiceNow GRC, Archer, OneTrust, Prevalent, or ProcessUnity.
  • Strong knowledge of risk and control frameworks including NIST, ISO 27001, SIG, SOC 2, and GDPR.
  • Proven ability to assess and report on third-party risk posture, remediation plans, and contract compliance.
  • Excellent written and verbal communication skills with ability to influence technical and non-technical audiences.

More Info

Job Type:
Industry:
Employment Type:

Job ID: 151573895

Similar Jobs

Bengaluru, India

Skills:

ArcherGdprIso 27001TPRM tools such as ServiceNow GRCOneTrustrisk and control frameworks including NISTProcessUnitySOC 2SIGPrevalent

Beware of Scammers

We don’t charge money for job offers