Advisor - Third Party Risk Management (Contract)

Posted yesterday

cgs cyberdefenseDenver (CO)

SENIORITY

Senior

Apply

About the role

Part Time - Contract - Advisor Third-Party Risk Management (TPRM)Cybersecurity Management ConsultingCGS Cyber Defense is seeking an experienced Advisor - Third-Party Risk Management, Part-Time to support day-to-day operations of a client's Third-Party Risk Management program, including vendor intake, assessment coordination, stakeholder communication, and workflow management. The Advisor works alongside a junior team member and reports to the CGS engagement lead.
Responsibilities: • Support third-party cybersecurity risk assessments and vendor due diligence engagements across industries and regulatory environments• Assist in developing and operationalizing TPRM frameworks, governance models, and operating procedures • Establish appropriate goals and objectives to deliver exceptional third-party risk management services in alignment with the client’s strategy and in support of client’s overall organization goals• Foster collaborative working relationships with client’s security stakeholders and guide the team to provide exceptional customer experience• Ensure third party assessment data integrity and quality control• Regularly review and gain insights from data and metrics • Evaluate vendor control environments using assessments• Support vendor segmentation, criticality classification, and continuous monitoring of risk profiles• Support and optimize technology enablement for TPRM programs using platforms• Coordinate communication between procurement, security, and compliance teams to enhance vendor governance• Monitor and manage vendor risk assessment requests in accordance with established procedures• Set up vendor records and coordinate assessment initiation and routing to appropriate stakeholders• Track assessment progress and follow up with vendors and internal teams to ensure timely completion• Trigger AI questionnaires when applicable and notify the Privacy team when a Privacy Risk Assessment is required• Maintain and update program reporting and status dashboards in accordance with established reporting cadence• Coordinate handoffs to designated risk reviewers upon completion of assessment activities• Maintain all vendor risk management records, documentation, and status updates within the GRC platform• Provide day-to-day guidance to a junior team member on third-party risk management processes and procedures Qualifications • 3-5 years of experience in cybersecurity, specifically third party risk management, or vendor/risk roles• Solid understanding of third-party risk management concepts, due diligence processes, and control assessment methodologies• Familiarity with frameworks and standards such as NIST CSF, ISO 27036, SOC 2, SIG, and shared responsibility models• Strong communication, project management, and client advisory skills• Experience working in a client-embedded or consulting environment - comfortable operating independently within a client's systems and processes • Proven experience successfully leading or mentoring others• Excellent written and verbal communication with ability to explain complex issues to technical and non-technical users across the enterprise and to external parties• Strong collaboration and coordination skills• Proficient in Microsoft O365 products Desired Experience• Bachelor's degree in Information Security, Supply Chain Risk, Business, or related field • Hands-on experience with GRC platforms (Service Now Vendor VRM, One Trust, Archer, etc)• Knowledge of regulatory requirements impacting vendor risk (e.g., OCC, HIPAA, GDPR, CMMC)• Strong analytical, reporting, and visualization skills (Excel, Power BI, or similar tools)• Experience with continuous vendor monitoring tools (Black Kite, Security Scorecard, etc)• Familiarity with AI risk questionnaires or privacy risk assessment

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this