Technology Risk Principal Technology Third Party Risk Management
Posted yesterday
is3 solutionsDallas (TX)
Information Technology Project ManagersComputer Systems Design Services
SENIORITY
Manager
About the role
Technology Risk Principal Technology Third Party Risk ManagementAs a Technology Risk Principal Technology Third Party Risk Management, you will be responsible for driving risk management efforts to ensure strong discipline and control for engagements with technology third parties, and providing advisory for the company's enterprise-wide TPRM program. Increasing levels of risk and regulatory requirements demand additional risk management rigor, and we must implement highly resilient, secure, and effective solutions that meet and, in some cases, exceed performance standards found in other information rich industries. You will provide leadership and support for Technology Risk initiatives across the business and strengthen third party risk management through development and maturing of governance and controls. You will utilize risk-based management to integrate information and technology risk processes into third party ecosystem operates.You will be responsible for orchestrating a diverse set of stakeholders to identify, assess, mitigate, and monitor third party risks and drive improved governance and control across the program. You will focus on inherent and residual risk of technology third parties that support mission critical systems, access and control sensitive data, and provide hardware and software products that support operations. You will evaluate the maturity of third party risk management practices and drive program enhancements to design key elements like third party inventory, risk tiering, due diligence, and monitoring. You will ensure that regulatory / risk policies and standards and their impact on business operations are understood and addressed consistently, and that third party risks of new and existing technologies are assessed, monitored, and remediated, as necessary.Responsibilities:Drive the evolution of Technology Third Party Risk Management program, including processes to identify, assess, mitigate, monitor, and report technology third-party risksAdvise on the design and enhancement of foundational TPRM capabilities, including policies and standards, third-party inventory, risk tiering, due diligence, onboarding, monitoring, and termination activitiesEvaluate program maturity and lead improvement initiatives across governance, processes, controls, technology enablement, and data management capabilitiesPartner with stakeholders across Supply Chain, Enterprise Risk Management, Compliance, Technology, and Legal to advance strategic program objectives and strengthen risk management practicesDevelop executive-level risk assessments, point-of-view documents, and escalation materials related to critical third parties, emerging risks, and program gapsServe as a trusted advisor to business units on emerging third-party risk topics, regulatory developments, and industry best practicesQualifications:7+ years experience in multiple industry risk, control, and governance disciplines (e.g., Audit, Information Security, and Regulatory Compliance)5+ years of work experience in third party risk management and/or supply chain processes at a global company with strong understanding of technology products, services, and lifecyclesStrong presentation and executive oral/written communication skills with demonstrated experience leading culture and capabilities change across a diverse set of stakeholder groupsExperience designing, implementing, and sustaining programs that effectively manage risk throughout the risk management lifecycle, including:Strategic technology risk advisoryRisk identification, including emerging risksMaturity and risk assessment, scenario analysisRisk response, mainly issue remediationRisk monitoringPolicy and committee governanceDemonstrated success in remediating self-identified, internal / external audit, and regulatory / compliance issues with proven ability to shape and solve complex problem statementsExtensive knowledge of information and technology risk management policies, methods, standards, tools, and processes (e.g., ISO, COSO, COBIT, NIST) as well as knowledge of compliance, legal, internal / external audit & regulatory requirements Desired QualificationBS and advanced degree preferredProfessional TPRM related certifications such as CTPRP, TPCRA, TPRMP, CRISC, CISSP preferred
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
