Third-Party Risk Management (TPRM) Risk Analyst

MongoDB Inc.

Dublin

Hybrid

EUR 120,000 - 150,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

MongoDB is seeking an experienced TPRM Risk Analyst in Dublin to support third-party risk management across onboarding and ongoing monitoring. You will collab­orate with Procurement, Legal, Enterprise Security and the business to assess risk, validate inherent risk ratings, and drive remediation in a complex data environment.

This role requires 7–10 years in TPRM/GRC, strong analytical skills, and certifications such as CRISC, CISM, CTPRP, or CRVPM.

Qualifications

  • 7-10 years of experience in Third-Party Risk Management (TPRM) or GRC.
  • Demonstrated experience performing substantive risk assessments and applying formula-based or quantitative risk methodologies.
  • Bachelor’s degree in a relevant field (Cybersecurity, Business, Information Systems).
  • Certifications (at least one required): CRISC, CISM, CTPRP, or CRVPM up to or in process of Level V.

Responsibilities

  • Lead risk assessment validation and remediation across third-party relationships, including high-risk and critical vendors.
  • Perform portfolio-level trend analysis and translate findings into risk-based recommendations.
  • Oversee SME reviews and assessments at onboarding and periodic reviews with minimal supervision.
  • Mentor Associate TPRM Risk Analyst and support audit and customer discussions.

Skills

Risk assessment
Data analysis
Stakeholder communication
Leadership
Mentoring
Audit support
Regulatory awareness
Critical thinking
GRC

Education

Bachelor’s degree in Cybersecurity, Business, Information Systems
Certifications: CRISC, CISM, CTPRP, CRVPM

Tools

TPRM platform
NIST SP 800-53
ISO 27001
SOC 2
CAIQ

Job description

Description:

The key objectives of the TPRM Program are to:

  • Assess the risk of third-party relationships which drive the rigor of risk management activities both during the third-party onboarding and ongoing monitoring lifecycle phases using the TPRM Program’s formula-based risk methodology
  • Act as a liaison across key internal stakeholder teams (Procurement, Legal, Enterprise Security and the Business) to ensure clear and accurate communication of third-party risks aligned to risk management activities in order to complete risk assessments in a timely manner
  • Identify TPRM program enhancements aimed at the effective and efficient management of third-party risk in order to support Business strategic initiatives

Reporting to the TPRM Manager, the TPRM Risk Analyst will be expected to have strong experience operating in a risk-based, data-driven model that will accommodate the business’s need to onboard vendors in a shortened timeframe, all while managing expectations and heightened scrutiny of both internal and external stakeholders including our customers. The TPRM Risk Analyst will understand and clearly communicate not only the “What” but also the “Why” in terms of third-party risk management activities in order to support efficient and effective third-party risk management as MongoDB continues to grow. This role requires substantial ability to interpret data and apply risk knowledge and judgment as the TPRM Risk Analyst manages a complex ecosystem of data, regulations, and stakeholder relationships while continuously identifying areas of enhancement to support effective third-party risk management.

We are looking to speak to candidates who are based in Dublin for our hybrid working model.

Responsibilities:

Risk Assessment Validation & Remediation

  • Strong experience in managing the full lifecycle of a Third Party from Sourcing to Payment
  • Independently validate inherent risk rating and Criticality designation for all third-party relationships with minimal intervention while proactively flagging any concerns to the TPRM Manager
  • Review third-party provided information and documentation for all third-party relationships in accordance with TPRM assessment methodology, proactively flagging any gaps or follow-up questions
  • Lead communication to third parties to remediate gaps for all High Risk and Critical third-party relationships, including documentation of remediation plans

Reporting & Trend Analysis

  • Independently lead portfolio-level trend analysis, build leadership- and audit-facing reporting, and translate findings into risk-based recommendations

Oversight & Periodic Review

  • Lead identification, tracking, and review of the adequacy of completion of SME reviews and assessments for all third-party relationships at onboarding with minimal oversight from manager
  • Independently provide oversight of the periodic review process, including identification and escalation of higher-risk findings or gaps

Mentorship & Stakeholder Support

  • Mentor the Associate TPRM Risk Analyst and support the TPRM Manager in audit and customer discussions
Requirements:
Experience & Education:
  • 7-10 years of experience in Third-Party Risk Management (TPRM) or Governance, Risk & Compliance (GRC)
  • Demonstrated experience performing substantive risk assessments and applying formula-based or quantitative risk methodologies
  • Bachelor’s degree in a relevant field (Cybersecurity, Business, Information Systems)
  • Certifications (at least one required): CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), CTPRP (Certified Third-Party Risk Professional), or CRVPM (Certified Regulatory Vendor Program Manager) up to or in process of Level V
Technical & Operational Proficiency:
  • Proficiency with a well established TPRM platform, including the ability to interpret intake data, Data Level classifications, and inherent risk scoring logic
  • Deep operational understanding of standard control frameworks (NIST SP 800-53, ISO 27001, SOC 2, SIG Core/Lite, CAIQ)
  • Working knowledge of heightened regulatory requirements relevant to the third-party population (e.g., DORA, GDPR, NIS2, FedRAMP, PCI-DSS, OCC, CCPA)
Core Competencies:
  • Analytical Rigor: ability to interpret data and apply risk knowledge and judgment to validate risk ratings and Criticality designations, not just process tickets
  • Communication: ability to translate portfolio-level findings into clear, leadership- and audit-facing risk recommendations
  • Check-and-Challenge: comfort with constructive challenge of third-party or SME responses to ensure gaps are identified and remediated
  • Leadership: ability to mentor junior team members and represent TPRM in audit and customer-facing discussions
About MongoDB

MongoDB is built for change, empowering our customers and our people to innovate at the speed of the market. We have redefined the data platform for the AI era, enabling builders to create, transform, and disrupt industries with software. MongoDB’s unified data platform, the most widely available, globally distributed data platform on the market, helps organizations modernize legacy workloads, embrace innovation, and unleash AI. Our cloud-native platform, MongoDB Atlas, is the only globally distributed, multi-cloud data platform and is available across AWS, Google Cloud, and Microsoft Azure.

With offices worldwide and over 67,000 customers, including AI-native startups and approximately 75% of the Fortune 100, relying on MongoDB for their most important applications, we’re powering the next era of software.

Our compass at MongoDB is our Leadership Commitment, guiding how and why we make decisions, show up for each other, and win. It’s what makes us MongoDB.

To drive the personal growth and business impact of our employees, we’re committed to developing a supportive and enriching culture for everyone. From employee affinity groups, to fertility assistance and a generous parental leave policy, we value our employees’ wellbeing and want to support them along every step of their professional and personal journeys. Learn more about what it’s like to work at MongoDB, and help us make an impact on the world!

MongoDB is committed to providing any necessary accommodations for individuals with disabilities within our application and interview process. To request an accommodation due to a disability, please inform your recruiter.

MongoDB is an equal opportunities employer.

Req. ID: 426442

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Third-Party Risk Management (TPRM) Risk Analyst
Third-Party Risk Management (TPRM) Risk Analyst

MongoDB • Dublin

On-site
EUR 90,000 - 130,000
Data-Driven TPRM Risk Analyst | Stakeholder Liaison
Data-Driven TPRM Risk Analyst | Stakeholder Liaison

MongoDB Inc. • Dublin

Hybrid
EUR 120,000 - 150,000
Hybrid work model
Hybrid TPRM Risk Analyst: Data-Driven Vendor Risk
Hybrid TPRM Risk Analyst: Data-Driven Vendor Risk

MongoDB • Dublin

Hybrid
EUR 90,000 - 130,000
Senior Financial Analyst
Senior Financial Analyst

MongoDB • Cork

On-site
EUR 75,000 - 110,000
Senior Financial Analyst
Senior Financial Analyst

MongoDB • Ireland

On-site
EUR 85,000 - 110,000
Hybrid work model (Dublin/Cork)
Senior Financial Analyst
Senior Financial Analyst

MongoDB • Dublin

On-site
EUR 70,000 - 98,000
Staff Technical Program Manager
Staff Technical Program Manager

Insider, Inc. • Dublin

On-site
EUR 80,000 - 110,000
Staff Technical Program Manager, Site Reliability Engineering
Staff Technical Program Manager, Site Reliability Engineering

MongoDB • Cork

On-site
EUR 110,000 - 150,000
Senior Manager, Financial Planning & Analysis
Senior Manager, Financial Planning & Analysis

AlleyCorp • Dublin

On-site
EUR 120,000 - 180,000
Senior Software Engineer, Product Security
Senior Software Engineer, Product Security

MongoDB Inc. • Dublin

Hybrid
EUR 120,000 - 150,000