Cyber Risk Management Lead (TPRM)

Aventiv Technologies

United States

On-site

USD 103,000 - 129,000

Full time

44 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health Insurance
401(k)
Disability Insurance
Life Insurance
Paid Time Off
Voluntary Benefits

Job summary

Aventiv Technologies seeks a seasoned Third-Party Risk Management leader to oversee the TPRM program, drive framework governance, and coordinate cross-functional risk activities. The role requires deep security risk acumen and experience aligning controls with PCI, HIPAA, SOC2, and privacy requirements.

You will collaborate with legal, procurement, and business units to remediate gaps, report on metrics, and mentor others in security best practices.

Qualifications

  • 10+ years in Third-Party Risk Management and contractual arrangements.

Responsibilities

  • Manage and maintain a comprehensive TPRM framework and roadmap.
  • Track, measure third-party cyber risk management roadmap with risk prioritization.
  • Design, implement, and maintain a consistent TPRM approach across the enterprise.
  • Identify opportunities to enhance TPRM processes with innovative solutions.
  • Assess and monitor the TPRM lifecycle activities (risk assessment, due diligence, contracting, monitoring).
  • Establish TPRM policy and procedures; lead deployment of the TPRM module in the GRC tool.

Skills

Cybersecurity risk management
Project management
Communication
Policy development
Stakeholder collaboration
Attention to detail
Mentoring others

Education

HS diploma or GED
Bachelor's degree preferred
Certifications: CISM, CISA, CRISC, CTPRP, CTPRA, CDPSE

Tools

GRC tool
Shared Assessments SIG

Job description

  • Associate Referral Reward Eligible**

Welcome to Aventiv! Please watch this brief video to find out if this is the place you want to be!

Aventiv Technologies – Where your future awaits - YouTube

  • Associate Referral Reward Eligible**
Job Purpose

Responsible for overseeing the Third-Party Risk Management Program (TPRM) including projects and initiatives. Collaborate, Influence cross-functional partnerships across the enterprise to guide the business of third-party cyber risk management.

Essential Duties
  • Manage and maintain a comprehensive TPRM framework and roadmap
  • Track, and measure third-party cyber risk management roadmap with risk prioritization
  • Design, implement and maintain a consistent approach to all third-party risk to understand inherent risk, residual risk, gaps, and track mitigations
  • Identify, prioritize, and pursue opportunities to enhance TPRM processes with innovative approaches and solutions to optimize efficiency and effectiveness.
  • Assess and monitor the TPRM lifecycle activities (risk assessment & due diligent, contract negotiation, ongoing monitoring, and termination)
  • Establish relevant TPRM policy and procedures
  • Lead the implementation and continued deployment of the TPRM module within the GRC tool
  • Assess TPRM controls against regulatory requirements such as PCI, HIPAA, SOC2, NYDFS, privacy, etc. to identify gaps and ensure alignment
  • Collaborate with the business, legal, and procurement to ensure gaps identified in the TPRM areas are corrected, remediated, and monitored
  • Drive integration of the TPRM processes into the business and other risk verticals to extend the program to these and other areas
  • Provide and manage monthly reporting activity and analyzing metrics for performance TPRM program
  • Provide TPRM training, guidance, and support to all internal customers (e.g. business units, legal, procurement, etc.) and TPRM team members
  • Leverage industry-leading practices and trends to provide valuable risk insights to senior management
  • Other Duties as Assigned
Knowledge, Skills, And Abilities
  • Deep understanding of cybersecurity risk management processes
  • SME with compliance regulations/laws, security frameworks, and standards (e.g. PCI-DSS, FISMA, NIST, HIPAA, ISO, COBIT, CCPA, HITRUST, etc.)
  • Strong project management skills and ability to manage multiple projects
  • Ability to exercise and mentor others on good professional judgment and security-related ethics
  • Strong attention to detail and highly results oriented.
  • Excellent communication skills and ability to influence and guide others.
  • Build and maintain ongoing business relationships with strong interpersonal and communication skills.
  • Other duties as assigned.
Minimum Qualifications
  • 10+ years of direct functional knowledge and experience in Third-Party Risk management and contractual arrangements
  • HS Diploma or GED
  • Direct functional knowledge and experience in TPRM and contractual arrangements
  • Process design and process improvement experience
  • Experience in data gathering, analysis, and problem-solving skills.
  • Experience with Shared Assessments Standard Information Gathering Questionnaire (SIG) and processes.
  • Professional certification: with at least one of the following, CISM, CISA, CRISC, CTPRP, CTPRA, CDPSE
Preferred Qualifications
  • Bachelors' degree or equivalent work experience in a related discipline
  • Strong knowledge of various data protection legislation
  • Professional certification: CISSP with at least one of the following, CISM, CISA, CRISC, CTPRP, CTPRA, CDPSE
Physical Requirements
  • While performing the duties of this job, the employee is regularly required to: stand, sit, talk, hear, and use hands and fingers to operate a computer, telephone, and a variety of office equipment.
  • Occasionally, this position may need to reach, stoop, or kneel.
Salary And Benefits

At Aventiv, our salary and benefits are designed to fit you as a whole person. We offer a salary range based on experience and qualifications to ensure your unique contributions are met with our most competitive offer.

  • $102,555.53- $128,604.00 per year
  • Eligible for $255 to purchase company equipment (keyboard, monitor, headset, etc.
  • Health Insurance
  • 401(k)
  • Disability
  • Life Insurance
  • Paid Time Off
  • Voluntary Benefits
Aventiv Privacy Policy

www.aventiv.com/privacy

Equal Employment Policy

Aventiv is proud to be an equal opportunity employer. All decisions regarding recruiting, hiring, promotion, assignment, training, termination and other terms and conditions of employment will be made without regard to race, color, national origin, biological sex, sexual orientation, gender identity, gender expression, gender presentation, religion, age, pregnancy, disability, work-related injury, veteran status, genetic information, marital status, or any other factor that the law protects from employment discrimination. We do not discriminate based on genetic information in accordance with the Genetic Information Nondiscrimination Act.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Manager - Third-Party IT Risk Manager
IT Security Manager - Third-Party IT Risk Manager

Mass Digital Health • Waltham (MA)

On-site
USD 118,000 - 207,000
Client Assurance & TPRM Manager - Assistant Vice President
Client Assurance & TPRM Manager - Assistant Vice President

iCapital • Greenwich (CT)

On-site
USD 100,000 - 140,000
Equity compensation
Health benefits
Unlimited PTO
IT Third-Party Risk Manager
IT Third-Party Risk Manager

bankerstoolbox • Raleigh (NC)

Hybrid
USD 110,000 - 150,000
Health benefits with HSA
Flexible PTO
401(k) plan with company match
+1
IT Security Manager - Third-Party IT Risk Manager
IT Security Manager - Third-Party IT Risk Manager

Wolters Kluwer • Riverwoods (IL)

On-site
USD 118,000 - 208,000
Medical, Dental, & Vision Plans
401(k)
FSA/HSA
+2
Sr. TPRM Security Analyst
Sr. TPRM Security Analyst

Claritev • United States

On-site
USD 135,000 - 145,000
Health insurance
401(k) with company match
Paid time off
+2
Director, Enterprise Third-Party Risk Management Operations & Governance
Director, Enterprise Third-Party Risk Management Operations & Governance

Vertex Pharmaceuticals Incorporated • Boston (MA)

Hybrid
USD 176,000 - 264,000
Medical benefits
Paid time off
Commuting subsidy
Senior Quality Engineer
Senior Quality Engineer

Aventiv Technologies • Town of Florida (NY)

Hybrid
USD 90,000 - 102,000
Health Insurance
401(k)
Disability
+3
Product Mgr, Third-Party Risk Management
Product Mgr, Third-Party Risk Management

Applied Materials • Austin (TX)

On-site
USD 108,000 - 148,500
Advisor – Third-Party Risk Management (TPRM)
Advisor – Third-Party Risk Management (TPRM)

CGS CyberDefense • West Palm Beach (FL)

On-site
USD 90,000 - 120,000
Access to cutting-edge cybersecurity tools
Ongoing professional development
A culture that values curiosity and innovation
Third-Party Security Risk Management (TPRM) Lead
Third-Party Security Risk Management (TPRM) Lead

Workday • Reston (VA)

Hybrid
USD 171,000 - 256,000