Cybersecurity TPRM Strategy and Governance SME

Hewlett Packard Enterprise Company

Friday Harbor (WA)

Hybrid

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Hewlett Packard Enterprise is seeking a Cybersecurity TPRM Strategy and Governance SME to lead the enterprise third-party risk management program. The role is hybrid, requiring an average of 2 days per week from an HPE office, and focuses on defining strategy, operating model, and a governance framework for TPRM across the organization.

You will partner with Procurement, Legal, Compliance, Privacy, IT, and business stakeholders to align processes with regulatory requirements, establish KPIs, and

Qualifications

  • Designing or managing TPRM programs, frameworks, and governance models.
  • Knowledge of cyber and IT security risks, threats, and prevention measures.
  • Experience with risk management frameworks like NIST CSF, NIST 800-53, ISO 27001.

Responsibilities

  • Develop and maintain the enterprise Cybersecurity Third-Party Risk Management strategy and operating model.
  • Define risk-based frameworks, standards, and procedures for managing third-party cybersecurity risk.
  • Lead vendor criticality, inherent risk, residual risk, and due diligence frameworks.
  • Identify opportunities to streamline and automate TPRM processes for scalability.
  • Partner with Procurement, Legal, Compliance, Privacy, IT, and stakeholders to align processes with regulatory requirements.
  • Establish metrics, KPIs, and reporting to measure program effectiveness and risk exposure.
  • Provide thought leadership on emerging risks including supply chain security and AI-related risks.
  • Lead assessments of TPRM tools and drive automation and workflow improvements.
  • Develop executive-level reporting to communicate maturity and strategic initiatives.
  • Support enterprise-wide regulatory compliance and governance initiatives.

Skills

TPRM strategy
Governance
Executive communication
Stakeholder management
NIST CSF knowledge
ISO 27001 knowledge
Cybersecurity risk management
GRC platforms

Education

Bachelor's or Master's degree in Engineering, Computer Science, Information Security or equivalent

Tools

OneTrust
Archer
ServiceNow

Job description

Cybersecurity TPRM Strategy and Governance SME

This role has been designed as 'Hybrid' with a requirement that you will work on average 2 days per week from an HPE office.

Who We Are:

Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today's complex world. Our culture thrives on finding new and better ways to accelerate what's next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.

Job Description:
Job Descritption

The Cybersecurity TPRM Strategy & Governance SME is responsible for defining and advancing the organization's third-party cybersecurity risk management strategy, operating model, and governance framework. This role drives program maturity, efficiency, and scalability by establishing risk-based processes, standards, methodologies, and technology-enabled solutions that support effective management of cybersecurity risks throughout the third-party lifecycle.

Responsibilities:
  • Develop and maintain the enterprise CybersecurityThird-Party Risk Management (TPRM) strategy, and operating model.
  • Define and continuously improve third party risk-based frameworks, methodologies, standards, and procedures for managing third-party cybersecurity risk.
  • Lead the evolution of vendor criticality, inherent risk, residual risk, and due diligence frameworks.
  • Identify opportunities to streamline, automate, and optimize TPRM processes to improve scalability, efficiency, and user experience.
  • Partner with Procurement, Legal, Compliance, Privacy, Supply Chain, IT, and business stakeholders to align TPRM processes with business objectives and regulatory requirements.
  • Establish metrics, KPIs, and reporting frameworks to measure program effectiveness, risk exposure, and operational performance.
  • Provide thought leadership on emerging risks, including supply chain security, software supply chain risk, cloud providers, AI-related risks, and operational resilience.
  • Lead assessments of TPRM tools and technology solutions and drive automation and workflow improvements.
  • Develop executive-level reporting and presentations to communicate program maturity, risks, and strategic initiatives.
  • Support enterprise-wide initiatives related to regulatory compliance, cybersecurity governance, and operational resilience.
  • Provides guidance and mentoring to less- experienced staff members.
Education and Experience Required:
  • Bachelor's or Master's degree in Engineering, Computer Science, Information Security or equivalent.
  • Typically 6-10 years experience.
  • Security Certifications: preferred - CISSP ( other CRISC,CISM,etc)
Knowledge and Skills:
  • Demonstrated experience and in-depth knowledge in designing or managing TPRM programs, frameworks, and governance models.
  • Solid knowledge and demonstrated experience of Cyber and IT security risks, threats and prevention measures.
  • Strong knowledge of cybersecurity and risk management frameworks such as NIST CSF, NIST 800-53, ISO 27001, and industry best practices.
  • Knowledge and experience of security fundamentals and technologies.
  • Experience translating regulatory and security requirements into scalable policies, standards, and operational processes.
  • Experience leading strategic initiatives, process transformation, and organizational change.
  • Industry certifications such as CISSP, CISM, CRISC, CISA, or equivalent.
  • Experience implementing or optimizing TPRM or GRC platforms (OneTrust, Archer, ServiceNow, etc.).
  • Knowledge of global regulatory requirements, including DORA, NIS2, GDPR, SEC Cybersecurity Rules, and supply chain cybersecurity regulations.
  • Strong analytical, communication, stakeholder management, and executive presentation skills.
  • Excellent written and verbal communication skills; mastery in English.
Accessibility

HPE is committed to creating an inclusive and accessible workplace and encourages applications from all qualified individuals, including those with disabilities. If you believe you require accommodation during any stage of the application or interview process, please submit your request by completing our secure form linked here .

Note: This option is reserved for applicants needing assistance/reasonable accommodation related to a disability.

What We Can Offer You:
Health & Wellbeing

We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.

Personal & Professional Development

We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have - whether you want to become a knowledge expert in your field or apply your skills to another division.

Unconditional Inclusion

We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.

Let's Stay Connected:

Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.

Job:

Engineering

Job Level:

TCP_04

HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity .

Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.

HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity TPRM Strategy and Governance SME
Cybersecurity TPRM Strategy and Governance SME

Hewlett Packard Enterprise • San Juan (PR)

Hybrid
USD 120,000 - 180,000
Health & wellbeing benefits
Career development programs
Inclusive workplace
Cybersecurity TPRM Strategy and Governance SME
Cybersecurity TPRM Strategy and Governance SME

Hewlett Packard Enterprise Development LP • San Juan (PR)

On-site
USD 140,000 - 190,000
Cybersecurity TPRM Strategy & Governance Lead
Cybersecurity TPRM Strategy & Governance Lead

Hewlett Packard Enterprise • San Juan (PR)

Hybrid
USD 120,000 - 180,000
Health & wellbeing benefits
Career development programs
Inclusive workplace
Manager, Advanced Threat Detection and Research
Manager, Advanced Threat Detection and Research

Hewlett Packard Enterprise • Sunnyvale (CA)

Hybrid
USD 183,000 - 371,000
Senior Engineer - Cybersecurity R&D
Senior Engineer - Cybersecurity R&D

Hewlett Packard Enterprise Development LP • San Juan (PR)

Hybrid
USD 120,000 - 180,000
Relocation support
Cybersecurity TPRM Strategy Lead
Cybersecurity TPRM Strategy Lead

Hewlett Packard Enterprise Company • Friday Harbor (WA)

Hybrid
USD 140,000 - 190,000
Principal Engineer - Cybersecurity R&D
Principal Engineer - Cybersecurity R&D

hpe • San Juan (PR)

Hybrid
USD 160,000 - 230,000
Relocation support
Inclusive, accessible workplace
VP, Head of Global Cyber Defense
VP, Head of Global Cyber Defense

Hewlett Packard Enterprise • Fort Collins (CO)

On-site
USD 203,000 - 407,000
VP, Head of Global Cyber Defense
VP, Head of Global Cyber Defense

Hobbsnews • Spring (TX), Northern (KY)

On-site
USD 203,000 - 407,000
VP, Head of Global Cyber Defense
VP, Head of Global Cyber Defense

Hewlett Packard Enterprise • Spring (TX)

On-site
USD 203,000 - 468,000