Cybersecurity TPRM Strategy and Governance SME

Hewlett Packard Enterprise

San Juan (PR)

Hybrid

USD 120,000 - 180,000

Full time

13 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health & wellbeing benefits
Career development programs
Inclusive workplace

Job summary

Hewlett Packard Enterprise is seeking a Cybersecurity TPRM Strategy & Governance SME to define and advance the organization’s third‑party cybersecurity risk management strategy, operating model, and governance framework. You will lead risk-based frameworks, partner with Procurement, Legal, Compliance, Privacy, IT, and business stakeholders, and establish metrics and executive reporting.

This hybrid role requires a Bachelor’s or Master’s in Engineering, CS, or Information Security with 6–10 years

Qualifications

  • Demonstrated experience designing or managing TPRM programs, frameworks, and governance models.
  • Strong knowledge of cyber and IT security risks, threats and prevention measures.
  • Experience translating regulatory and security requirements into scalable policies, standards and processes.
  • Experience leading strategic initiatives, process transformation, and organizational change.
  • Industry certifications such as CISSP, CISM, CRISC, CISA, or equivalent.

Responsibilities

  • Develop and maintain the enterprise Cybersecurity Third-Party Risk Management (TPRM) strategy and operating model.
  • Define and improve third-party risk frameworks, standards, and procedures.
  • Lead evolution of vendor criticality, inherent risk, residual risk, and due diligence.
  • Identify opportunities to streamline and automate TPRM processes for scalability.
  • Partner with Procurement, Legal, Compliance, Privacy, IT, and stakeholders to align TPRM with objectives and regulatory requirements.
  • Establish metrics, KPIs, and reporting frameworks to measure program effectiveness and risk exposure.
  • Provide thought leadership on emerging risks including supply chain security and AI-related risks.
  • Lead assessments of TPRM tools and drive automation and workflow improvements.
  • Develop executive-level reporting to communicate program maturity and risks.
  • Support enterprise-wide regulatory compliance and governance initiatives.

Skills

TPRM programs
Governance models
NIST CSF/NIST 800-53
ISO 27001
Cybersecurity risk mgmt
Executive stakeholder mgmt

Education

Bachelor's or Master's in Engineering/CS/InfoSec

Tools

OneTrust
Archer
ServiceNow

Job description

This role has been designed as 'Hybrid' with a requirement that you will work on average 2 days per week from an HPE office.

Who We Are

Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.

Job Description

The Cybersecurity TPRM Strategy & Governance SME is responsible for defining and advancing the organization’s third-party cybersecurity risk management strategy, operating model, and governance framework. This role drives program maturity, efficiency, and scalability by establishing risk-based processes, standards, methodologies, and technology-enabled solutions that support effective management of cybersecurity risks throughout the third-party lifecycle.

Responsibilities
  • Develop and maintain the enterprise CybersecurityThird-Party Risk Management (TPRM) strategy, and operating model.
  • Define and continuously improve third party risk-based frameworks, methodologies, standards, and procedures for managing third-party cybersecurity risk.
  • Lead the evolution of vendor criticality, inherent risk, residual risk, and due diligence frameworks.
  • Identify opportunities to streamline, automate, and optimize TPRM processes to improve scalability, efficiency, and user experience.
  • Partner with Procurement, Legal, Compliance, Privacy, Supply Chain, IT, and business stakeholders to align TPRM processes with business objectives and regulatory requirements.
  • Establish metrics, KPIs, and reporting frameworks to measure program effectiveness, risk exposure, and operational performance.
  • Provide thought leadership on emerging risks, including supply chain security, software supply chain risk, cloud providers, AI-related risks, and operational resilience.
  • Lead assessments of TPRM tools and technology solutions and drive automation and workflow improvements.
  • Develop executive-level reporting and presentations to communicate program maturity, risks, and strategic initiatives.
  • Support enterprise-wide initiatives related to regulatory compliance, cybersecurity governance, and operational resilience.
  • Provides guidance and mentoring to less- experienced staff members.
Education And Experience Required
  • Bachelor's or Master's degree in Engineering, Computer Science, Information Security or equivalent.
  • Typically 6-10 years experience.
  • Security Certifications: preferred - CISSP ( other CRISC,CISM,etc)
Knowledge And Skills
  • Demonstrated experience and in-depth knowledge in designing or managing TPRM programs, frameworks, and governance models.
  • Solid knowledge and demonstrated experience of Cyber and IT security risks, threats and prevention measures.
  • Strong knowledge of cybersecurity and risk management frameworks such as NIST CSF, NIST 800-53, ISO 27001, and industry best practices.
  • Knowledge and experience of security fundamentals and technologies.
  • Experience translating regulatory and security requirements into scalable policies, standards, and operational processes.
  • Experience leading strategic initiatives, process transformation, and organizational change.
  • Industry certifications such as CISSP, CISM, CRISC, CISA, or equivalent.
  • Experience implementing or optimizing TPRM or GRC platforms (OneTrust, Archer, ServiceNow, etc).
  • Knowledge of global regulatory requirements, including DORA, NIS2, GDPR, SEC Cybersecurity Rules, and supply chain cybersecurity regulations.
  • Strong analytical, communication, stakeholder management, and executive presentation skills.
  • Excellent written and verbal communication skills; mastery in English.
Accessibility

HPE is committed to creating an inclusive and accessible workplace and encourages applications from all qualified individuals, including those with disabilities. If you believe you require accommodation during any stage of the application or interview process, please submit your request by completing our secure form linked here.

Note: This option is reserved for applicants needing assistance/reasonable accommodation related to a disability.

What We Can Offer You
Health & Wellbeing

We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.

Personal & Professional Development

We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.

Unconditional Inclusion

We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.

Let's Stay Connected

Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.

Job

Engineering

Job Level

TCP_04

HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.

Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.

HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity TPRM Strategy and Governance SME
Cybersecurity TPRM Strategy and Governance SME

Hewlett Packard Enterprise Company • Friday Harbor (WA)

Hybrid
USD 140,000 - 190,000
Cybersecurity TPRM Strategy and Governance SME
Cybersecurity TPRM Strategy and Governance SME

Hewlett Packard Enterprise Development LP • San Juan (PR)

On-site
USD 140,000 - 190,000
Manager, Advanced Threat Detection and Research
Manager, Advanced Threat Detection and Research

Hewlett Packard Enterprise • Sunnyvale (CA)

Hybrid
USD 183,000 - 371,000
Technical Program Manager
Technical Program Manager

Hewlett Packard Enterprise • New Hampshire

On-site
USD 146,000 - 343,000
Comprehensive benefits for health and wellbeing
Personal and professional development programs
Flexible work arrangements
VP, Head of Global Cyber Defense
VP, Head of Global Cyber Defense

Hewlett Packard Enterprise • Fort Collins (CO)

On-site
USD 203,000 - 407,000
Technical Program Manager
Technical Program Manager

Hewlett Packard Enterprise • Illinois

On-site
USD 146,000 - 343,000
Comprehensive health benefits
Personal & professional development programs
Flexible work arrangements
VP, Head of Global Cyber Defense
VP, Head of Global Cyber Defense

Hewlett Packard Enterprise • Spring (TX)

On-site
USD 203,000 - 468,000
Senior Engineer - Cybersecurity R&D
Senior Engineer - Cybersecurity R&D

Hewlett Packard Enterprise Development LP • San Juan (PR)

Hybrid
USD 120,000 - 180,000
Relocation support
VP, Head of Global Cyber Defense
VP, Head of Global Cyber Defense

Hewlett Packard Enterprise • Reston (VA)

On-site
USD 203,000 - 468,000
Technical Program Manager
Technical Program Manager

Hewlett Packard Enterprise • Phoenix (AZ)

On-site
USD 146,000 - 343,000
Comprehensive health and wellbeing benefits
Personal and professional development programs
Flexible work schedule