Ralph Lauren IT Third-Party Risk Management (TPRM) Manager

BoF Careers

Nutley (NJ)

On-site

USD 150,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ralph Lauren Corporation seeks a Third-Party Risk Management (TPRM) manager to lead and mature the vendor risk program across the lifecycle. You will partner with Procurement, Legal, Privacy, Information Security, Internal Audit and business units to assess, monitor, and mitigate third-party risks in line with regulatory and business requirements.

Responsibilities include establishing governance, KPIs, risk assessments, and reporting; driving automation and process improvements; and guiding risk

Qualifications

  • 7+ years in Information Security, IT Risk Management, Cybersecurity, Compliance, Internal Audit, or TPRM.
  • 3+ years leading TPRM programs or teams.
  • Experience evaluating controls against ISO 27001, NIST, SOC 1/2, PCI DSS, and privacy regulations.

Responsibilities

  • Lead day-to-day execution of the Third-Party Risk Management program.
  • Maintain and enhance TPRM policies, standards, procedures, and governance frameworks.
  • Drive program maturity, automation initiatives, and process optimization.
  • Establish and monitor TPRM KPIs, KRIs, SLAs, and reporting metrics.
  • Lead risk assessments of new and existing third-party providers.
  • Review security documentation and certifications (SIG, SOC, ISO).
  • Document findings and provide remediation recommendations.
  • Present significant third-party risks to senior leadership.

Skills

Vendor risk assessment
Risk analysis
Stakeholder management
Executive reporting
GRC platforms

Education

Bachelor's degree in Information Security, Cybersecurity, IT, Risk Management

Tools

OneTrust
ServiceNow
Archer
ProcessUnity
AuditBoard

Job description

Company Description

Ralph Lauren Corporation (NYSE:RL) is a global leader in the design, marketing and distribution of premium lifestyle products in five categories: apparel, accessories, home, fragrances, and hospitality. For more than 50 years, Ralph Lauren's reputation and distinctive image have been consistently developed across an expanding number of products, brands and international markets. The Company's brand names, which include Ralph Lauren, Ralph Lauren Collection, Ralph Lauren Purple Label, Polo Ralph Lauren, Double RL, Lauren Ralph Lauren, Polo Ralph Lauren Children, Chaps, among others, constitute one of the world's most widely recognized families of consumer brands. At Ralph Lauren, we unite and inspire the communities within our company as well as those in which we serve by amplifying voices and perspectives to create a culture of belonging, ensuring inclusion, and fairness for all. We foster a culture of inclusion through: Talent, Education & Communication, Employee Groups and Celebration.

Position Overview

The Third-Party Risk Management (TPRM) manager is responsible for leading and enhancing Ralph Lauren's Third-Party Risk Management program. This role oversees the assessment, monitoring, and reporting of third-party risks across the vendor lifecycle, ensuring alignment with information security, privacy, compliance, regulatory, and business requirements. The successful candidate will partner with Procurement, Legal, Privacy, Information Security, Internal Audit, and business stakeholders to identify, assess, and mitigate risks associated with third-party providers while supporting enterprise risk management objectives. The role will also drive program maturity, operational efficiency, reporting, and continuous improvement initiatives.

Essential Duties & Responsibilities
  • Manage day-to-day execution of the Third-Party Risk Management program.
  • Maintain and enhance TPRM policies, standards, procedures, and governance frameworks.
  • Drive program maturity improvements, automation initiatives, and process optimization.
  • Establish and monitor TPRM KPIs, KRIs, SLAs, and reporting metrics. Risk Assessments & Due Diligence
  • Lead risk assessments of new and existing third-party providers.
  • Review SIG questionnaires, SOC reports, ISO certifications, penetration testing reports, and other security documentation.
  • Evaluate information security, privacy, compliance, operational, and resilience risks.
  • Document findings, develop risk assessments, and provide recommendations for remediation. Risk Governance & Oversight
  • Facilitate risk acceptance, exception management, and escalation processes.
  • Present significant third-party risks to senior leadership and governance committees.
  • Ensure consistent application of risk-tiering methodologies and review requirements.
  • Support audits, regulatory inquiries, and compliance initiatives. Stakeholder Management
  • Serve as the primary point of contact for business stakeholders regarding third-party risk requirements.
  • Partner with Procurement, Legal, Privacy, Architecture, Security Engineering, and business units throughout the vendor lifecycle.
  • Provide guidance on security and compliance requirements during vendor onboarding and contract negotiations. Reporting & Analytics
  • Develop executive-level dashboards and reporting related to vendor risk posture, assessment volumes, remediation status, SLA performance, and program health.
  • Track and report findings, remediation progress, and emerging third-party risks.
  • Provide actionable insights to leadership to support informed risk decisions. Team Leadership
  • Manage and mentor TPRM analysts and/or external consultants.
  • Establish quality standards for risk assessments and deliverables.
  • Promote a culture of accountability, operational excellence, and continuous improvement.
Experience, Skills & Knowledge
Education
  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business Administration, Risk Management, or related field. Experience
Experience
  • 7+ years of experience in Information Security, IT Risk Management, Cybersecurity, Compliance, Internal Audit, or Third-Party Risk Management.
  • 3+ years of experience managing TPRM programs or teams.
  • Experience evaluating security controls and industry standards such as ISO 27001, NIST, SOC 1, SOC 2, PCI DSS, and privacy regulations.
Skills
  • Strong vendor risk assessment and risk analysis capabilities.
  • Knowledge of cybersecurity, privacy, and regulatory requirements.
  • Exceptional stakeholder management and communication skills.
  • Strong reporting, metrics, and executive presentation skills.
  • Experience with GRC and TPRM platforms (e.g., OneTrust, ServiceNow, Archer, ProcessUnity, AuditBoard).
Preferred Qualifications
  • CISSP, CISM, CRISC, CISA, CGEIT, or equivalent certification.
  • Experience in retail, consumer products, or global enterprise environments.
  • Experience implementing TPRM automation and workflow solutions.
  • Knowledge of privacy regulations and data protection frameworks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Third-Party Risk Manager (TPRM)
Senior Third-Party Risk Manager (TPRM)

BoF Careers • Nutley (NJ)

On-site
USD 150,000 - 190,000
Senior Manager, Security, Risk, Resilience & Global Intelligence
Senior Manager, Security, Risk, Resilience & Global Intelligence

The Security Executive Council • Nutley (NJ)

On-site
USD 110,000 - 150,000
Senior Manager, Security, Risk, Resilience & Global Intelligence
Senior Manager, Security, Risk, Resilience & Global Intelligence

Ralph Lauren • Nutley (NJ)

On-site
USD 120,000 - 180,000
ERP+ PMO Operations, Contracts & Financials, Manager
ERP+ PMO Operations, Contracts & Financials, Manager

Ralph Lauren • Nutley (NJ)

On-site
USD 120,000 - 170,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE Clear Europe Limited • Northern (KY)

Hybrid
USD 90,000 - 120,000
Ralph Lauren ERP+ PMO Operations, Contracts & Financials, Manager
Ralph Lauren ERP+ PMO Operations, Contracts & Financials, Manager

Ralph Lauren • Nutley (NJ)

On-site
USD 120,000 - 180,000
Head of Third-Party Risk Management
Head of Third-Party Risk Management

Getevolved • Memphis (TN)

On-site
USD 120,000 - 180,000
Third Party Risk Officer
Third Party Risk Officer

Getevolved • Memphis (TN)

On-site
USD 120,000 - 180,000
Senior TPRM Consultant (Partner Engagements)
Senior TPRM Consultant (Partner Engagements)

Adobe • New York (NY)

On-site
USD 140,000 - 200,000
Senior Manager Vulnerability Management
Senior Manager Vulnerability Management

Ralph Lauren • Nutley (NJ)

On-site
USD 110,000 - 170,000