Senior Third-Party Risk & Security Leader

Gong.io

San Francisco (CA)

On-site

USD 117,000 - 185,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
401(k) program
Education stipend
Flexible vacation time
Paid parental leave
Company-wide recharge days
Work from home stipend

Job summary

Gong is seeking an experienced Third Party Risk Manager to lead our Governance, Risk, and Compliance efforts. You will own the third-party risk program, ensuring vendors meet security, privacy, and compliance standards, and you will collaborate with Procurement, Legal, and Security.

The role reports to the Head of GRC and builds scalable processes aligned with SOC 2, ISO 27001, and GDPR. You will monitor risk, communicate findings, and drive continuous improvement across the vendor lifecycle.

Qualifications

  • 7 years of experience in third-party/vendor risk management, GRC, information security, or a related field.
  • Ability to establish baselines and controls and take a risk-based approach to vendor reviews.
  • Strong working knowledge of security and compliance frameworks (SOC 2, ISO 27001, NIST) and data privacy regulations.
  • Experience conducting vendor risk assessments and interpreting security documentation (e.g., SOC 2 reports, pen test results, questionnaires).

Responsibilities

  • Own the end-to-end third-party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.
  • Establish baselines and controls that Gong can implement to reduce and manage third-party risk across the vendor portfolio.
  • Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality.
  • Build a robust and scalable TPRM program that adapts to evolving business needs and supports Gong’s growth.
  • Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements.
  • Partner with Procurement and Legal to embed risk requirements into contracts, data processing agreements, and vendor onboarding workflows.
  • Maintain and enhance the TPRM framework, policies, standards, and procedures in alignment with frameworks such as SOC 2, ISO 27001, and relevant privacy regulations (e.g., GDPR, CCPA).
  • Manage continuous monitoring of the vendor portfolio, including periodic reassessments, tiering, and tracking of remediation items.
  • Administer and optimize TPRM tooling and automation to scale the program.
  • Report on third-party risk posture, key metrics, and trends to GRC leadership and relevant stakeholders.
  • Support audit and customer assurance activities related to third-party risk.
  • Experience handling security agreements between vendors – and holding vendors accountable to such agreements.

Skills

Vendor risk management
Cross-functional collaboration
Risk-based approach
Security & privacy knowledge
Communication skills
TPRM tooling

Education

Security certifications (CTPRP, CISA, CISSP, CRISC)

Tools

Zip

Job description

Gong is seeking an experienced Third Party Risk Manager to lead our Governance, Risk, and Compliance efforts. You will own the third-party risk program, ensuring vendors meet security, privacy, and compliance standards, and you will collaborate with Procurement, Legal, and Security.

The role reports to the Head of GRC and builds scalable processes aligned with SOC 2, ISO 27001, and GDPR. You will monitor risk, communicate findings, and drive continuous improvement across the vendor lifecycle.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Third-Party Risk & Security Lead
Senior Third-Party Risk & Security Lead

Gong • San Francisco (CA)

On-site
USD 128,000 - 174,000
Medical/Dental/Vision plans
Wellbeing stipend
Mental Health benefits
+6
Senior Third-Party Risk & Security Lead — Remote
Senior Third-Party Risk & Security Lead — Remote

Gong • Austin (CO)

On-site
USD 117,000 - 185,000
Medical, dental, and vision plans
Wellbeing fund
Mental health benefits
+6
Senior TPRM & Security Leader — Remote
Senior TPRM & Security Leader — Remote

Gong • Salt Lake City (UT)

On-site
USD 117,000 - 185,000
Health plans (medical, dental, vision)
Wellbeing stipend
Mental health benefits
+6
Strategic TPRM & Security Lead
Strategic TPRM & Security Lead

Gong • New York (NY)

On-site
USD 117,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
+6
Senior TPRM & Security Lead
Senior TPRM & Security Lead

Gong • Chicago (IL)

On-site
USD 117,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
+6
Senior GRC & Security Lead — Policy, Risk & Compliance
Senior GRC & Security Lead — Policy, Risk & Compliance

Gong • San Francisco (CA)

On-site
USD 121,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
401(k) program
+2
Senior GRC & Security Lead — Policy, Risk & Compliance
Senior GRC & Security Lead — Policy, Risk & Compliance

Gong • Austin (CO)

Hybrid
USD 121,000 - 185,000
Medical, dental, and vision plans
Flexible wellness stipend
401(k) program
+2
Senior TPRM Security Lead
Senior TPRM Security Lead

Gong • Chicago (IL)

On-site
USD 117,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
+6
Senior TPRM Security Lead
Senior TPRM Security Lead

Gong • New York (NY)

On-site
USD 117,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
+6
Senior TPRM Security Lead
Senior TPRM Security Lead

Gong • Salt Lake City (UT)

On-site
USD 117,000 - 185,000
Health plans (medical, dental, vision)
Wellbeing stipend
Mental health benefits
+6