Senior TPRM - GRC Consultant

Yoh Services LLC

McKinney (TX)

On-site

USD 69,000 - 90,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Yoh Services LLC is seeking a Senior TPRM and GRC Consultant to lead the third-party risk program in a hybrid role based in Plano or McKinney, TX. Immediate start with 2-3 days onsite.

The ideal candidate will manage the full TPRM lifecycle, conduct due diligence and risk assessments, and partner with Legal, Procurement, and Information Security to strengthen controls. Experience with AuditBoard or RSA Archer is preferred; strong communication skills are essential for senior leadership reporting

Qualifications

  • Five+ years in IT security, cyber risk, or GRC focusing on third-party risk management.
  • Experience managing vendor onboarding, due diligence, risk assessments, remediation tracking, and offboarding.
  • Knowledge of NIST, ISO 27001, SOC 2, PCI DSS, HIPAA, and CCPA.
  • Hands-on with AuditBoard or RSA Archer or similar GRC platforms.
  • Experience collaborating with Procurement, Legal, Compliance, Information Security, and business stakeholders.
  • Strong analytical, documentation, reporting, and stakeholder-management abilities.
  • Ability to work onsite Wednesday–Friday.

Responsibilities

  • Lead end-to-end TPRM lifecycle for new and existing vendors.
  • Conduct vendor due diligence, security risk assessments, and control reviews.
  • Evaluate vendor compliance with security requirements and regulatory standards.
  • Identify gaps, document findings, and track remediation to completion.
  • Develop and improve TPRM policies, procedures, and workflows.
  • Collaborate with Procurement, Legal, and IT Security to embed security in contracting.
  • Maintain AuditBoard or RSA Archer for assessments and reporting.
  • Monitor risk metrics and remediation progress for leadership.

Skills

Vendor Risk Mgmt
Stakeholder Mgmt
Analytical Skills

Education

None

Tools

AuditBoard
RSA Archer

Job description

Senior TPRM and GRC Consultant
Third-Party Risk Management Specialist

Work Arrangement: Hybrid, 2-3 days onsite

Location: Plano Texas or McKinney Texas

Start Date: Immediate

POSITION SUMMARY

IT Third-Party Risk Management professional to lead and strengthen the TPRM program within the Governance, Risk, and Compliance function.

  • This position manages the complete third-party risk lifecycle, including vendor onboarding, due diligence, risk assessments, periodic reviews, remediation tracking, ongoing monitoring, and offboarding.
  • The ideal candidate has extensive experience evaluating technology vendors, identifying security and compliance risks, improving TPRM processes, and working independently with business and technical stakeholders.
  • Hands-on AuditBoard experience is strongly preferred, although candidates with strong RSA Archer experience will also be considered.
RESPONSIBILITIES
  • Lead the end-to-end third-party risk management lifecycle for new and existing vendors.
  • Conduct vendor due diligence, security risk assessments, control reviews, and periodic reassessments.
  • Evaluate vendor compliance with organizational security requirements and regulatory and industry standards.
  • Identify control gaps, document risk findings, recommend corrective actions, and track remediation through completion.
  • Develop, maintain, and improve TPRM policies, procedures, assessment methodologies, workflows, and supporting documentation.
  • Partner with Procurement, Legal, Information Security, Compliance, and business teams to incorporate security requirements into vendor selection and contracting.
  • Maintain and optimize AuditBoard or RSA Archer for vendor assessments, workflow management, documentation, issue tracking, and reporting.
  • Monitor third-party risk metrics, emerging trends, remediation progress, and overall compliance posture.
  • Prepare risk reports, dashboards, and program updates for senior leadership.
  • Support internal and external audits involving third-party risk, cybersecurity governance, and regulatory compliance.
  • Stay current with emerging cybersecurity threats, regulatory changes, and third-party risk management best practices.
REQUIRED QUALIFICATIONS
  • Minimum of five years of direct Third-Party Risk Management experience within an IT Security, Cybersecurity, Risk Management, or GRC function.
  • Demonstrated experience managing vendor onboarding, due diligence, risk assessments, control-gap identification, remediation tracking, periodic reviews, and offboarding.
  • Strong knowledge of cybersecurity frameworks, control standards, and regulatory requirements, including NIST, ISO 27001, SOC 2, PCI DSS, HIPAA, and CCPA.
  • Hands-on experience with AuditBoard, RSA Archer, or a comparable GRC platform.
  • Experience partnering with Procurement, Legal, Compliance, Information Security, and business stakeholders.
  • Strong analytical, documentation, reporting, communication, and stakeholder-management skills.
  • Ability to work independently, manage competing priorities, and deliver results in a fast-paced environment.
  • Ability to work onsite Wednesday through Friday.
PREFERRED QUALIFICATIONS
  • Hands-on experience configuring or optimizing AuditBoard TPRM workflows.
  • Experience developing, implementing, or maturing an enterprise Third-Party Risk Management program.
  • Experience creating executive-level risk reports, dashboards, and metrics.
  • CTPRP, CISA, CISSP, CRISC, or another relevant risk or cybersecurity certification.

Estimated Min Rate: $50.00

Estimated Max Rate: $65.00

What’s In It for You?

We welcome you to be a part of the largest and legendary global staffing companies to meet your career aspirations. Yoh’s network of client companies has been employing professionals like you for over 65 years in the U.S., UK and Canada. Join Yoh’s extensive talent community that will provide you with access to Yoh’s vast network of opportunities and gain access to this exclusive opportunity available to you. Benefit eligibility is in accordance with applicable laws and client requirements.

Benefits include:

  • Medical, Prescription, Dental & Vision Benefits (for employees working 20+ hours per week)
  • Health Savings Account (HSA) (for employees working 20+ hours per week)
  • Life & Disability Insurance (for employees working 20+ hours per week)
  • MetLife Voluntary Benefits
  • Employee Assistance Program (EAP)
  • 401K Retirement Savings Plan
  • Direct Deposit & weekly epayroll
  • Referral Bonus Programs
  • Certification and training opportunities

Note: Any pay ranges displayed are estimations. Actual pay is determined by an applicant's experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply.

Yoh, a Day & Zimmermann company, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Visit https://www.yoh.com/applicants-with-disabilities to contact us if you are an individual with a disability and require accommodation in the application process.

For California applicants, qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. All of the material job duties described in this posting are job duties for which a criminal history may have a direct, adverse, and negative relationship potentially resulting in the withdrawal of a conditional offer of employment.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

By applying and submitting your resume, you authorize Yoh to review and reformat your resume to meet Yoh’s hiring clients’ preferences. To learn more about Yoh’s privacy practices, please see our Candidate Privacy Notice: https://www.yoh.com/privacy-notice

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vendor Risk Management
Vendor Risk Management

Synergis • Atlanta (GA)

Hybrid
Senior TPRM & GRC Lead — Vendor Risk & Compliance
Senior TPRM & GRC Lead — Vendor Risk & Compliance

Yoh Services LLC • McKinney (TX)

Hybrid
USD 69,000 - 90,000
IT Security Manager - Third-Party IT Risk Manager
IT Security Manager - Third-Party IT Risk Manager

Mass Digital Health • Waltham (MA)

On-site
USD 118,000 - 207,000
Senior GRC Analyst
Senior GRC Analyst

Gilder Search Group • Atlanta (GA)

On-site
USD 90,000 - 120,000
Discretionary Annual Bonus
Comprehensive Benefits Package
401k and PTO
Senior GRC Analyst
Senior GRC Analyst

Gilder Search Group • St. Louis (MO)

On-site
USD 80,000 - 100,000
Discretionary Annual Bonus
Comprehensive Benefits Package
Generous PTO and paid company holidays
Advisor – Third-Party Risk Management (TPRM)
Advisor – Third-Party Risk Management (TPRM)

CGS CyberDefense • West Palm Beach (FL)

On-site
USD 90,000 - 120,000
Access to cutting-edge cybersecurity tools
Ongoing professional development
A culture that values curiosity and innovation
Senior GRC Analyst
Senior GRC Analyst

Gilder Search Group • Phoenix (AZ)

On-site
USD 80,000 - 120,000
Comprehensive Benefits Package
Discretionary Annual Bonus
Flexible Spending Accounts
Business Analyst III - Hybrid in PA or Remote
Business Analyst III - Hybrid in PA or Remote

Yoh, A Day & Zimmermann Company • Audubon Township (IA)

Hybrid
Medical, Prescription, Dental & Vision Benefits
Health Savings Account (HSA)
Life & Disability Insurance
+2
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE Clear Europe Limited • Northern (KY)

Hybrid
USD 90,000 - 120,000
Technical Program Manager – Data Center PDI Program and Product Portfolio
Technical Program Manager – Data Center PDI Program and Product Portfolio

Yoh, A Day & Zimmermann Company • Atlanta (GA)

On-site
Medical, Prescription, Dental & Vision Benefits
Health Savings Account (HSA)
Life & Disability Insurance
+3