We are seeking an experienced Third-Party Risk Management (TPRM) Manager to lead and evolve our enterprise TPRM program. This role will drive TPRM strategy, operations, reporting, supplier incident management, M&A risk integration, and governance initiatives while ensuring effective execution of OneTrust assessments and BitSight operations. The ideal candidate will leverage automation, AI-enabled solutions, and innovative approaches to enhance efficiency, risk visibility, and decision-making. Strong leadership, stakeholder management, team development, and hiring experience are essential to build a high-performing TPRM function and deliver measurable business outcomes.
· Lead and evolve the EMEA Third-Party Risk Management (TPRM) program, aligning strategy with regulatory, business, M&A, and InfoSec Supply Chain Risk Management objectives.
· Oversee end-to-end TPRM operations, including due diligence, risk assessments, reassessments, exception management, SLA performance, and operational scalability.
· Develop and deliver executive, regulatory, and operational reporting, providing actionable risk insights and ensuring data accuracy and traceability.
· Lead TPRM integration for M&A activities, including acquisition due diligence, supplier risk assessments, onboarding into TPRM frameworks, and Day-0/30/90 integration objectives.
· Own the supplier security incident management framework, coordinating breach response, impact assessments, remediation, and executive reporting.
· Drive AI, automation, and innovation initiatives to improve efficiency, decision-making, risk visibility, and operational effectiveness across TPRM processes.
· Own and optimize OneTrust TPRM workflows, assessments, questionnaires, control mappings, and platform integrations.
· Govern continuous supplier monitoring through BitSight and similar tools, driving risk-based supplier engagement, remediation, and executive reporting.
· Define, track, and continuously improve TPRM KPIs, KRIs, maturity metrics, and performance reporting.
· Build and lead a high-performing TPRM organization through hiring, workforce planning, mentoring, coaching, succession planning, and stakeholder engagement.
Required Qualifications
· 10+ years of experience in Third-Party Risk Management (TPRM), Supply Chain Risk Management, Information Security Risk, Governance, Risk & Compliance (GRC), or related cybersecurity functions.
· Demonstrated experience leading enterprise-scale TPRM programs, operations, and governance frameworks across multiple regions and business units.
· Strong expertise in supplier risk assessments, due diligence, risk reporting, incident management, and regulatory compliance requirements.
· Hands-on experience with OneTrust TPRM, third-party risk assessment methodologies, workflow configuration, and process optimization.
· Experience with continuous monitoring platforms such as BitSight and integrating security posture insights into risk management decisions.
· Proven leadership experience managing teams, driving organizational change, resolving complex stakeholder issues, and influencing executive-level decisions.
· Familiarity with AI tools, workflow automation platforms, and integrating AI into existing systems is preferred.
Preferred Qualifications
· Experience developing automation using Copilot or other Agentic AI frameworks
· Experience leading TPRM activities during mergers, acquisitions, divestitures, and integration programs.
· Knowledge of emerging risks including AI, cloud security, geopolitical risk, privacy, and evolving regulatory requirements.
· Experience implementing automation, AI-driven workflows, analytics, and operational transformation initiatives within TPRM or cybersecurity programs.
· Familiarity with enterprise risk frameworks and standards such as ISO 27001, NIST, SOC 2, PCI DSS, and privacy regulations.
· Experience collaborating with Procurement, Legal, Privacy, Internal Audit, and Enterprise Risk Management teams.
· Strong executive communication skills with a proven ability to present complex risk concepts to senior leadership, boards, and auditors.
Soft Skills
· Strong analytical and problem-solving skills with the ability to manage multiple priorities in a fast-paced environment.
· Experience working within multinational environments with complex IT asset landscapes.
· Attention to detail and accuracy.
· Strong problem-solving and analytical abilities.
· Ability to translate compliance requirements into technical controls.
· Commitment to continuous improvement and maturity enablement of the program.
Software Powered by ICIMS
www.icims.com