Cyber Risk Management Lead (TPRM)

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
103K-255K Annually
Expert/Leader
Big Data • Information Technology • Security • Software
The Role
Leads the enterprise Third-Party Risk Management program, including framework development, risk assessments, lifecycle monitoring, policy creation, GRC tool implementation, regulatory control reviews, remediation tracking, reporting, training, and cross-functional collaboration with business, legal, and procurement teams.
Summary Generated by Built In

Welcome to Aventiv! Please watch this brief video to find out if this is the place you want to be!

Aventiv Technologies – Where your future awaits - YouTube

**Associate Referral Reward Eligible**

Job Purpose: Responsible for overseeing the Third-Party Risk Management Program (TPRM) including projects and initiatives. Collaborate, Influence cross-functional partnerships across the enterprise to guide the business of third-party cyber risk management.

Essential Duties: 

  • Manage and maintain a comprehensive TPRM framework and roadmap
  • Track, and measure third-party cyber risk management roadmap with risk prioritization
  • Design, implement and maintain a consistent approach to all third-party risk to understand inherent risk, residual risk, gaps, and track mitigations
  • Identify, prioritize, and pursue opportunities to enhance TPRM processes with innovative approaches and solutions to optimize efficiency and effectiveness.
  • Assess and monitor the TPRM lifecycle activities (risk assessment & due diligent, contract negotiation, ongoing monitoring, and termination)
  • Establish relevant TPRM policy and procedures
  • Lead the implementation and continued deployment of the TPRM module within the GRC tool
  • Assess TPRM controls against regulatory requirements such as PCI, HIPAA, SOC2, NYDFS, privacy, etc. to identify gaps and ensure alignment
  • Collaborate with the business, legal, and procurement to ensure gaps identified in the TPRM areas are corrected, remediated, and monitored
  • Drive integration of the TPRM processes into the business and other risk verticals to extend the program to these and other areas
  • Provide and manage monthly reporting activity and analyzing metrics for performance TPRM program
  • Provide TPRM training, guidance, and support to all internal customers (e.g. business units, legal, procurement, etc.) and TPRM team members
  • Leverage industry-leading practices and trends to provide valuable risk insights to senior management
  • Other Duties as Assigned

Knowledge, Skills, and Abilities:

  • Deep understanding of cybersecurity risk management processes
  • SME with compliance regulations/laws, security frameworks, and standards (e.g. PCI-DSS, FISMA, NIST, HIPAA, ISO, COBIT, CCPA, HITRUST, etc.)
  • Strong project management skills and ability to manage multiple projects
  • Ability to exercise and mentor others on good professional judgment and security-related ethics
  • Strong attention to detail and highly results oriented.
  • Excellent communication skills and ability to influence and guide others.
  • Build and maintain ongoing business relationships with strong interpersonal and communication skills.
  • Other duties as assigned.

Minimum Qualifications:

  • 10+ years of direct functional knowledge and experience in Third-Party Risk management and contractual arrangements
  • HS Diploma or GED
  • Direct functional knowledge and experience in TPRM and contractual arrangements
  • Process design and process improvement experience
  • Experience in data gathering, analysis, and problem-solving skills.
  • Experience with Shared Assessments Standard Information Gathering Questionnaire (SIG) and processes.
  • Professional certification: with at least one of the following, CISM, CISA, CRISC, CTPRP, CTPRA, CDPSE 

Preferred Qualifications:

  • Bachelors' degree or equivalent work experience in a related discipline
  • Strong knowledge of various data protection legislation
  • Professional certification: CISSP with at least one of the following, CISM, CISA, CRISC, CTPRP, CTPRA, CDPSE

Physical Requirements:

  • While performing the duties of this job, the employee is regularly required to: stand, sit, talk, hear, and use hands and fingers to operate a computer, telephone, and a variety of office equipment. 
  • Occasionally, this position may need to reach, stoop, or kneel.  

    Salary and Benefits:

    At Aventiv, our salary and benefits are designed to fit you as a whole person. We offer a salary range based on experience and qualifications to ensure your unique contributions are met with our most competitive offer.

    • $102,555.53- $128,604.00 per year
    • Eligible for $255 to purchase company equipment (keyboard, monitor, headset, etc.
    • Health Insurance
    • 401(k)
    • Disability
    • Life Insurance
    • Paid Time Off
    • Voluntary Benefits

        Aventiv Privacy Policy:

        www.aventiv.com/privacy

        Equal Employment Policy:

        Aventiv is proud to be an equal opportunity employer. All decisions regarding recruiting, hiring, promotion, assignment, training, termination and other terms and conditions of employment will be made without regard to race, color, national origin, biological sex, sexual orientation, gender identity, gender expression, gender presentation, religion, age, pregnancy, disability, work-related injury, veteran status, genetic information, marital status, or any other factor that the law protects from employment discrimination. We do not discriminate based on genetic information in accordance with the Genetic Information Nondiscrimination Act.

        Equal Opportunity Employer
        This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

        Skills Required

        • 10+ years of direct functional knowledge and experience in Third-Party Risk Management and contractual arrangements
        • High school diploma or GED
        • Experience with TPRM and contractual arrangements
        • Process design and process improvement experience
        • Experience in data gathering, analysis, and problem-solving
        • Experience with the Shared Assessments Standard Information Gathering Questionnaire (SIG) and related processes
        • At least one professional certification: CISM, CISA, CRISC, CTPRP, CTPRA, or CDPSE
        • Bachelor's degree or equivalent work experience in a related discipline
        • Strong knowledge of data protection legislation
        • CISSP certification
        Am I A Good Fit?
        beta
        Get Personalized Job Insights.
        Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

        The Company
        HQ: Plano, TX
        1,001 Employees

        What We Do

        Aventiv Technologies is a diversified technology company that provides innovative solutions to customers in the corrections and government services sectors. Aventiv is the parent company to Securus Technologies and AllPaid, leading providers of innovative products and services. The collective power of these unified organizations deliver superior value and service to all of our customers nationwide. We believe society improves when modern standards of simplicity are integrated with the highest demands of security. That’s why we apply technology solutions to make complex connections more secure and more convenient than ever before. Whether in communications, media and entertainment, payments, or monitoring, we help transform the industries we serve and impact the lives they touch each day. We lead with technology to solve problems in revolutionary ways and are dedicated to making the complex simple by fusing integrated products with unparalleled service. With our legacy in superior security, we ensure safety and reliability at every touchpoint, and earn trust one connection at a time. Relentlessly improving, we optimize our data-driven solutions to improve outcomes for all of our customers, helping people and technology work better together.

        Similar Jobs

        Globe Life Logo Globe Life

        Customer Retention Trainer (Remote)

        Insurance • Financial Services
        Remote
        USA
        3000 Employees

        Globe Life Logo Globe Life

        Commission Analyst (Remote)

        Insurance • Financial Services
        Remote
        TX, USA
        3000 Employees

        Arcadia Logo Arcadia

        Principal Talent Acquisition Manager (Technical Recruiting)

        Big Data • Fitness • Healthtech • Information Technology • Software • Analytics
        Remote
        USA
        360 Employees

        SambaSafety Logo SambaSafety

        Director, Customer Success

        Insurance • Logistics • Software • Transportation • Business Intelligence
        Remote or Hybrid
        United States
        300 Employees
        120K-150K Annually

        Similar Companies Hiring

        Onshore Thumbnail
        Artificial Intelligence • Fintech • Software • Financial Services
        New York, New York
        60 Employees
        Revel Thumbnail
        Aerospace • Hardware • Robotics • Software
        Marina Del Rey, California
        60 Employees
        Blee Thumbnail
        Artificial Intelligence • Marketing Tech • Software
        New York, New York
        30 Employees

        Sign up now Access later

        Create Free Account

        Please log in or sign up to report this job.

        Create Free Account