Cybersecurity TPRM Strategy and Governance SME

Posted 5 Hours Ago
Be an Early Applicant
2 Locations
In-Office or Remote
Senior level
Artificial Intelligence • Cloud • Information Technology • Consulting
The Role
Leads the enterprise third-party cybersecurity risk management strategy, operating model, governance framework, and risk methodologies. Establishes vendor risk and due diligence processes, improves TPRM scalability through automation and technology, defines metrics and executive reporting, and partners with business, legal, procurement, compliance, privacy, IT, and supply chain teams. Provides expertise on regulatory requirements, supply chain security, cloud, AI-related risks, operational resilience, and cybersecurity frameworks while mentoring junior staff.
Summary Generated by Built In
Cybersecurity TPRM Strategy and Governance SME

  

This role has been designed as 'Hybrid' with a requirement that you will work on average 2 days per week from an HPE office.

Who We Are:

Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.

Job Description:

   

Job Descritption

The Cybersecurity TPRM Strategy & Governance SME is responsible for defining and advancing the organization's third-party cybersecurity risk management strategy, operating model, and governance framework. This role drives program maturity, efficiency, and scalability by establishing risk-based processes, standards, methodologies, and technology-enabled solutions that support effective management of cybersecurity risks throughout the third-party lifecycle.


Responsibilities:

  • Develop and maintain the enterprise CybersecurityThird-Party Risk Management (TPRM) strategy, and operating model.
  • Define and continuously improve third party risk-based frameworks, methodologies, standards, and procedures for managing third-party cybersecurity risk.
  • Lead the evolution of vendor criticality, inherent risk, residual risk, and due diligence frameworks.
  • Identify opportunities to streamline, automate, and optimize TPRM processes to improve scalability, efficiency, and user experience.
  • Partner with Procurement, Legal, Compliance, Privacy, Supply Chain, IT, and business stakeholders to align TPRM processes with business objectives and regulatory requirements.
  • Establish metrics, KPIs, and reporting frameworks to measure program effectiveness, risk exposure, and operational performance.
  • Provide thought leadership on emerging risks, including supply chain security, software supply chain risk, cloud providers, AI-related risks, and operational resilience.
  • Lead assessments of TPRM tools and technology solutions and drive automation and workflow improvements.
  • Develop executive-level reporting and presentations to communicate program maturity, risks, and strategic initiatives.
  • Support enterprise-wide initiatives related to regulatory compliance, cybersecurity governance, and operational resilience.
  • Provides guidance and mentoring to less- experienced staff members.

Education and Experience Required:

  • Bachelor's or Master's degree in Engineering, Computer Science, Information Security or equivalent.
  • Typically 6-10 years experience.
  • Security Certifications: preferred - CISSP ( other CRISC,CISM,etc)

Knowledge and Skills:

  • Demonstrated experience and in-depth knowledge in designing or managing TPRM programs, frameworks, and governance models.
  • Solid knowledge and demonstrated experience of Cyber and IT security risks, threats and prevention measures.
  • Strong knowledge of cybersecurity and risk management frameworks such as NIST CSF, NIST 800-53, ISO 27001, and industry best practices.
  • Knowledge and experience of security fundamentals and technologies.
  • Experience translating regulatory and security requirements into scalable policies, standards, and operational processes.
  • Experience leading strategic initiatives, process transformation, and organizational change.
  • Industry certifications such as CISSP, CISM, CRISC, CISA, or equivalent.
  • Experience implementing or optimizing TPRM or GRC platforms (OneTrust, Archer, ServiceNow, etc.).
  • Knowledge of global regulatory requirements, including DORA, NIS2, GDPR, SEC Cybersecurity Rules, and supply chain cybersecurity regulations.
  • ​Strong analytical, communication, stakeholder management, and executive presentation skills.
  • Excellent written and verbal communication skills; mastery in English.

Accessibility


HPE is committed to creating an inclusive and accessible workplace and encourages applications from all qualified individuals, including those with disabilities. If you believe you require accommodation during any stage of the application or interview process, please submit your request by completing our secure form linked here.


Note: This option is reserved for applicants needing assistance/reasonable accommodation related to a disability.

What We Can Offer You:

Health & Wellbeing

We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.

Personal & Professional Development

We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.

Unconditional Inclusion

We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.

Let's Stay Connected:

Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.

Job:

Engineering

Job Level:

TCP_04

    

    

HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.

Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.

   

HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.

   

Recruitment Fraud Alert

We have become aware of an increase in fraudulent recruitment activities in which individuals impersonate our company or authorized recruitment agencies to offer fake employment opportunities. These scams may occur through false websites, emails, social media, or chat-based applications and often aim to obtain personal information or money. Please note that Hewlett Packard Enterprise (HPE), its direct and indirect subsidiaries and affiliated companies, and its authorized recruitment agencies/vendors will never charge a candidate a registration fee, hiring fee, or any other fee in connection with its recruitment and hiring process. We also never request personal information such as back account details, Social Security numbers, or national IDs via social media or chat applications.

All legitimate job opportunities will come through official company channels, and candidates are responsible for verifying the credentials of any third party claiming to represent the company. Any reliance on fraudulent communication is at the individual’s own risk, and HPE disclaims legal liability for any resulting damages. If you suspect recruitment fraud, do not share personal information or make any payments and report the incident to your local authorities immediately.

Skills Required

  • Bachelor’s or master’s degree in engineering, computer science, information security, or equivalent
  • Typically 6–10 years of experience
  • Experience designing or managing third-party risk management programs, frameworks, and governance models
  • Knowledge and experience with cybersecurity and IT security risks, threats, and prevention measures
  • Knowledge of NIST CSF, NIST 800-53, ISO 27001, and industry cybersecurity best practices
  • Experience translating regulatory and security requirements into policies, standards, and operational processes
  • Experience leading strategic initiatives, process transformation, and organizational change
  • Experience implementing or optimizing TPRM or GRC platforms such as OneTrust, Archer, or ServiceNow
  • Knowledge of global regulatory requirements including DORA, NIS2, GDPR, SEC Cybersecurity Rules, and supply chain cybersecurity regulations
  • Strong analytical, communication, stakeholder management, and executive presentation skills
  • Excellent written and verbal English communication skills
  • CISSP certification
  • CISM, CRISC, CISA, or equivalent certification

Hewlett Packard Enterprise Compensation & Benefits Highlights

  • Parental & Family Support Parental leave is frequently highlighted as a standout, with extended fully paid time off and transition support for new parents. Additional offerings like backup childcare and family-care programs strengthen the family-friendly profile.
  • Retirement Support Retirement programs, including employer-supported 401(k) matching, are consistently cited as solid components of the package. Feedback suggests these offerings contribute meaningful long-term financial support.
  • Wellbeing & Lifestyle Benefits Work-life and wellness features such as Wellness Fridays, flexible/hybrid work, and volunteer time off are commonly emphasized. Feedback suggests these elements enhance balance and day-to-day experience.

Hewlett Packard Enterprise Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Houston, TX
85,422 Employees
Year Founded: 2015

What We Do

In 1939, Bill Hewlett and Dave Packard, college friends turned business partners, started the original Silicon Valley startup in the space of a rented Palo Alto garage. Starting with audio oscillators, the friends built the foundation for a company that would grow to become a global leader in enterprise technology. More than 75 years later, our success is exemplified through our employees’ drive to advance ideas that bring meaningful innovations to life for our customers and partners around the globe. We are guided by our mission to help customers use technology to turn ideas into value, and empower them to transform industries, markets and lives. We simplify Hybrid IT, power the Intelligent Edge and provide the expertise to make it all happen.

Hewlett Packard Enterprise Offices

OnSite Workspace

Typical time on-site: None
HQHouston, TX
Heredia
SG
Alpharetta, US
Bangalore, Bangalore
Bengaluru, IN
Berkshire, GB
Durham, US
Fort Collins, US
Frisco, US
Galway, IE
Guadalajara, MX
Gurugram, Haryana
Kolkata, West Bengal
London, GB
Madrid, ES
New York, US
Puteaux, FR
Reading, GB
Riyadh, SA
Roseville, US
San Jose, US
Singapore, SG
Spring, US
Tokyo, JP
Learn more

Similar Jobs

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Software Engineer

Artificial Intelligence • Cloud • Information Technology • Consulting
Remote or Hybrid
2 Locations
85422 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Factory Express Engineering / Engagement Project Management

Artificial Intelligence • Cloud • Information Technology • Consulting
Remote
Aguadilla, PRI
85422 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

GLO Customs & Compliance Specialist

Artificial Intelligence • Cloud • Information Technology • Consulting
Remote
Aguadilla, PRI
85422 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

GLO Customs & Compliance Specialist

Artificial Intelligence • Cloud • Information Technology • Consulting
Remote
Aguadilla, PRI
85422 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account