Director of AI-Driven Third-Party Cyber Risk
Habitat For Humanity Of Durham
Language Fluency: English (Required) Work Shift: 1st shift (United States of America) Job Grade: 114 Please review the following job description: Truist is seeking a senior leader to transform, modernize, and operate the Cybersecurity Third-Party Risk Management (CTPRM) function within Truist Protection Services (TPS). Reporting to the Head of Security Governance, this role will redefine how cyber third-party risk is identified, assessed, and continuously monitored—leveraging agentic AI, automation, and advanced analytics to scale decision-making across Truist’s ecosystem. This leader will drive the evolution from traditional, manual assessment models to intelligent, adaptive, and technology-driven risk management capabilities. The role partners closely with the Enterprise Third Party Risk Operations Function (TPROF), second line Risk, Business Information Security Officers (BISOs), Sourcing, Legal, and Technology teams to strengthen Truist’s cyber supply chain posture at scale. The ideal candidate has led CTPRM teams in a large, regulated environment, can translate technical risk into clear business decisions, and can drive measurable program outcomes at scale. What success looks like
- A modern, intelligence-driven CTPRM Function leveraging agentic AI and automation to reduce manual effort, accelerate assessments, and enable near real-time risk visibility across the third-party ecosystem.
- Measurable improvements in assessment cycle time, signal quality, and automation coverage through the adoption of AI-driven workflows and decision support.
- Executive-ready reporting that highlights top cyber risks, trends, and prioritized remediation actions across critical suppliers and services.
- Strong partnerships across first, second, and third lines of defense and positive outcomes in regulatory and audit engagements. ESSENTIAL DUTIES AND RESPONSIBILITIES
- Architect and lead the transformation of the Cyber Third-Party Risk Management (CTPRM) operating model, embedding agentic AI, automation, and intelligent workflows to significantly improve scalability, speed, and risk insight.
- Drive a culture of automation and innovation—challenging legacy processes, reducing manual effort, and continuously identifying opportunities to apply AI and emerging technologies to improve program effectiveness.
- Own the cyber contract deviation (exception) governance process—including intake, risk analysis, decision support, approvals, documentation, and ongoing monitoring/expiration, in partnership with Legal.
- Build, lead, and continuously improve the third-party cybersecurity assessment activities(methodology, scoping, testing/evidence standards, quality assurance) and drive timely remediation of identified Third Party Sub-Issues and risks.
- Leverage agentic AI, technology, data, third-party intelligence, and strategic partners to scale assessment throughput, improve risk signal quality, and increase automation where appropriate.
- Partner with BISOs and business leaders to integrate cyber third-party risk into business decisions, onboarding, change management, and ongoing Third Party performance/risk reviews.
- Hire, develop, and retain a high-performing team of cybersecurity and third-party cybersecurity risk professionals; set clear goals, coaching, and a strong culture of accountability and collaboration.
- Partner with second line Risk to align oversight expectations, strengthen issue management, and reduce Truist’s exposure to cyber supply chain and concentration risk.
- Establish strong cross-functional working relationships and alignment across TPS, Enterprise TPROF, Technology, Procurement, Legal, and business stakeholders, embodying a “we deliver together” culture.
- Support regulatory exams and internal audit engagements related to information security and third-party cybersecurity risk; ensure timely, accurate responses, sustainable remediation, and strong control evidence.
QUALIFICATIONS
Required Qualifications: The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.- BS IT/ Computer Science / Cyber Security, MIS, Economics, Finance, Operations Management, or a related discipline. MBA or related graduate degree a plus.
- 15+ years professional experience in top 10 USA banks or other financial institution, consulting firm, and/ or software company, preferably within a merger/acquisition environment with significant transformational change with people, process, and technology.
- 10+ years information security and third-party security threat and risk assessment and management experience, including using industry frameworks such as ITIL, COBIT, NIST CSF, CIS RAM, MITRE.
- 2+ years’ experience with digital banking deployed on public cloud platforms and (strong plus) leveraging artificial intelligence technologies.
- Broad knowledge of Information Security frameworks (e.g., NIST, FFIEC), regulations (SOX, GLBA, NYDFS), functions (Anticipate, Protect, Detect, Respond) and information security controls.
- Expertise working across IT and business functions and with second and third lines of defense, and regulators.
- Demonstrates strong relationship management skills. Proven ability to quickly build trust and rapport with others in order to structure problems, build consensus, and negotiate agreement.
- Proven ability to manage large, deadline-driven projects in a way that reduces risk, ensures predictable results, meets or exceeds its timeline.
- Thrives in a fast-paced environment, can think and act both tactically and strategically.
- Exhibits high degree of creativity, self-motivation, and commitment to task.
- Ability to create a strong network of relationships among peers, internal partners, external constituencies, and decision makers to deliver end products.
- Experience preparing materials for and comfortable presenting to executive management.
- Excellent written and oral communication skills.
- Strong coordination, influencing and negotiation skills.
- Excellent risk-based judgement and decision making
- Passionate about building world-class Information Security programs.
- ...Position Summary The Sr. Manager of Cybersecurity Third-Party Risk Management leads the enterprise program responsible for identifying... ...party services, provide executive visibility into third-party cyber risk exposure, remediation status, systemic supplier risk,...CyberRiskContract workFor contractorsFor subcontractorWork at officeLocal areaWork from home
$76.4k - $138.6k
...Within Information Security we blend risk strategy, digital identity, cyber defense, application security and... ...in the assessment and validation of third-party risk assessments and ensuring that EY... ...capital markets. Enabled by data, AI and advanced technology, EY teams...CyberRiskSummer holidayLocal areaFlexible hours$126k - $242k
...innovative, and hands-on AI Security leader to join Verizon's Cyber AI Services (CAIS) organization... ...and lead our Governance, Risk and Compliance (GRC) team... .... The Associate Director will lead the... ...Experience working on third party risk assessments. Demonstrated...CyberRiskFull timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week- Director of Technical Account Management, Customer Success Leading DLP AI Cybersecurity Provider | Remote (US) | Full-Time The Mission You’re the cybersecurity co-pilot... ...policy, you’re the one translating real-world cyber risk into product reality . Their cybersecurity...CyberRiskFull timeRemote workWork from homeSleeping nightsFlexible hoursNight shift
$135.4k - $208.1k
...infrastructure at Cardinal Health. The Director, Cyber Detection & Response is responsible... ...capabilities, and ensuring alignment with risk and resilience objectives. Location... ...with advanced analytics, automation, and AI-driven security operations, a strong...CyberRiskTemporary workLocal areaImmediate startRemote workFlexible hours- ...modern data platforms, and the AI systems that depend on them. TAMs... ...capabilities into reduced risk, controlled access, and safe AI... ...protected from insider threats, cyber-attacks, and policy violations... ...documented and assessed by appropriate parties Engage with customers at...CyberRiskRemote work
- ...a Senior Associate or Director, you will assist senior... ...project among interested parties including investors,... ...estate investment manager, driven by our by our belief... ...knowledge, taking calculated risks aligned with our... ...No calls or emails from third parties at this time please...RiskWork experience placementWork at officeLocal area
- ...important industries. Our growth is driven by delivering real results for our... ...is currently seeking an Associate Director, Presales Solution Architect - Cyber to join our KPMG Delivery Network organization... ...member firms and Global/Regional Risk leadership Act with integrity,...CyberRiskH1bLocal area
- ...VulnOps. This role sits at the intersection of security risk, automation, and emerging AI‑driven capabilities. If you’re a cybersecurity professional... ...functional environment to protect Vanguard and its clients from cyber security threats. Core Responsibilities (In This Role...CyberRiskWork experience placement
- ...applications, and service teams to align AI enablement with operational standards Translate... ...within a regulated or compliance‑driven environment (pharmaceutical, biotech, life... ...including data protection, privacy, security, and risk management Ability to analyze user...RiskLocal area
- ...Third-Party Risk Management Analyst II If you are motivated and believe in the credit union philosophy of "People Helping People," join our team! Position Overview: The Third-Party Risk Management (TPRM) program provides strategic direction for TPRM governance...Risk2 days per week
- ...combining creativity, technology, and data-driven intelligence. Within Song, the Customer... ...customer data, marketing technology, and AI-powered decisioning to transform how brands... ...Ensure secure deployment aligned to enterprise risk and compliance policies. Cloud &...RiskLive inWork at officeLocal area
- ...our vision of a safe and secure cyber world. Our globally recognized... ...most vulnerable about cyber risks and empowering access to enter... ...Salesforce Premier Support and third-party system integrators.... ...skills. Experience working with AI tools or a demonstrated willingness...CyberRiskWork experience placementWork at officeRemote work
- ...timeposted on: Posted Todayjob requisition id: JR101184Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity...CyberRiskRemote work
$170k - $225k
Job Title : AI Engineering Transformation Director Corporate Title : Director Location : Cary, NC In short -... ...areas. Our Technologists drive Cloud, Cyber and business technology strategy... ...engineering change to business outcomes, risk posture, and cost efficiency. It...CyberRiskWork at officeWork from homeShift work$128.1k - $239.6k
...Information Security we blend risk strategy, digital identity, cyber defense, application... ...Opportunity As an Assistant Director in the Information... ...infrastructure, applications, and third-party dependencies. Improve... .... Enabled by data, AI and advanced technology,...CyberRiskWork experience placementSummer holidayLocal areaFlexible hours- ...Job Title: AI-Native Technical Program Manager Location:... ...in the Role: Supporting org director distill down most important action... ...on timelines, status, and risks AI-native expectations:... ...Build and maintain lightweight AI-driven workflows for recurring rituals...RiskFlexible hours
- ...product portfolio's progress and escalates risks to all stakeholders through executive... ...shape and lead delivery Capacity to develop AI‑driven processes to improve ways of working... ...Preferred Qualifications Experience in Cyber Security and working with Financial Services...CyberRisk
$135.4k - $208.1k
...infrastructure at Cardinal Health. The Director, Exposure Management is responsible for... ...identify, prioritize, and reduce cybersecurity risk across network, cloud, endpoint, and data... ...management initiatives with broader cyber defense and risk reduction strategies....CyberRiskTemporary workLocal areaImmediate startRemote workFlexible hours- ...delivers real business value with AI. What You’ll Do Teradata... ...to join our global Enterprise Risk and Assurance Services (ERAS)... ...in complex, cloud‑based, data‑driven environments. The IT Senior Auditor... ...Technology, Information/Cyber Security, or a related business...CyberRiskPermanent employmentRemote workFlexible hours
$109.2k - $223.4k
...Job Description The Director for Global Defense - Japan is responsible for leading... ...solutions (e.g., cloud, data platforms, AI/analytics, cyber). Ensure proposals and delivery... ...influencing, and cross-cultural leadership Risk management and operational excellence...CyberRiskContract workTemporary workFor contractorsLocal areaFlexible hours- ...Our end‑to‑end platform blends AI-powered capabilities and... ...challenges into clear, value‑driven solutions. What You’ll Do Product... ...cyberthreats with an end‑to‑end cyber resilience platform to manage,... ...capabilities, market‑leading third‑party integrations, and the flexibility...CyberLocal areaFlexible hours
- ...visualization to help customers make data-driven decisions. Provide technical leadership and risk management across multiple... ...data analytics, including where AI can augment analysis, automation,... ...+ certification or other cyber certification/experience If...CyberRiskFull timeContract workPart timeLocal areaImmediate startFlexible hours
$109.2k - $223.4k
...organizations while managing dependencies, risks, timelines, and cross-functional alignment... ...Background working in engineering-driven organizations with strong technical depth... ...innovations to life-saving care. And with AI embedded across our products and services,...RiskTemporary workFlexible hours$109.2k - $223.4k
...scaling at an unprecedented pace to support the next generation of AI-driven workloads. We are seeking a Senior Principal Technical Program... ...plans, identify and mitigate technical and operational risks, and ensure commitments are met across multiple organizations with...RiskTemporary workFlexible hours$35.87 - $51.57 per hour
...we serve. Summary : The HCS Compliance Analyst III will be assigned to support the Compliance and Privacy Operations - Third Party Risk Management Department in the Compliance Program and will report directly to the manager of that team. Relevant work assignments...RiskHourly payFull time- ...important industries. Our growth is driven by delivering real results for... ...seeking an Associate Director, Technology Innovation - Google... ...documented deployments within firm risk and security guardrails Own... ...platforms; exposure to AI/agent platforms or automation...RiskH1bLocal area
- ...Cyber Defense & Data Security Lead (Americas) Location: Raleigh... ...focused on business impact and risk. Provide operational... ...service providers and support third party incident response engagements... ...supporting regulated or customer driven security requirements, including...CyberRiskFull timeLocal areaShift work
$115.4k - $251.6k
...competitive voice for Oracle Autonomous AI Lakehouse. In this highly visible, high-impact... ...integrity and defend results against third-party scrutiny. # Create technical content assets... ...on capability gaps, positioning risks, and market opportunities. # Support analyst...RiskTemporary workFlexible hours$55 - $60 per hour
...initiative to achieve compliance with the EU Cyber Resilience Act (CRA) ahead of the December... ...and waiver database supporting consistent risk-acceptance management, audit traceability,... ...) Prior exposure to semi-automated or AI-assisted vulnerability remediation...CyberRiskHourly payPermanent employmentTemporary work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of AI-Driven Third-Party Cyber Risk. Be the first to apply!
- director lease administration Raleigh, NC
- residence director Raleigh, NC
- director of foundation relations Raleigh, NC
- director of benefits Raleigh, NC
- nonprofit director Raleigh, NC
- director of video production Raleigh, NC
- senior director it Raleigh, NC
- director biotech Raleigh, NC
- director medical device Raleigh, NC
- director m&a integration Raleigh, NC

