Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Manager, Third-Party Risk Management (TPRM)

Hagerty Insurance

Senior Manager, Third Party Risk Management (TPRM)

Hagerty is a company built by drivers for drivers. We put our members at the center of everything we do and are dedicated to making it easier and more enjoyable for enthusiasts to drive and celebrate the machines they love. We're proud to be the world's largest insurer of collectible and enthusiast vehicles and are home to the Hagerty Drivers Club, the world's largest car club. Our Marketplace business presents live and digital sales across the U.S. and Europe, we host a number of driving events and concours, and our award-winning automotive journalists produce the most popular car magazine globally, alongside internationally awarded videos. We're committed to Never Stop Driving. Ready to get in the driver's seat? Join us!

The Senior Manager, Third Party Risk Management (TPRM) Policy is a key leadership role embedded within Hagerty's Enterprise Procurement & TPRM function. This position is responsible for building and stewarding a robust third-party risk governance framework that protects Hagerty from vendor-related operational, financial, regulatory, and reputational exposure—while enabling the business to move at speed with the right partners.

Sitting within Enterprise Procurement, this role is uniquely positioned at the intersection of sourcing decisions and risk governance. The Senior Manager will own TPRM policy end-to-end, integrate risk discipline into the full vendor lifecycle, and serve as the connective tissue between Procurement, Enterprise Risk Management, Legal, IT/Security, and business stakeholders. The ideal candidate combines policy expertise with a practical, business-enabling mindset – someone who knows that good risk management doesn't slow deals down; it makes them better.

What You'll Do

Policy Ownership & Governance

  • TPRM policy development: Own, author, and maintain Hagerty's enterprise wide Third Party Risk Management policy, standards, and procedures, ensuring alignment with regulatory requirements, industry frameworks (e.g., NIST CSF, ISO 27001, COBIT), and Hagerty's risk appetite.
  • Policy lifecycle management: Lead scheduled and event-driven policy reviews, updating documentation in response to changes in regulation, business strategy, technology, or the vendor landscape.
  • Framework integration: Align TPRM policy with adjacent governance frameworks including information security, business continuity, data privacy, and enterprise risk management—ensuring consistency without duplication.
  • Regulatory compliance: Ensure TPRM policies meet applicable state and federal insurance regulations, NAIC model law requirements, and any contractual or audit-driven obligations.
  • Exception management: Design and administer a formal policy exception process, documenting risk acceptance decisions with appropriate stakeholder sign-off.

Vendor Lifecycle Risk Integration

  • Risk-tiered due diligence: Design and embed a risk tiering methodology into Hagerty's sourcing and onboarding process, ensuring the level of pre-contract due diligence is calibrated to the risk profile of each vendor.
  • Onboarding & contracting: Partner with Enterprise Procurement and Legal to ensure vendor contracts include appropriate risk and compliance provisions—covering data protection, business continuity, audit rights, and termination for cause.
  • Ongoing monitoring: Oversee a structured program of periodic reassessments, performance reviews, and continuous monitoring activities for active third parties, with heightened attention to critical and high-risk vendors.
  • Offboarding controls: Establish standards for vendor offboarding that protect Hagerty's data, systems, and operational continuity at contract termination.
  • Supplier relationship management program: Maintain a register of critical and high-risk third parties, coordinate enhanced oversight activities and reviews, and ensure concentration risks are visible to senior leadership.

Procurement Partnership & Business Enablement

  • Embedded risk advisory: Function as the day-to-day risk advisor to the Enterprise Procurement team, providing guidance during sourcing events, RFP evaluation, negotiation, and contract execution.
  • Risk-informed sourcing: Bring third party risk considerations into category strategies and sourcing decisions early—helping the business identify and mitigate risk before commitments are made.
  • Business unit advisory: Serve as a trusted TPRM resource for business unit stakeholders who engage vendors directly, ensuring consistent application of policy across the organization and active participation in supplier business reviews.
  • Training & enablement: Design and deliver TPRM training for Enterprise Procurement staff and business-facing teams, building risk literacy and practical policy compliance across all vendor-facing roles.

Reporting, Audit & Program Maturity

  • Executive reporting: Develop and present TPRM program dashboards, key risk indicators (KRIs), and risk trend analysis to the VP of Enterprise Procurement, ERM leadership, and Risk Committee audiences as appropriate.
  • Audit & regulatory examination support: Serve as Enterprise Procurement's primary point of contact for internal audit and external regulatory examiners on TPRM policy, controls, and evidence.
  • Issue & remediation tracking: Identify, document, and drive resolution of risk findings and gaps across the third party portfolio, escalating as needed to senior stakeholders.
  • Program maturity roadmap: Build and execute a multi-year TPRM maturity roadmap aligned to Hagerty's growth trajectory, digital transformation, and evolving risk environment.
  • GRC tooling: Lead or support the evaluation and implementation of TPRM software and GRC platforms to automate assessments, centralize vendor data, and improve reporting efficiency.

This might describe you

  • Proven, progressive experience in third party risk management, vendor management, procurement risk, compliance, or enterprise risk—including experience in a policy ownership or program leadership role.
  • Demonstrated expertise in TPRM framework design and policy writing, including risk tiering, due diligence program management, and vendor lifecycle controls.
  • Strong knowledge of applicable regulatory and compliance frameworks, including insurance industry regulations, NAIC guidelines, state privacy laws, and standards such as NIST CSF, SOC 2, and ISO 27001.
  • Experience working directly within or alongside a Procurement or Strategic Sourcing function, with an understanding of sourcing processes, contract structures, and supplier relationship management.
  • Proven ability to influence senior stakeholders and drive alignment across cross-functional teams without direct authority.
  • Exceptional written and verbal communication skills, with a track record of producing high-quality policy documents and presenting risk topics clearly to executive audiences.

Over and above

  • Prior experience in the insurance or financial services industry, with direct familiarity with NAIC model laws and state insurance department examination processes.
  • Professional certifications such as CRISC, CTPRP, CISA, CISM, CPM, or equivalent risk or procurement credentials.
  • Hands-on experience implementing or administering a GRC or TPRM platform (e.g., Archer, ServiceNow GRC, ProcessUnity, Venminder, Coupa Risk Assess).
  • Experience supporting or leading regulatory examinations or internal audits related to vendor management or operational risk.
  • Bachelor's degree in Risk Management, Business, Supply Chain, Finance, Information Systems, or a related field.

Other things to note

  • This position is open to U.S. remote work. However, team members who reside within 20 miles of the Traverse City headquarters will follow a hybrid schedule, working from the office three days per week.
  • Familiarity with public company requirements, including Sarbanes Oxley and key regulations, if applicable. For SOX compliant roles, responsible for designing, executing, and documenting internal controls where they have been identified as owners to prevent errors in financial reporting, processes, and business operations. Including attestation to the completeness, accuracy, and compliance of all financial reporting data, where applicable.

If you reside in the following jurisdictions: Illinois, Colorado, California, District of Columbia, Hawaii, Maryland, Minnesota, Nevada, New York, or Jersey City, New Jersey, Cincinnati or Toledo, Ohio, Rhode Island, Washington, British Columbia, Canada please email View email address on click.appcast.io for compensation, comprehensive benefits and the perks that set us apart.

At Hagerty, we share the road. We are an inclusive automotive community where all are welcomed, valued and belong regardless of race, gender, age, or car preference. We are united by our shared passion for driving, our commitment to preserve car culture for future generations and our desire to make a positive impact in the world.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior Manager, Third-Party Risk Management (TPRM) in Washington DC vacancy
  •  ...TryApplyNow is looking for a Compliance Third-Party Risk Management Program Manager based in Washington DC. This role involves managing the Compliance TPRM framework and guiding processes related to third-party engagements. The ideal candidate will have over 5 years of... 
    Senior
    Remote work

    TryApplyNow

    Washington DC
    4 days ago
  • $120.8k - $137.9k

    Capital One is seeking a Principal Associate for the Third Party Risk Management (TPRM) Team in McLean, VA. In this role, you will assess risks before procurement and provide oversight to ensure effective management of operational risks. You should have at least 3 years... 
    Senior

    Capital One

    Mc Lean, VA
    2 days ago
  •  ...and techniques to proactively identify risks and vulnerabilities in people, processes...  ...deploy risk-driven tests and simulations (or manage a highly-skilled team that does) and...  ...most critical applications, platforms, and third-party assets. You will work with application... 
    Senior
    Worldwide

    JPMorgan Chase & Co.

    Washington DC
    1 day ago
  • $94k - $142k

    Fairygodboss is looking for a professional to support third party risk management at Freddie Mac by completing the third party framework and associated reporting. The role involves collaborating with key stakeholders to enhance reporting processes and address risks. The... 
    Senior

    Fairygodboss

    Mc Lean, VA
    4 days ago
  • $120.8k - $137.9k

    Principal Associate, Third Party Risk Management Capital One is seeking an energetic, self-motivated Principal Associate to join the Third Party Risk Management (TPRM) Team within the Operational Risk Management second line of defense. The TPRM team is a dedicated group... 
    Suggested
    Full time
    Part time
    Local area

    Capital One

    Mc Lean, VA
    2 days ago
  •  ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, Washington, DC The Senior Analyst, Cybersecurity...  ...processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and Risk functions... 
    Senior
    Work experience placement

    NextStep

    Washington DC
    1 day ago
  • $150k - $180k

     ...actively looking for a proven Senior Account Executive (AE)...  ...and financial risk reporting systems. This...  ...experience in project management and cross-functional leadership...  ...in the Supply Chain, Third Party Risk, Credit Risk or...  ...quota through selling TPRM, SCRM platform to well-... 
    Senior
    Contract work
    For contractors
    Work experience placement
    Flexible hours

    RapidRatings

    Arlington, VA
    3 days ago
  • $170k - $185k

    ## Senior Manager, External RelationsApplylocations: Washington DCtime type: Full timeposted on: Posted Todayjob requisition id: JR-119...  ...of experts, politicians, industry groups, and other relevant third parties to enhance the company's presence and gather critical... 
    Senior
    Work at office
    Local area
    Worldwide
    3 days per week

    Sony

    Washington DC
    11 hours ago
  • $94k - $142k

     ...more accessible and affordable across the nation. Position Overview This position will support 1st line of defense (1LOD) third party risk management activities for the Enterprise Third Party Office (ETPO). The successful candidate will be responsible for completing the... 
    Senior
    Full time
    Work at office

    Fairygodboss

    Mc Lean, VA
    4 days ago
  • $170.7k - $190.8k

     ...Senior Manager, Security Operations (Hybrid) Senior Manager, Security Operations The Senior...  ...partners across the organization to reduce risk, respond effectively to threats, and...  ...management, regulatory requirements, and third‑party risk. Provide leadership across the... 
    Senior
    Work at office
    Remote work
    Flexible hours

    The Pew Charitable Trusts

    Washington DC
    1 day ago
  • $131k - $209k

     ...Workday Source to Pay Senior Manager Protiviti is looking for a Workday (Source-to-Pay) Senior Manager to join our growing Supply...  ...functions, such as Contract Lifecycle Management, Source-to-Pay, Third Party Risk Management/Monitoring, Warehouse Management Systems, and... 
    Senior
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Remote work
    Flexible hours

    Protiviti

    Washington DC
    4 days ago
  •  ...fields such as Accounting, Asset Management, Capital Markets and Investor...  ...today. Summary The Senior Project Manager, Design & Construction...  ..., product quality, risk management, contract negotiation...  ..., and management of third parties for the assigned projects. Projects... 
    Senior
    Contract work
    For contractors
    Work at office
    Remote work

    Realterm

    Washington DC
    26 days ago
  • $105.5k - $243k

     ...Senior Manager Information Governance This role has been designed as ‘’Onsite’ with an expectation...  ...by regulatory changes, litigation risk, and business needs. ~ Ensure...  ...responsible for verifying the credentials of any third party claiming to represent the company. Any... 
    Senior
    Work experience placement
    Work at office
    Local area
    Immediate start

    HPE

    Washington DC
    11 hours ago
  •  ...experienced professionals in Washington, DC, for a major construction management project. The role involves overseeing all aspects of...  ...and ensuring program success through effective leadership and risk management. The ideal candidate will have over 15 years of relevant... 
    Senior

    Parsons Corporation

    Washington DC
    4 days ago
  • $140k - $175k

     ...are looking for a highly strategic and results-oriented Senior Events Marketing Manager . This crucial role focuses on driving awareness, generating...  ...tradeshows and customer summits—and coordinating third-party activations, such as trade advertising and influencer campaigns... 
    Senior
    Contract work
    For contractors
    Freelance

    Xometry Inc.

    Bethesda, MD
    3 days ago
  •  ...POSITION SUMMARY: The Preconstruction Manager focuses on companywide success in...  ...Understanding & Compliance with Risk Management Policies Coordinate Subcontractor...  ...over half a century. Attention All Third-Party Agencies, Headhunters, and Recruiters... 
    For contractors
    For subcontractor
    Work at office
    Flexible hours

    Manhattan Construction

    Washington DC
    5 days ago
  • $70k - $80k

    Senior Project Coordinator Corporate Intelligence, Americas We have...  ...leaders, project managers, and researchers across both...  ...and on time. Subcontractor & Third-Party Onboarding Lead the full subcontractor...  ...conflict checks, and internal risk procedures. Operations... 
    Senior
    Permanent employment
    Contract work
    For subcontractor
    Work at office
    Local area
    Immediate start
    Day shift
    Afternoon shift

    S-RM Intelligence and Risk Consulting

    Washington DC
    5 days ago
  •  ...Sunstall Inc. is seeking a Construction Senior Project Manager to oversee large, complex construction projects from planning through closeout....  ...include project planning, contract management, quality assurance, risk management, and maintaining strong client relationships to... 
    Senior
    Contract work

    Sunstall Inc

    Washington DC
    4 days ago
  • $115k - $125k

     ...Flatiron Construction Corp is seeking a Risk Manager to lead its project risk management program. This role involves managing insurance programs, overseeing claims, and ensuring compliance with risk mitigation strategies. Candidates should have a Bachelor's degree and... 
    Senior

    Flatiron Construction

    Riverdale Park, MD
    18 hours ago
  •  ...Description AECOM is seeking a motivated and experienced Senior Water/Wastewater Project Manager to join our expanding water engineering practice. The...  ...relationship with the client and all stakeholders. Performs risk management to minimize project risks. Consistently... 
    Senior
    Local area

    AECOM

    Arlington, VA
    4 days ago
  • $50k - $63.16k

     ...Senior Copier Account Executive Does the art of the deal drive your day-to-day need...  ...and technologies from Canon USA and our third-party providers and promote those benefits to...  ...functionality to driving backfile conversion and managed print, IT, and automation services. -... 
    Senior
    Full time
    Temporary work
    For contractors
    For subcontractor
    Casual work
    Work at office
    Local area
    Immediate start
    Remote work
    Work from home

    Canon USA

    Arlington, VA
    4 days ago
  • $135k

    Baldwin Group Colleague, Inc. is seeking a Senior Client Executive in Bethesda, Maryland, to manage and develop consultative client relationships. The ideal candidate...  ...and interpersonal skills while providing complex risk management services. This position offers a starting... 
    Senior

    Baldwin Group Colleague, Inc.

    Bethesda, MD
    1 day ago
  •  ...GoIntellects Inc. is looking for an experienced Project Manager to coordinate IT project management tasks for the DC Government. The role...  ...skills, and the ability to handle documentation and risk management. Candidates must have a Bachelor’s degree in Information... 
    Senior

    Go Intellects

    Washington DC
    3 days ago
  • A leading engineering firm in Virginia is looking for a Senior Water/Wastewater Project Manager to oversee key projects in water and wastewater treatment...  ...in the D.C. metropolitan area. Strong communication and risk management skills are essential. #J-18808-Ljbffr AECOM
    Senior

    AECOM

    Arlington, VA
    5 days ago
  •  ...accountability for financial results and client satisfaction on large projects, defining staffing needs, and ensuring safety and risk management. The ideal candidate will have a Bachelor's degree and significant construction experience, alongside a proven track record as... 
    Senior

    Baker Construction

    Washington DC
    1 day ago
  •  ...Apogee Global RMS is seeking a Senior Program / Project Manager to lead complex, multi‑stakeholder public‑sector initiatives across federal, IC,...  ...vendors, and mission owners — ensuring programs stay aligned, risks stay visible, and delivery stays on track. What You... 
    Senior
    Contract work

    Apogee Global RMS

    Arlington, VA
    11 hours ago
  • Datavant is seeking a Client Coding Project Manager in Washington, D.C., to oversee risk adjustment coding audits and ensure compliance across operations. You'll be responsible for monitoring performance, educating staff, and maintaining high-quality standards in coding... 
    Senior

    Datavant

    Washington DC
    4 days ago
  • $151k - $178k

     ...rapid development in America and globally. About the role The Senior Manager Product Deployment is a senior security leadership role responsible...  ...and government bodies on all matters of security strategy and risk Program Governance & Delivery Lead the implementation and... 
    Senior
    Bi-weekly pay
    Work experience placement

    Epoch Biodesign

    Washington DC
    3 days ago
  • $109.8k - $241.6k

    CACI International Inc. is looking for a Senior Project Operations Manager in Suitland, MD. This role involves leading complex defense acquisition programs...  ...management and strong skills in program management and risk management. CACI values integrity, trust, and continuous... 
    Senior

    CACI International Inc.

    Suitland, MD
    2 days ago
  • Customer Value Partners, Inc. is seeking a Program Manager in Washington, DC to lead large-scale healthcare transformation programs that...  ...healthcare IT program management, a PMP certification, and strong risk management capabilities. The position requires a focus on... 
    Senior

    Customer Value Partners, Inc.

    Washington DC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Manager, Third-Party Risk Management (TPRM). Be the first to apply!