Senior Manager, Third-Party Risk Management (TPRM)
Hagerty Insurance
Senior Manager, Third Party Risk Management (TPRM)
Hagerty is a company built by drivers for drivers. We put our members at the center of everything we do and are dedicated to making it easier and more enjoyable for enthusiasts to drive and celebrate the machines they love. We're proud to be the world's largest insurer of collectible and enthusiast vehicles and are home to the Hagerty Drivers Club, the world's largest car club. Our Marketplace business presents live and digital sales across the U.S. and Europe, we host a number of driving events and concours, and our award-winning automotive journalists produce the most popular car magazine globally, alongside internationally awarded videos. We're committed to Never Stop Driving. Ready to get in the driver's seat? Join us!
The Senior Manager, Third Party Risk Management (TPRM) Policy is a key leadership role embedded within Hagerty's Enterprise Procurement & TPRM function. This position is responsible for building and stewarding a robust third-party risk governance framework that protects Hagerty from vendor-related operational, financial, regulatory, and reputational exposure—while enabling the business to move at speed with the right partners.
Sitting within Enterprise Procurement, this role is uniquely positioned at the intersection of sourcing decisions and risk governance. The Senior Manager will own TPRM policy end-to-end, integrate risk discipline into the full vendor lifecycle, and serve as the connective tissue between Procurement, Enterprise Risk Management, Legal, IT/Security, and business stakeholders. The ideal candidate combines policy expertise with a practical, business-enabling mindset – someone who knows that good risk management doesn't slow deals down; it makes them better.
What You'll Do
Policy Ownership & Governance
- TPRM policy development: Own, author, and maintain Hagerty's enterprise wide Third Party Risk Management policy, standards, and procedures, ensuring alignment with regulatory requirements, industry frameworks (e.g., NIST CSF, ISO 27001, COBIT), and Hagerty's risk appetite.
- Policy lifecycle management: Lead scheduled and event-driven policy reviews, updating documentation in response to changes in regulation, business strategy, technology, or the vendor landscape.
- Framework integration: Align TPRM policy with adjacent governance frameworks including information security, business continuity, data privacy, and enterprise risk management—ensuring consistency without duplication.
- Regulatory compliance: Ensure TPRM policies meet applicable state and federal insurance regulations, NAIC model law requirements, and any contractual or audit-driven obligations.
- Exception management: Design and administer a formal policy exception process, documenting risk acceptance decisions with appropriate stakeholder sign-off.
Vendor Lifecycle Risk Integration
- Risk-tiered due diligence: Design and embed a risk tiering methodology into Hagerty's sourcing and onboarding process, ensuring the level of pre-contract due diligence is calibrated to the risk profile of each vendor.
- Onboarding & contracting: Partner with Enterprise Procurement and Legal to ensure vendor contracts include appropriate risk and compliance provisions—covering data protection, business continuity, audit rights, and termination for cause.
- Ongoing monitoring: Oversee a structured program of periodic reassessments, performance reviews, and continuous monitoring activities for active third parties, with heightened attention to critical and high-risk vendors.
- Offboarding controls: Establish standards for vendor offboarding that protect Hagerty's data, systems, and operational continuity at contract termination.
- Supplier relationship management program: Maintain a register of critical and high-risk third parties, coordinate enhanced oversight activities and reviews, and ensure concentration risks are visible to senior leadership.
Procurement Partnership & Business Enablement
- Embedded risk advisory: Function as the day-to-day risk advisor to the Enterprise Procurement team, providing guidance during sourcing events, RFP evaluation, negotiation, and contract execution.
- Risk-informed sourcing: Bring third party risk considerations into category strategies and sourcing decisions early—helping the business identify and mitigate risk before commitments are made.
- Business unit advisory: Serve as a trusted TPRM resource for business unit stakeholders who engage vendors directly, ensuring consistent application of policy across the organization and active participation in supplier business reviews.
- Training & enablement: Design and deliver TPRM training for Enterprise Procurement staff and business-facing teams, building risk literacy and practical policy compliance across all vendor-facing roles.
Reporting, Audit & Program Maturity
- Executive reporting: Develop and present TPRM program dashboards, key risk indicators (KRIs), and risk trend analysis to the VP of Enterprise Procurement, ERM leadership, and Risk Committee audiences as appropriate.
- Audit & regulatory examination support: Serve as Enterprise Procurement's primary point of contact for internal audit and external regulatory examiners on TPRM policy, controls, and evidence.
- Issue & remediation tracking: Identify, document, and drive resolution of risk findings and gaps across the third party portfolio, escalating as needed to senior stakeholders.
- Program maturity roadmap: Build and execute a multi-year TPRM maturity roadmap aligned to Hagerty's growth trajectory, digital transformation, and evolving risk environment.
- GRC tooling: Lead or support the evaluation and implementation of TPRM software and GRC platforms to automate assessments, centralize vendor data, and improve reporting efficiency.
This might describe you
- Proven, progressive experience in third party risk management, vendor management, procurement risk, compliance, or enterprise risk—including experience in a policy ownership or program leadership role.
- Demonstrated expertise in TPRM framework design and policy writing, including risk tiering, due diligence program management, and vendor lifecycle controls.
- Strong knowledge of applicable regulatory and compliance frameworks, including insurance industry regulations, NAIC guidelines, state privacy laws, and standards such as NIST CSF, SOC 2, and ISO 27001.
- Experience working directly within or alongside a Procurement or Strategic Sourcing function, with an understanding of sourcing processes, contract structures, and supplier relationship management.
- Proven ability to influence senior stakeholders and drive alignment across cross-functional teams without direct authority.
- Exceptional written and verbal communication skills, with a track record of producing high-quality policy documents and presenting risk topics clearly to executive audiences.
Over and above
- Prior experience in the insurance or financial services industry, with direct familiarity with NAIC model laws and state insurance department examination processes.
- Professional certifications such as CRISC, CTPRP, CISA, CISM, CPM, or equivalent risk or procurement credentials.
- Hands-on experience implementing or administering a GRC or TPRM platform (e.g., Archer, ServiceNow GRC, ProcessUnity, Venminder, Coupa Risk Assess).
- Experience supporting or leading regulatory examinations or internal audits related to vendor management or operational risk.
- Bachelor's degree in Risk Management, Business, Supply Chain, Finance, Information Systems, or a related field.
Other things to note
- This position is open to U.S. remote work. However, team members who reside within 20 miles of the Traverse City headquarters will follow a hybrid schedule, working from the office three days per week.
- Familiarity with public company requirements, including Sarbanes Oxley and key regulations, if applicable. For SOX compliant roles, responsible for designing, executing, and documenting internal controls where they have been identified as owners to prevent errors in financial reporting, processes, and business operations. Including attestation to the completeness, accuracy, and compliance of all financial reporting data, where applicable.
If you reside in the following jurisdictions: Illinois, Colorado, California, District of Columbia, Hawaii, Maryland, Minnesota, Nevada, New York, or Jersey City, New Jersey, Cincinnati or Toledo, Ohio, Rhode Island, Washington, British Columbia, Canada please email View email address on click.appcast.io for compensation, comprehensive benefits and the perks that set us apart.
At Hagerty, we share the road. We are an inclusive automotive community where all are welcomed, valued and belong regardless of race, gender, age, or car preference. We are united by our shared passion for driving, our commitment to preserve car culture for future generations and our desire to make a positive impact in the world.
- ...TryApplyNow is looking for a Compliance Third-Party Risk Management Program Manager based in Washington DC. This role involves managing the Compliance TPRM framework and guiding processes related to third-party engagements. The ideal candidate will have over 5 years of...SeniorRemote work
$120.8k - $137.9k
Capital One is seeking a Principal Associate for the Third Party Risk Management (TPRM) Team in McLean, VA. In this role, you will assess risks before procurement and provide oversight to ensure effective management of operational risks. You should have at least 3 years...Senior- ...and techniques to proactively identify risks and vulnerabilities in people, processes... ...deploy risk-driven tests and simulations (or manage a highly-skilled team that does) and... ...most critical applications, platforms, and third-party assets. You will work with application...SeniorWorldwide
$94k - $142k
Fairygodboss is looking for a professional to support third party risk management at Freddie Mac by completing the third party framework and associated reporting. The role involves collaborating with key stakeholders to enhance reporting processes and address risks. The...Senior$120.8k - $137.9k
Principal Associate, Third Party Risk Management Capital One is seeking an energetic, self-motivated Principal Associate to join the Third Party Risk Management (TPRM) Team within the Operational Risk Management second line of defense. The TPRM team is a dedicated group...SuggestedFull timePart timeLocal area- ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, Washington, DC The Senior Analyst, Cybersecurity... ...processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and Risk functions...SeniorWork experience placement
$150k - $180k
...actively looking for a proven Senior Account Executive (AE)... ...and financial risk reporting systems. This... ...experience in project management and cross-functional leadership... ...in the Supply Chain, Third Party Risk, Credit Risk or... ...quota through selling TPRM, SCRM platform to well-...SeniorContract workFor contractorsWork experience placementFlexible hours$170k - $185k
## Senior Manager, External RelationsApplylocations: Washington DCtime type: Full timeposted on: Posted Todayjob requisition id: JR-119... ...of experts, politicians, industry groups, and other relevant third parties to enhance the company's presence and gather critical...SeniorWork at officeLocal areaWorldwide3 days per week$94k - $142k
...more accessible and affordable across the nation. Position Overview This position will support 1st line of defense (1LOD) third party risk management activities for the Enterprise Third Party Office (ETPO). The successful candidate will be responsible for completing the...SeniorFull timeWork at office$170.7k - $190.8k
...Senior Manager, Security Operations (Hybrid) Senior Manager, Security Operations The Senior... ...partners across the organization to reduce risk, respond effectively to threats, and... ...management, regulatory requirements, and third‑party risk. Provide leadership across the...SeniorWork at officeRemote workFlexible hours$131k - $209k
...Workday Source to Pay Senior Manager Protiviti is looking for a Workday (Source-to-Pay) Senior Manager to join our growing Supply... ...functions, such as Contract Lifecycle Management, Source-to-Pay, Third Party Risk Management/Monitoring, Warehouse Management Systems, and...SeniorFull timeContract workTemporary workWork at officeLocal areaRemote workFlexible hours- ...fields such as Accounting, Asset Management, Capital Markets and Investor... ...today. Summary The Senior Project Manager, Design & Construction... ..., product quality, risk management, contract negotiation... ..., and management of third parties for the assigned projects. Projects...SeniorContract workFor contractorsWork at officeRemote work
$105.5k - $243k
...Senior Manager Information Governance This role has been designed as ‘’Onsite’ with an expectation... ...by regulatory changes, litigation risk, and business needs. ~ Ensure... ...responsible for verifying the credentials of any third party claiming to represent the company. Any...SeniorWork experience placementWork at officeLocal areaImmediate start- ...experienced professionals in Washington, DC, for a major construction management project. The role involves overseeing all aspects of... ...and ensuring program success through effective leadership and risk management. The ideal candidate will have over 15 years of relevant...Senior
$140k - $175k
...are looking for a highly strategic and results-oriented Senior Events Marketing Manager . This crucial role focuses on driving awareness, generating... ...tradeshows and customer summits—and coordinating third-party activations, such as trade advertising and influencer campaigns...SeniorContract workFor contractorsFreelance- ...POSITION SUMMARY: The Preconstruction Manager focuses on companywide success in... ...Understanding & Compliance with Risk Management Policies Coordinate Subcontractor... ...over half a century. Attention All Third-Party Agencies, Headhunters, and Recruiters...For contractorsFor subcontractorWork at officeFlexible hours
$70k - $80k
Senior Project Coordinator Corporate Intelligence, Americas We have... ...leaders, project managers, and researchers across both... ...and on time. Subcontractor & Third-Party Onboarding Lead the full subcontractor... ...conflict checks, and internal risk procedures. Operations...SeniorPermanent employmentContract workFor subcontractorWork at officeLocal areaImmediate startDay shiftAfternoon shift- ...Sunstall Inc. is seeking a Construction Senior Project Manager to oversee large, complex construction projects from planning through closeout.... ...include project planning, contract management, quality assurance, risk management, and maintaining strong client relationships to...SeniorContract work
$115k - $125k
...Flatiron Construction Corp is seeking a Risk Manager to lead its project risk management program. This role involves managing insurance programs, overseeing claims, and ensuring compliance with risk mitigation strategies. Candidates should have a Bachelor's degree and...Senior- ...Description AECOM is seeking a motivated and experienced Senior Water/Wastewater Project Manager to join our expanding water engineering practice. The... ...relationship with the client and all stakeholders. Performs risk management to minimize project risks. Consistently...SeniorLocal area
$50k - $63.16k
...Senior Copier Account Executive Does the art of the deal drive your day-to-day need... ...and technologies from Canon USA and our third-party providers and promote those benefits to... ...functionality to driving backfile conversion and managed print, IT, and automation services. -...SeniorFull timeTemporary workFor contractorsFor subcontractorCasual workWork at officeLocal areaImmediate startRemote workWork from home$135k
Baldwin Group Colleague, Inc. is seeking a Senior Client Executive in Bethesda, Maryland, to manage and develop consultative client relationships. The ideal candidate... ...and interpersonal skills while providing complex risk management services. This position offers a starting...Senior- ...GoIntellects Inc. is looking for an experienced Project Manager to coordinate IT project management tasks for the DC Government. The role... ...skills, and the ability to handle documentation and risk management. Candidates must have a Bachelor’s degree in Information...Senior
- A leading engineering firm in Virginia is looking for a Senior Water/Wastewater Project Manager to oversee key projects in water and wastewater treatment... ...in the D.C. metropolitan area. Strong communication and risk management skills are essential. #J-18808-Ljbffr AECOMSenior
- ...accountability for financial results and client satisfaction on large projects, defining staffing needs, and ensuring safety and risk management. The ideal candidate will have a Bachelor's degree and significant construction experience, alongside a proven track record as...Senior
- ...Apogee Global RMS is seeking a Senior Program / Project Manager to lead complex, multi‑stakeholder public‑sector initiatives across federal, IC,... ...vendors, and mission owners — ensuring programs stay aligned, risks stay visible, and delivery stays on track. What You...SeniorContract work
- Datavant is seeking a Client Coding Project Manager in Washington, D.C., to oversee risk adjustment coding audits and ensure compliance across operations. You'll be responsible for monitoring performance, educating staff, and maintaining high-quality standards in coding...Senior
$151k - $178k
...rapid development in America and globally. About the role The Senior Manager Product Deployment is a senior security leadership role responsible... ...and government bodies on all matters of security strategy and risk Program Governance & Delivery Lead the implementation and...SeniorBi-weekly payWork experience placement$109.8k - $241.6k
CACI International Inc. is looking for a Senior Project Operations Manager in Suitland, MD. This role involves leading complex defense acquisition programs... ...management and strong skills in program management and risk management. CACI values integrity, trust, and continuous...Senior- Customer Value Partners, Inc. is seeking a Program Manager in Washington, DC to lead large-scale healthcare transformation programs that... ...healthcare IT program management, a PMP certification, and strong risk management capabilities. The position requires a focus on...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager, Third-Party Risk Management (TPRM). Be the first to apply!
- risk management manager Washington DC
- risk management specialist Washington DC
- director of risk management Washington DC
- risk management associate Washington DC
- operational risk manager Washington DC
- head of risk management Washington DC
- enterprise risk manager Washington DC
- director credit risk Washington DC
- senior automation controls engineer Washington DC
- senior accounts payable Washington DC


