Third-Party Risk Management - Cybersecurity
Hudson Manpower
Job Description:
GRC TPRM Assessment and Remediation SME
We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert (SME) to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation.
The role will be responsible for supplier inventory governance, assessment coordination, findings management, remediation tracking, escalation management, and executive reporting . The ideal candidate will have strong TPRM/GRC expertise, excellent communication skills, and experience managing high-volume, multi-step risk assessment workflows.
Location: Austin, TX / Cupertino, CA
Work Model: Hybrid – 3 Days a Week Onsite
Duration: 12+ Months Contract
Key Responsibilities
1. Supplier Inventory Management
Maintain the Supplier Inventory within the GRC platform as the single source of truth for assessment status.
Tier and filter suppliers requiring reassessment versus new assessments based on program criteria.
Maintain accurate Direct Responsible Individual (DRI) records within the GRC tool.
2. Assessment Execution
Evaluate suppliers against established frameworks and standards, including:
SIG
CAIQ
NIST CSF
ISO 27001
SOC 2
Review and validate supplier evidence, including audit reports, certifications, penetration test results, and other security documentation.
Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
Log and track assessment tasks in workflow/tracking tools, including acknowledgement evidence.
Verify that onsite-assessed suppliers have current-year assessment coverage.
Participate in recurring findings-review meetings and provide guidance on policy requirements and evidence standards.
3. Remediation Management
Own Corrective Action Plans (CAPs) from initiation through closure.
Define remediation SLAs and track progress against established timelines.
Drive remediation closure with suppliers and internal business owners.
Coordinate with Legal, Procurement, and Information Security (InfoSec) teams regarding remediation timelines and compensating controls.
Monitor open findings and ensure appropriate documentation and evidence are maintained.
4. Stakeholder Communication & Escalation
Manage a structured outreach cadence with DRIs, including:
Initial kick-off
Follow-up communications
Management escalations
Track response and non-response rates for each outreach cycle.
Escalate unresolved or high-risk findings to appropriate leadership.
Maintain clear documentation of all communications, decisions, and remediation activities.
Build and maintain strong relationships with business stakeholders and suppliers.
5. Weekly Reporting
Prepare and deliver weekly metrics and status reports for leadership.
Track and report:
Outreach volume
Supplier response rates
Follow-up and escalation status
Suppliers approved for new assessments or reassessments
Assessment completion and coverage
Open findings and remediation status
Overall TPRM program progress
Required Qualifications
5+ years of experience in Cybersecurity, Third-Party Risk Management (TPRM), GRC Operations, Supplier Risk, or a related field.
Strong working knowledge of:
NIST CSF
ISO 27001
SOC 2
SIG
CAIQ
Hands-on experience with GRC/TPRM platforms , such as:
OneTrust
RSA Archer
ServiceNow GRC
SupplierNinja
or similar platforms
Proven experience managing high-volume, multi-step communication and assessment workflows.
Strong findings and remediation management experience.
Excellent written and verbal communication skills.
Strong documentation, organization, and follow-through skills.
Experience working with distributed or remote teams.
Ability to communicate effectively with business stakeholders, suppliers, and leadership.
Preferred Qualifications
Relevant certification such as CTPRP, CRISC, CISA, or CISSP .
Experience with workflow and tracking tools such as:
Wrike
Airtable
Jira
or similar platforms
Experience working in regulated industries such as:
Financial Services
Healthcare
Insurance
Experience preparing leadership-facing metrics, dashboards, and weekly reports .
Experience managing supplier cybersecurity assessments and remediation programs in a large enterprise environment.
$156k - $255k
...decisions we make, including how we manage and protect the data of our... .... LinkedIn’s Enterprise & Third-Party Security team is dedicated... ...security and privacy risks throughout our external ecosystem... ...degree in Computer Science, Cybersecurity, Information Security, or...SuggestedFor contractorsWork experience placementWork at officeFlexible hours$60k - $215k
...Great Company, Great Culture, Great Rewards, and Great Careers. GEICO’s Cybersecurity organization has an exciting opportunity for an accomplished Engineer II – Third-Party Cyber Risk Management . This individual will play a key role within GEICO’s Trustworthy...SuggestedHourly payFull timeWork experience placementLocal area$108k - $148.5k
...Learn more about our benefits. Role SummaryThe TPRM Product Manager - owns the enterprise TPRM technology product strategy and ensures... ...the platform supports scalable, automated, and compliant third-party risk management processes.This role serves as the bridge between Procurement...SuggestedFull timeTemporary workShift work- ...About the Company Innovative cybersecurity ratings platform Industry... ...Technology Specialties it management cyber insurance cyber resilience cyber risk vendor risk management... ...vendor risk monitoring third-party risk management cyber vrm...SuggestedRemote work
$131.3k - $229.7k
...comprehensive security assessments and risk management. This role requires international... ...America, and South America Regions.The Cybersecurity Supply Chain Assessor plays a critical... ...strengthening the security posture of third-party manufacturing and supplier partners across...SuggestedContract workLocal areaFlexible hours$140k - $215k
As a global leader in cybersecurity, CrowdStrike protects... ...Traditional Privileged Access Management (PAM) solutions rely... ...internal and external parties. You will deliver core... ...and integrations with third party solutions.Real... ...or exploitable risk.Fluency with core identity...Full timeWork experience placementLive inWork at officeLocal areaImmediate start2 days per week- ...global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI... ...(a governed, metered product that lets third-party agents and systems reach Proofpoint data... ...customer-facing plane where agents are managed and governed). The agents themselves —...Full time
- ...architectures, identifying security risks, defining remediation... ...and stakeholder management skills Core Responsibilities... ...Identity & Access Controls * Third-Party Risk Evaluation * SaaS Security... ...of the following: * NIST Cybersecurity Framework (CSF) * NIST 800-5...Long term contract
$90k - $145k
...We Are In order to be the cybersecurity partner of choice, we must... ...executive programs, and premier third-party industry events. Own key... ...the event lifecycle. Manage purchase orders, expense tracking... ...milestones, deliverables, risks, and dependencies,...Full timeWork at officeVisa sponsorshipWork visa- ...Who We AreIn order to be the cybersecurity partner of choice, we must... ...a highly fragmented OS and third-party ecosystem. This is a high-impact... ...for Global Support, Product Management, and engineering leadership... ...that dream big, take risks, and challenge cybersecurity...Full timeLocal areaRemote workVisa sponsorshipWork visa
$105.5k - $213.5k
Manufacturing Program Manager (Sunnyvale, CA)This role has been designed as 'Hybrid' with... ...and managing. Manages corporate and third-party vendor efforts to plan, build and implement... ...improvement of Quality, Cost, Delivery and Risk mitigation. Other manufacturing-related...Full timeWork experience placementWork at officeLocal areaImmediate start2 days per week$152k - $246.5k
...Who We AreIn order to be the cybersecurity partner of choice, we must... ...SummaryJob DescriptionAs the Sr. Manager of Product Partnerships, you... ...and SCM) offerings through third-party integrations, acting as a... ...trailblazers that dream big, take risks, and challenge cybersecurity...Full timeWork at officeShift work- ...Project Manager With Budget System Implementation ExperienceComtech LLC is a woman-owned... ...System. Coordinate with staff resources and third parties/vendors for the execution of the project... .... Ability to effectively perform risk management to minimize project risks. Ability...Work experience placementWork at office
- ...ever-evolving landscape of cybersecurity.When you join our team, you... ...they can identify and minimize risk in the cloud.You will design... ....Partner with Product Management to review, refine requirement... ...check through an authorized third-party vendor. If you receive any communication...Immediate start
- ...include:• Application Development• Project Management• Quality Assurance• Business/Systems... ...Intelligence• Infrastructure & Network Services• Risk Management & Compliance• Business... ...H1B VISAS OR CANDIDATES REPRESENTED BY THIRD PARTIES.On behalf of our client, Procom Services...Permanent employmentContract workFor contractorsH1b
- ...include:• Application Development• Project Management• Quality Assurance• Business/Systems... ...Intelligence• Infrastructure & Network Services• Risk Management & Compliance• Business... ...H1B VISAS OR CANDIDATES REPRESENTED BY THIRD PARTIES.On behalf of our client, Procom is looking...Permanent employmentContract workFor contractorsH1b
$200k
...physical world. As Senior Engineering Program Manager, you will drive execution of our... ...development, platform hardware, software, and third-party IP (3PIP) vendors.This role is the... ...manufacturing partners. You will surface risks early, drive decisions to closure, and keep...Contract workFlexible hours$200k - $225k
...the design and oversight of cybersecurity, compliance, and privacy programs... ...AND DUTIESRisk Management: Sets the mission, vision, and strategy for technology risk management including cybersecurity... ...share lessons learned.Vendor & Third‑Party Management:Lead vendor...Full timeTemporary workFlexible hours- ...leadership and oversight of the enterprise Cybersecurity Governance, Risk, and Compliance (GRC) program. This... ...to effectively identify, assess, manage, and communicate cybersecurity and... ...obligations and risk implications. Third-Party Risk Management Establish and oversee...Local areaWorldwideFlexible hours
$85 per hour
...Senior Cybersecurity Program Manager LeadStack Inc. is an award-winning, one of the nation's fastest... ...collaborate with IT, Security Operations, Risk Management, Compliance, and business... ...external stakeholders, vendors, and third-party service providers. Facilitate...$132k - $264k
...key part of e-commerce at Walmart. It is a gateway for Third-Party Sellers to manage their operations, such as onboarding, catalogs, order fulfillment... .... We’re a team of software engineers, data scientists, cybersecurity expert's and service professionals within the world’s...Full timeTemporary workPart time$68.75 - $137.5 per hour
...partner with engineers product managers and stakeholders across... ...engineers, data scientists, cybersecurity expert's and service professionals... ...that power Walmart's third-party seller ecosystem. About the... ...Payout Critical Payout Services Risk Management Agentic AI-...Full timeTemporary workPart time$149.52k - $175.9k
...environments.Lead production operations, incident management, problem management, and root-cause... ...demand.Present platform health metrics, risk assessments, capacity plans, and... ...infrastructure, networking, application development, cybersecurity, and operations teams.Provide executive-...Full timeWork experience placementLocal area3 days per week$210k - $289.25k
...are, you’re in the right place.Who We AreIn order to be the cybersecurity partner of choice, we must trailblaze the path and shape the... ...digital world by providing the highest quality incident response, risk management, and digital forensic services to clients of all sizes. Our...Full timeRemote workVisa sponsorshipWork visa$104.8k - $218.5k
...Organizations today face increasingly complex cybersecurity challenges driven by evolving threats,... ...identify opportunities to strengthen risk management and governance, and develop practical... ..., Data Protection, Cloud Security, Third-Party Risk Management, or Zero Trust....Full timeSummer holidayFlexible hours$120 - $170 per hour
...Sr. Program Manager, NPIFull-time | Permanent Salaried | Remote- $120-$170KWe are not currently working with third party agencies on this role.About Us: Vantedge Medical is the premier... ...internal stakeholders on program status, risks, and decisions; prevent surprises...Permanent employmentFull timeContract workWork at officeRemote work$157.6k - $216.7k
...are, you’re in the right place.Who We AreIn order to be the cybersecurity partner of choice, we must trailblaze the path and shape the... ...including AI Security, Zero Trust, Cloud Security, and Cyber Risk Management. You will leverage a variety of advanced tools and...Full timeRemote workVisa sponsorshipWork visa$120k - $125k
...General Manager - Palo Alto, CA Take the Next Step in Your Property Management Career! SRG Residential is a premier third-party multifamily property management firm committed to creating... ...manager; identifies actual or potential risk management issues. Reads,...Full timeContract workFor contractors- ...identifies and mitigates technical risks and hazards, and works directly with Program Managers, operators, program offices,... ..., quality assurance, cybersecurity, release processes, risk management... ...interoperability standards, data rights, and third-party integration. ● Experience...Flexible hours
- ...Prelude Services is a Managed Service Provider that has delivered innovative and secure... ...Hardware and Software Support ~ HIPAA IT Risk Assessment and Security Management Services... ..., employee recognition events, holiday parties, etc. # Conducts audits of payroll, benefits...Temporary workCasual workWork at officeLocal areaRemote workWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third-Party Risk Management - Cybersecurity. Be the first to apply!
- risk Cupertino, CA
- risk adjustment Cupertino, CA
- technology risk Cupertino, CA
- high risk Cupertino, CA
- rn risk management Cupertino, CA
- cybersecurity software engineer Cupertino, CA
- senior cybersecurity engineer Cupertino, CA
- cybersecurity administrator Cupertino, CA
- cybersecurity specialist Cupertino, CA
- non financial risk



