Unknown Company
- Own the enterprise Third Party Risk Management (TPRM) security strategy, program, and operating model
- Align TPRM with enterprise cyber risk appetite, business priorities, and pharmaceutical regulatory expectations
- Establish scalable approaches for risk tiering, assessment depth, reassessment cadence, continuous monitoring, and exception governance
- Provide executive-level oversight and approval for high-risk and critical vendor risk assessments
- Lead governance for remediation prioritization, compensating controls, and formal risk acceptances
- Escalate material vendor risks to enterprise risk committees and executive leadership
- Serve as a senior Technical Information Security Lead for high-impact business initiatives, platforms, and transformations
- Advise executive-level business and technology leaders on cybersecurity risk
- Translate complex technical risks into executive-level insights and decision-ready recommendations
- Partner with Procurement, Legal, Privacy, Quality, Security, Internal Audit, and Business Leadership
- Influence contract standards and onboarding requirements to embed security, privacy, and resilience controls into third-party agreements
- Represent GRC in executive forums, governance bodies, and cross-functional steering committees
- Set strategic priorities and outcomes, delegate execution, and maintain accountability
- Drive talent development, succession planning, and capability maturity across the function
Requirements
- Bachelor’s degree with at least 8+ years of experience; OR a Master’s degree with more than 7+ years of experience; OR a Ph.D. with 5+ years of experience
- Minimum 8+ years of experience in cybersecurity, cyber risk, GRC, TPRM, security architecture, IT risk, or audit
- Experience leading and developing teams, including direct people management responsibility for technical and cybersecurity professionals
- Demonstrated experience leading complex risk programs involving multiple stakeholders and competing priorities
- Strong strategic thinking, analytical, and problem-solving capabilities
- Ability to interpret risk data and drive informed decision-making
- Exceptional communication and interpersonal skills
- Strong organizational and leadership skills, including guiding teams, managing change, and driving continuous program improvement
- Demonstrated experience in an agile work environment
- Must be authorized to be employed in the U.S. by any employer
- Must have permanent work authorization in the United States
- U.S. work visa sponsorship is not available now or in the future
- Ability to work through a personal laptop computer or mobile device for extended periods
- Travel as required by the business, less than 5% domestic and/or international
Core Competencies
Demonstrates expertise in Third Party Risk Management (TPRM) and cybersecurity, with a strong focus on aligning risk strategies with business priorities and regulatory expectations. Proven ability to lead complex risk programs, influence stakeholders, and drive continuous improvement in risk governance and remediation processes.
Highest-signal resume keywords
- Third Party Risk Management (TPRM)
- Cybersecurity
- Governance, Risk, and Compliance (GRC)
- Risk Assessment
- Team Leadership
ATS Optimization Keywords
Hard Skills
- Cyber Risk
- Security Architecture
- IT Risk
- Risk Data Interpretation
- Risk Program Management
- Agile Methodologies
- Vendor Risk Assessment
- Remediation Governance
- Continuous MonitoringAnalytical Problem-Solving
Soft Skills
- Strategic Thinking
- Exceptional Communication
- Interpersonal Skills
- Organizational Skills
- Change Management
Industry Keywords
- Pharmaceutical Regulatory Expectations
- Executive Oversight
- Stakeholder Management
- Contract Standards
- Capability Maturity
Director, Third-Party Risk Management – Technical Information Security Lead in new york at Unknown Company
This position is listed as contract and onsite.