Responsibilities
- Run substantive third‑party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses
- Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers
- Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI‑specific provisions
- Review contracts for non‑standard security language when flagged by Legal or deal desk, and recommend redlines
- Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register
- Enable sales through maturing the customer trust program
- Build the capability for continuous monitoring of vendor ecosystem
Requirements
- 8+ years in third‑party/vendor risk management, security risk, or a related GRC role
- Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation
- Experience reviewing or redlining security and data‑handling contract language, ideally in partnership with a legal team
- Working knowledge of data privacy fundamentals (GDPR, CCPA) as they relate to vendor and subprocessor relationships
- Strong cross‑functional collaboration skills — this role touches Legal, Engineering, Product, and Sales regularly
- Experience building repeatable, scalable vendor review processes rather than inheriting an existing one
- Bonus Qualifications include direct experience assessing foundation model providers or AI/ML vendors specifically
Core Competencies
Expertise in third‑party risk management, including independent vendor risk assessment and contract review, with a strong understanding of data privacy regulations and the ability to collaborate across multiple functions. Proven capability in building scalable vendor review processes and maintaining comprehensive risk registers.
#J-18808-LjbffrThird Party Risk Management Lead in foster city at Unknown Company
This position is listed as contract and onsite.