Unknown Company

Third Party Risk Manager

new york, ny • Posted 3 days ago
Remote Full Time General

Consultant Role at CroweYour journey at Crowe starts here:At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you're trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That's why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services.

Join us at Crowe and embark on a career where you can help shape the future of our industry.Job Description:Consulting is a dynamic business focused on solving problems for our clients and serving our core markets through innovative solutions. As technology and AI continue to reshape the consulting landscape, we are looking for individuals who are curious, adaptable, and eager to learn. At Crowe, consultants are expected to build both technical and transferable skills, think critically, and use technology to solve real business problems. In this role, you will continuously learn, collaborate across teams, and explore how tools, including emerging AI capabilities, can improve efficiency, insights, and client outcomes.In management at Crowe, you play a pivotal role in leading teams, guiding project execution, and deepening client relationships. You are expected to contribute to account planning, identify opportunities to add value, and ensure high-quality delivery. As your responsibilities expand, you take on broader account ownership, balancing project leadership with growing involvement in client strategy and solution development.Success in this role comes from a growth mindset, strong communication skills, advanced critical thinking, and the ability to navigate new challenges with confidence.The Third Party Risk Manager position will be primarily responsible for managing and leading the assessment of the information security posture of key clients' third parties while overseeing the overall execution, quality, and delivery of assessments.

The position will work within a Crowe team at a client or third-party site and be responsible for leading teams in identifying key risks, information security gaps, and remediation strategies. This role will also serve as a trusted advisor to client leadership and provide mentorship and oversight to junior team members. Projects would be performed through interacting with the client's Information Security and Business Unit leadership, as well as the client's vendors, service providers, and partners.Specific projects and responsibilities may include:Leading Third Party Risk Assessments by evaluating third-party questionnaire responses, performing control validation, and assessing documentation per established procedures and standardsManaging and overseeing assessment teams, project timelines, and client deliverables across multiple engagementsPerforming and overseeing site visits to third-party facilitiesEvaluating the effectiveness of security controls for compliance with applicable policies, security laws, regulations, and industry standardsAssessing cloud technologies such as Software as a Service (SaaS) hosted applications, Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) deploymentsDocumenting information security risk and compliance findings, presenting recommendations for remediation, and communicating results to client leadershipPerforming quality assurance reviews of assessments completed by team members to ensure consistency and accuracyDelivering high-quality, executive-level reports and presentationsCoordinating schedules, resource allocation, and assessment activities for key third-party clients while overseeing all key deliverablesSupporting business development initiatives, client relationship management, and practice growth effortsMentoring, coaching, and developing staff and senior consultants within the practiceOur clients operate in and our team members work across the following industries:PharmaceuticalLife SciencesBiotechnologyHealthcareManufacturingFinancial ServicesTechnology, Media and TelecommunicationsBasic QualificationsBachelor's DegreeInformation Technology and/or Cybersecurity background and/or experience, including 5–8+ years of IT, cybersecurity, risk management, or third-party risk experience with network, platform, and/or application technologyOne or more of the following certifications required:Certified Information Systems Security Professional (CISSP)Certified Information Systems Auditor (CISA)Certified Third Party Risk Assessor (CTPRA)Certified in Risk and Information Systems Control (CRISC) preferredStrong knowledge of security domains such as auditing, policy, database security, firewall design and implementation, risk analysis, identity management, access management, cloud security, or web securityWorking knowledge of one or more compliance frameworks such as SOC 2, ISO 27001, NIST, HIPAA, PCI DSS, or HITRUSTExperience managing multiple projects and teams in a fast-paced consulting environmentDemonstrated leadership experience overseeing project execution, client relationships, and team performanceProven ability to learn new technologies and systems, especially through independent research and self-studyStrong verbal and written communication skills with the ability to present technical information to both technical and executive audiencesAbility to manage project schedules, budgets, staffing, and client expectationsAbility to travel domestically an average of 20%–50% per yearPreferred QualificationsBachelor's and/or advanced degree with a concentration in Cybersecurity, Risk Management, Computer Science, Management Information Systems, or related fieldExperience working with or assessing third-party vendors and service providersIT or cybersecurity experience at a leading public company, consulting firm, or regulated industry organizationExperience with Archer, ProcessUnity, ServiceNow, OneTrust, or other GRC/VRM platformsExperience with security ratings platforms and continuous monitoring solutionsExperience leading teams and mentoring junior professionals in a consulting or advisory environmentBilingual capabilities preferredOpen to remote work arrangementsWe expect the candidate to uphold Crowe's values of Care, Trust, Courage, and Stewardship. These values define who we are. We expect all of our people to act ethically and with integrity at all times.In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Crowe is not sponsoring for work authorization at this time.The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.

The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Crowe, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $59,800.00 - $114,500.00 per year.

Back to Job Search