Technology Risk Principal Technology Third Party Risk Management

IS3 Solutions

Dallas, TX

JOB DETAILS
SKILLS
Access Control, Analysis Skills, Best Practices, Business Operations, CISSP - Certified Information Systems Security Professional, Committee of Sponsoring Organizations of the Treadway Commission (COSO), Communication Skills, Control Objectives for Information and related Technology (COBIT), Data Management, Due Diligence, Ecosystems, External Audit, ISO (International Organization for Standardization), Information Technology & Information Systems, Information/Data Security (InfoSec), Internal Audit, Leadership, Legal, Onboarding, Operational Support, Problem Solving Skills, Process Improvement, Product Lifecycle, Product Support, Program Control, Program Evaluation, Regulations, Regulatory Compliance, Regulatory Requirements, Risk, Risk Analysis, Risk Management, Security Auditing, Software Administration, Supply Chain, Technical Leadership, Technical Strategy, Technical Support, U.S. National Institute of Standards and Technology (NIST), Writing Skills
LOCATION
Dallas, TX
POSTED
5 days ago

As a Technology Risk Principal Technology Third Party Risk Management, you will be responsible for driving risk management efforts to ensure strong discipline and control for engagements with technology third parties, and providing advisory for the company's enterprise-wide TPRM program. Increasing levels of risk and regulatory requirements demand additional risk management rigor, and we must implement highly resilient, secure, and effective solutions that meet and, in some cases, exceed performance standards found in other information rich industries. You will provide leadership and support for Technology Risk initiatives across the business and strengthen third party risk management through development and maturing of governance and controls. You will utilize risk-based management to integrate information and technology risk processes into third party ecosystem operates.

You will be responsible for orchestrating a diverse set of stakeholders to identify, assess, mitigate, and monitor third party risks and drive improved governance and control across the program. You will focus on inherent and residual risk of technology third parties that support mission critical systems, access and control sensitive data, and provide hardware and software products that support operations. You will evaluate the maturity of third party risk management practices and drive program enhancements to design key elements like third party inventory, risk tiering, due diligence, and monitoring. You will ensure that regulatory / risk policies and standards and their impact on business operations are understood and addressed consistently, and that third party risks of new and existing technologies are assessed, monitored, and remediated, as necessary.

Responsibilities:

  • Drive the evolution of Technology Third Party Risk Management program, including processes to identify, assess, mitigate, monitor, and report technology third-party risks
  • Advise on the design and enhancement of foundational TPRM capabilities, including policies and standards, third-party inventory, risk tiering, due diligence, onboarding, monitoring, and termination activities
  • Evaluate program maturity and lead improvement initiatives across governance, processes, controls, technology enablement, and data management capabilities
  • Partner with stakeholders across Supply Chain, Enterprise Risk Management, Compliance, Technology, and Legal to advance strategic program objectives and strengthen risk management practices
  • Develop executive-level risk assessments, point-of-view documents, and escalation materials related to critical third parties, emerging risks, and program gaps
  • Serve as a trusted advisor to business units on emerging third-party risk topics, regulatory developments, and industry best practices

Qualifications:

  • 7+ years experience in multiple industry risk, control, and governance disciplines (e.g., Audit, Information Security, and Regulatory Compliance)
  • 5+ years of work experience in third party risk management and/or supply chain processes at a global company with strong understanding of technology products, services, and lifecycles
  • Strong presentation and executive oral/written communication skills with demonstrated experience leading culture and capabilities change across a diverse set of stakeholder groups
  • Experience designing, implementing, and sustaining programs that effectively manage risk throughout the risk management lifecycle, including:
    • Strategic technology risk advisory
    • Risk identification, including emerging risks
    • Maturity and risk assessment, scenario analysis
    • Risk response, mainly issue remediation
    • Risk monitoring
    • Policy and committee governance
  • Demonstrated success in remediating self-identified, internal / external audit, and regulatory / compliance issues with proven ability to shape and solve complex problem statements
  • Extensive knowledge of information and technology risk management policies, methods, standards, tools, and processes (e.g., ISO, COSO, COBIT, NIST) as well as knowledge of compliance, legal, internal / external audit & regulatory requirements Desired Qualification
  • BS and advanced degree preferred
  • Professional TPRM related certifications such as CTPRP, TPCRA, TPRMP, CRISC, CISSP preferred

About the Company

I

IS3 Solutions