About the Role
Manager, Third Party Risk Management
remote type
Remote (USA)
locations
Portland, OR
Remote, USA
Remote, OR
time type
Full time
job requisition id
REQ004562
At The Standard, youll join a team focused on putting our customers first.
Our continued success is driven by a high-performance culture. Were looking for people who are collaborative, accountable, creative, agile and are driven by a passion for doing whats right across the company and in our local communities.
We offer a caring culture where you can make a real difference, every day.
Ready to reach your highest potential? Lets work together.
Job Summary:
This position will manage the third-party risk management (TPRM) team responsible for understanding and managing risk associated with third parties that the company does business and/or shares data. The TPRM team works to identify and assess information security, business continuity, operational, technology, financial and other risks, communicate this risk to stakeholders and consult with them to develop mitigation strategies to reduce the risk.
This position is responsible for managing the work environment, partnering with senior leaders to identify workforce needs, and ensuring performance against corporate manager expectations, values, and vision.
Principal Duties & Responsibilities:
TPRM TeamManagement
50% Manages team of TPRM professionals including hiring, training, coaching, mentoring, and development of team members.
- Leads the design and continuous improvement of third-party risk assessment processes including the development and maintenance of procedures, automation, artifacts, and metrics to be used in the assessment of third parties.
- Drives the identification of new third-party risks and leads the TPRM teams design and implementation of new risk assessment procedures to address those risks.
- Leads the identification, evaluation, acquisition, and implementation of new technologies, inclusive of Artificial Intelligence (AI) bases technologies, to support the TPRM program.
- Provides input into the TPRM budget.
TPRM Operations
45% Oversees the capture high level information for third-party engagements, including analysis of the business environment, the data involved, how the business will use the vendor and the business criticality of the processes the vendor will support.
- Applies inherent risk scoring and business intelligence to determine level of due diligence required.
- Manages the TPRM team as it assesses and evidences the existence and efficacy of third-party information security and other risk controls and recommend treatment as needed to align with Standards risk appetite and information security standards; consult with stakeholders to mitigate risk.Ensures that all risk review documentation is complete and accurate in addressing the risks to The Standard.
- Advises business on any changes requested by third parties to security and privacy provisions of our contracts.
- Performs third party compliance risk tracking, trending, analysis, and reporting.Provides leadership with operational updates on the TPRM programs overall vendor risk assessment progress on a routine basis.
- Advises business owners, supplier management and project teams on vendor assessment requirements and desired outcomes.
- Keeps abreast of the latest security, privacy, business continuity and regulatory concerns and best practices impacting third party risk management.
- Participates in cross-functional team initiatives and projects to continuously improve the processes and security posture.
5% Other duties as assigned.
Job Specifications:
REQUIRED EDUCATION: High School Diploma
PREFERRED EDUCATION: Bachelors degree in business or related field.
Required experience:
- Seven (7) years of experience in third-party risk management, information security, general risk management, business continuity management and business operations. Three (3) years of people management experience, building and developing teams.
- Demonstrates knowledge and support for the LEAN management system, including all aspects of leader standard work.
- Thorough understanding of security, IT, and business compliance frameworks and processes (SOC1, SOC2, ISO, etc.).
- Technical, information security and MS Office skills.
- Familiarity with vendor management tools such as Archer, Risk Recon, etc.
PREFERRED EXPERIENCE: Experience initiating and leading projects, including strategy development, business case presentations and strategy execution. Experience promoting corporate objectives and initiatives.
PREFERRED LICENSE/CERTIFICATION: Risk management-related certification (i.e. CTPRP, CBCP, CRISC, CISSP, etc.) is a plus.