More jobs:
Third Party Risk Management Lead
Job in
Foster City, San Mateo County, California, 94420, USA
Listed on 2026-07-21
Listing for:
Jobtailor
Full Time
position Listed on 2026-07-21
Job specializations:
-
Security
Information Security & Data Protection
Job Description & How to Apply Below
Responsibilities
- Run substantive third‑party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses
- Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers
- Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI‑specific provisions
- Review contracts for non‑standard security language when flagged by Legal or deal desk, and recommend redlines
- Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register
- Enable sales through maturing the customer trust program
- Build the capability for continuous monitoring of vendor ecosystem
- 8+ years in third‑party/vendor risk management, security risk, or a related GRC role
- Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation
- Experience reviewing or redlining security and data‑handling contract language, ideally in partnership with a legal team
- Working knowledge of data privacy fundamentals (GDPR, CCPA) as they relate to vendor and subprocessor relationships
- Strong cross‑functional collaboration skills — this role touches Legal, Engineering, Product, and Sales regularly
- Experience building repeatable, scalable vendor review processes rather than inheriting an existing one
- Bonus Qualifications include direct experience assessing foundation model providers or AI/ML vendors specifically
Expertise in third‑party risk management, including independent vendor risk assessment and contract review, with a strong understanding of data privacy regulations and the ability to collaborate across multiple functions. Proven capability in building scalable vendor review processes and maintaining comprehensive risk registers.
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×