Cybersecurity Third Party Risk Management Director
Listed on 2026-06-28
-
IT/Tech
Cybersecurity, Information Security, Data Security
Language Fluency: English (Required)
Work Shift: 1st shift (United States of America)
Job Grade: 114
Please review the following job description:
Truist is seeking a senior leader to transform, modernize, and operate the Cybersecurity Third-Party Risk Management (CTPRM) function within Truist Protection Services (TPS). Reporting to the Head of Security Governance, this role will redefine how cyber third-party risk is identified, assessed, and continuously monitored—leveraging agentic AI, automation, and advanced analytics to scale decision-making across Truist’s ecosystem. This leader will drive the evolution from traditional, manual assessment models to intelligent, adaptive, and technology-driven risk management capabilities.
The role partners closely with the Enterprise Third Party Risk Operations Function (TPROF), second line Risk, Business Information Security Officers (BISOs), Sourcing, Legal, and Technology teams to strengthen Truist’s cyber supply chain posture ideal candidate has led CTPRM teams in a large, regulated environment, can translate technical risk into clear business decisions, and can drive measurable program outcomes at scale.
success looks like
- A modern, intelligence-driven CTPRM Function leveraging agentic AI and automation to reduce manual effort, accelerate assessments, and enable near real-time risk visibility across the third-party ecosystem.
- Measurable improvements in assessment cycle time, signal quality, and automation coverage through the adoption of AI-driven workflows and decision support.
- Executive-ready reporting that highlights top cyber risks, trends, and prioritized remediation actions across critical suppliers and services.
- Strong partnerships across first, second, and third lines of defense and positive outcomes in regulatory and audit engagements.
This role leads the strategy, governance, and delivery of Truist’s cybersecurity third-party risk management Function. Responsibilities will evolve as the Function scales and matures.
- Architect and lead the transformation of the Cyber Third-Party Risk Management (CTPRM) operating model, embedding agentic AI, automation, and intelligent workflows to significantly improve scalability, speed, and risk insight.
- Drive a culture of automation and innovation—challenging legacy processes, reducing manual effort, and continuously identifying opportunities to apply AI and emerging technologies to improve program effectiveness.
- Own the cyber contract deviation (exception) governance process—including intake, risk analysis, decision support, approvals, documentation, and ongoing monitoring/expiration, in partnership with Legal.
- Build, lead, and continuously improve the third-party cybersecurity assessment activities (methodology, scoping, testing/evidence standards, quality assurance) and drive timely remediation of identified Third Party Sub-Issues and risks.
- Leverage agentic AI, technology, data, third-party intelligence, and strategic partners to scale assessment throughput, improve risk signal quality, and increase automation where appropriate.
- Partner with BISOs and business leaders to integrate cyber third-party risk into business decisions, onboarding, change management, and ongoing Third Party performance/risk reviews.
- Hire, develop, and retain a high-performing team of cybersecurity and third-party cybersecurity risk professionals; set clear goals, coaching, and a strong culture of accountability and collaboration.
- Partner with second line Risk to align oversight expectations, strengthen issue management, and reduce Truist’s exposure to cyber supply chain and concentration risk.
- Establish strong cross-functional working relationships and alignment across TPS, Enterprise TPROF, Technology, Procurement, Legal, and business stakeholders, embodying a “we deliver together” culture.
- Support regulatory exams and internal audit engagements related to information security and third-party cybersecurity risk; ensure timely, accurate responses, sustainable remediation, and strong control evidence.
Required Qualifications:
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).