- Company Name
- Atlas
- Job Title
- Third Party Risk Management Consultant
- Job Description
-
**Job Title**
Third Party Risk Management Consultant
**Role Summary**
Act as the analytical lead for third‑party cyber risk management, integrating compliance, cybersecurity, and vendor governance to protect critical data. Orchestrate risk assessments, audits, continuous monitoring, and stakeholder engagement to ensure vendors meet security, regulatory, and operational standards.
**Expectations**
- Deliver a comprehensive TPCRM program that meets DK Act and other regulatory requirements by end‑of‑year 2026.
- Achieve 100 % assessment of new suppliers and 100 % reassessment of high‑risk suppliers within the allotted timeline.
- Communicate risk findings in business terms, enabling informed decision‑making across digital, procurement, legal, and compliance functions.
- Maintain an integrated dashboard of risk metrics and audit results.
**Key Responsibilities**
- Develop, update, and enforce TPCRM security standards, metrics, and documentation.
- Continuously assess vendor risk, applying NIST, ISO 27001, FISMA, SOC 1/2 frameworks.
- Design and execute a cyber risk audit service, establishing audit calendars, priorities, and dashboards.
- Evaluate security assurance statements of critical suppliers and manage reassessments.
- Select and deploy monitoring tools, AI/ML analytics, and automation platforms to capture real‑time risk indicators.
- Align TPCRM requirements with procurement, compliance, legal, privacy, QA, and digital teams.
- Lead cross‑functional relationships with Digital, Legal, and Global Procurement leaders.
- Provide training, awareness, and storytelling on risk to stakeholders.
**Required Skills**
- 5+ years in TPCRM with strong analytical background.
- Proficiency with risk/control frameworks (NIST, ISO 27001, FISMA, SOC 1/2).
- Experience using GRC platforms (ServiceNow, Galvanize, Archer, WolfPAC).
- Hands‑on use of AI/ML tools, risk analytics, and automation.
- Excellent communication, data storytelling, and stakeholder management.
- Knowledge of GDPR, SOX, HIPAA, and other industry regulations.
- Ability to work in multinational, virtual teams and adapt to evolving cyber‑security practices.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, MIS, or related field (or equivalent experience).
- Certifications: CTPRP, CRISC, CISSP, CISA, or CISM.
---