The opportunity
The key objectives of the TPRM Program are to:
What you'll do
Assess the risk of third-party relationships which drive the rigor of risk: management activities both during the third-party onboarding and ongoing monitoring lifecycle phases using the TPRM Program’s formula-based risk methodology;
Act as a liaison across key internal stakeholder teams (Procurement, Legal,: Enterprise Security and the Business) to ensure clear and accurate communication of third-party risks aligned to risk management activities in order to complete risk assessments in a timely manner;
Identify TPRM program enhancements aimed at the effective and efficient: management of third-party risk in order to support Business strategic initiatives.
Apply the TPRM Program’s formula-based inherent risk methodology and assign: Criticality designations for standard third-party relationships, documenting the inputs, rationale, and supporting evidence
Perform completeness and consistency checks on intake information, risk: calculations, and assessment records; identify missing, inconsistent, or unclear information and escalate exceptions in accordance with defined thresholds.
Gather, organize, and maintain third-party-provided information and: documentation in accordance with TPRM assessment methodology and audit-readiness expectations.
What they're looking for
- Identify and route required SME reviews using defined risk triggers, track: responses, and document completed SME assessments and supporting evidence.
- Maintain accurate and timely records in Graphite Connect, Jira, and other approved systems of record.
- Support execution of third-party risk assessment remediation of identified: gaps or findings based on defined risk triggers to obtain complete responses and supporting documentation.
- Support routine communication with third parties to resolve identified gaps,: with primary responsibility for Medium-Risk and Low-Risk remediation activities.