Senior TPRM Security Lead

7 minutes ago
Full-time
Senior
Cybersecurity
Gong

Gong

Gong provides a revenue intelligence platform that captures and analyzes customer interactions, enabling B2B sales teams to enhance their sales conversations and make data-driven decisions to increase revenue.

Internet Software & Services
251-1K
Founded 2015
$583M raised

Description

  • Own the end-to-end third-party risk lifecycle, including intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.
  • Establish baselines and controls to reduce and manage third-party risk across the vendor portfolio.
  • Apply a risk-based approach to vendor reviews by tiering vendors based on criticality, data sensitivity, and inherent risk.
  • Build a robust, scalable TPRM program that evolves with business needs and supports growth.
  • Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains.
  • Partner with Procurement and Legal to embed risk requirements into contracts, data processing agreements, and onboarding workflows.
  • Maintain and enhance TPRM frameworks, policies, standards, and procedures aligned to SOC 2, ISO 27001, and privacy regulations.
  • Manage continuous monitoring, periodic reassessments, tiering, and remediation tracking across the vendor portfolio.
  • Administer and optimize TPRM tooling and automation to scale the program.
  • Report third-party risk posture, metrics, and trends to GRC leadership and stakeholders.
  • Support audit and customer assurance activities related to third-party risk.
  • Ensure vendors meet security agreements and are held accountable to their commitments.

Requirements

  • 7+ years of experience in third-party/vendor risk management, GRC, information security, or a related field.
  • Demonstrated ability to establish baselines and controls and use a risk-based approach to vendor reviews.
  • Strong working knowledge of security and compliance frameworks such as SOC 2, ISO 27001, and NIST, plus data privacy regulations.
  • Experience conducting vendor risk assessments and interpreting security documentation such as SOC 2 reports, pen test results, and questionnaires.
  • Excellent cross-functional collaboration and communication skills with the ability to translate risk into business terms.
  • Experience with TPRM tooling, such as Zip.
  • Relevant certifications such as CTPRP, CISA, CISSP, or CRISC are a plus.

Benefits

  • Medical, dental, and vision coverage for employees and families.
  • Flexible wellbeing fund/wellness stipend.
  • Mental health benefits with covered therapy and coaching.
  • 401(k) program.
  • Education and learning stipend.
  • Flexible vacation time.
  • Paid parental leave.
  • Quarterly company-wide recharge days.
  • Work-from-home stipend.
  • Annual salary range of $117,000 to $185,000 USD.
  • Potential total compensation includes incentive compensation, bonus, equity, and benefits.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Client Due Dilligence Analyst (DDQ)

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a DDQ Analyst to support its global sales process by managing client due diligence questionnaires and related compliance workflows.

Cybersecurity
23 hours, 7 minutes ago

Senior Cybersecurity Awareness Engineer

iFood 5K-10K Air Freight & Logistics

O iFood busca uma pessoa para liderar programas de Security Awareness e risco humano, fortalecendo a cultura de segurança com comunicação, dados e iniciativas comportamentais em parceria com áreas internas.

23 hours, 22 minutes ago

Lead Security & Compliance Analyst

Parachute Health 51-250 Health Care Providers & Services

Parachute Health is hiring a hybrid security compliance and technical security professional to own audits and strengthen the security posture of its digital ordering platform for post-acute care.

AWS Bash HIPAA Python SIEM TLS WAF
23 hours, 37 minutes ago

FOIA Litigation Analyst

TechOp Solutions International 51-250 Internet Software & Services

TechOp Solutions International is hiring a FOIA Litigation Analyst to manage complex Freedom of Information Act litigation cases and support legal teams in ensuring compliance and transparency.

23 hours, 37 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers