FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Manager, Third Party Risk Management
AsurionSenior Manager leading third-party risk management program at Asurion. Collaborating with cross-functional teams to mitigate vendor risks and enhance supply chain resilience.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Third-Party/Vendor Risk Management, including strategy development, risk assessment, and compliance with industry standards. Proficient in leading risk teams and operationalizing risk management processes to ensure security and resilience across vendor relationships.
Highest-signal resume keywords
Third-Party Risk ManagementNIST CSF 2.0ISO 27001Vendor Risk Lifecycle ManagementPeople Leadership
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk AssessmentRisk-Tiering MethodologySecurity AssessmentsContractual Security RequirementsMetrics and KRIs Definition
Soft Skills
LeadershipCollaborationCommunication
Tools & Technologies
TPRM PlatformsContinuous Monitoring ToolsSecurity-Rating Tools
Certifications & Qualifications
SOC 2PCI DSS
Industry Keywords
Information SecurityIT RiskGRCVendor ConcentrationIncident Response
About the role
Key responsibilities & impact- Own strategy, design, and continuous improvement of the Third-Party/Vendor Risk Management (TPRM) program
- Define and maintain TPRM policy, standards, procedures, and risk-tiering methodology
- Establish third-party risk appetite and tolerance thresholds with CISO and GRC leadership
- Embed risk gates within sourcing, onboarding, contracting, renewal, and offboarding
- Lead the full vendor risk lifecycle: intake, inherent-risk classification, due diligence, residual-risk determination
- Operationalize inherent-risk tiering to scope assessment depth and cadence
- Direct security, privacy, and resilience assessments using methodologies such as SIG/Shared Assessments
- Evaluate fourth-party/Nth-party dependencies, vendor concentration, and systemic risk
- Establish and lead risk reviews for third-party AI/GenAI tooling
- Coordinate third-party incident response with SOC/IR
- Manage the third-party risk register and findings inventory
- Develop a standardized library of contractual security requirements
- Define and report outcome-driven metrics and KRIs
Requirements
What you’ll need- 8+ years in information security, IT risk, or GRC
- 4+ years focused on third-party/vendor risk management
- 2+ years of direct people leadership managing analysts or a risk team
- Strong working knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS
- Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test reports)
- Hands-on experience with TPRM/GRC platforms and continuous monitoring/security-rating tools
- Experience partnering with Procurement and Legal on vendor contracting and security/privacy terms
- Bachelor’s degree in a related field or equivalent professional experience
Benefits
Comp & perks- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Professional development opportunities