About this role
Welcome to Aventiv! Please watch this brief video to find out if this is the place you want to be!
Aventiv Technologies – Where your future awaits - YouTube
**Associate Referral Reward Eligible**
Job Purpose: Responsible for overseeing the Third-Party Risk Management Program (TPRM) including projects and initiatives. Collaborate, Influence cross-functional partnerships across the enterprise to guide the business of third-party cyber risk management.
Essential Duties:
- Manage and maintain a comprehensive TPRM framework and roadmap
- Track, and measure third-party cyber risk management roadmap with risk prioritization
- Design, implement and maintain a consistent approach to all third-party risk to understand inherent risk, residual risk, gaps, and track mitigations
- Identify, prioritize, and pursue opportunities to enhance TPRM processes with innovative approaches and solutions to optimize efficiency and effectiveness.
- Assess and monitor the TPRM lifecycle activities (risk assessment & due diligent, contract negotiation, ongoing monitoring, and termination)
- Establish relevant TPRM policy and procedures
- Lead the implementation and continued deployment of the TPRM module within the GRC tool
- Assess TPRM controls against regulatory requirements such as PCI, HIPAA, SOC2, NYDFS, privacy, etc. to identify gaps and ensure alignment
- Collaborate with the business, legal, and procurement to ensure gaps identified in the TPRM areas are corrected, remediated, and monitored
- Drive integration of the TPRM processes into the business and other risk verticals to extend the program to these and other areas
- Provide and manage monthly reporting activity and analyzing metrics for performance TPRM program
- Provide TPRM training, guidance, and support to all internal customers (e.g. business units, legal, procurement, etc.) and TPRM team members
- Leverage industry-leading practices and trends to provide valuable risk insights to senior management
- Other Duties as Assigned
Knowledge, Skills, and Abilities:
- Deep understanding of cybersecurity risk management processes
- SME with compliance regulations/laws, security frameworks, and standards (e.g. PCI-DSS, FISMA, NIST, HIPAA, ISO, COBIT, CCPA, HITRUST, etc.)
- Strong project management skills and ability to manage multiple projects
- Ability to exercise and mentor others on good professional judgment and security-related ethics
- Strong attention to detail and highly results oriented.
- Excellent communication skills and ability to influence and guide others.
- Build and maintain ongoing business relationships with strong interpersonal and communication skills.
- Other duties as assigned.
Minimum Qualifications:
- 10+ years of direct functional knowledge and experience in Third-Party Risk management and contractual arrangements
- HS Diploma or GED
- Direct functional knowledge and experience in TPRM and contractual arrangements
- Process design and process improvement experience
- Experience in data gathering, analysis, and problem-solving skills.
- Experience with Shared Assessments Standard Information Gathering Questionnaire (SIG) and processes.
- Professional certification: with at least one of the following, CISM, CISA, CRISC, CTPRP, CTPRA, CDPSE
Preferred Qualifications:
- Bachelors' degree or equivalent work experience in a related discipline
- Strong knowledge of various data protection legislation
- Professional certification: CISSP with at least one of the following, CISM, CISA, CRISC, CTPRP, CTPRA, CDPSE
Physical Requirements:
- While performing the duties of this job, the employee is regularly required to: stand, sit, talk, hear, and use hands and fingers to operate a computer, telephone, and a variety of office equipment.
- Occasionally, this position may need to reach, stoop, or kneel.
Salary and Benefits:
At Aventiv, our salary and benefits are designed to fit you as a whole person. We offer a salary range based on experience and qualifications to ensure your unique contributions are met with our most competitive offer.
- $102,555.53- $116,913.30 per year
- Eligible for $255 to purchase company equipment (keyboard, monitor, headset, etc.
- Health Insurance
- 401(k)
- Disability
- Life Insurance
- Paid Time Off
- Voluntary Benefits
Aventiv Privacy Policy:
www.aventiv.com/privacy
Equal Employment Policy:
Aventiv is proud to be an equal opportunity employer. All decisions regarding recruiting, hiring, promotion, assignment, training, termination and other terms and conditions of employment will be made without regard to race, color, national origin, biological sex, sexual orientation, gender identity, gender expression, gender presentation, religion, age, pregnancy, disability, work-related injury, veteran status, genetic information, marital status, or any other factor that the law protects from employment discrimination. We do not discriminate based on genetic information in accordance with the Genetic Information Nondiscrimination Act.