About this role
About the Role
We are looking for a TPRM Program Lead to own end-to-end delivery of a Third-Party Risk Management Managed Service for an enterprise client. Engagements typically span multiple risk domains — such as Cyber Security, Privacy (DPIA/DTIA/TOM), ESG, AI-Enabled Supplier Assessment, and Geopolitical Risk — depending on the client’s program scope. This is a delivery leadership role: you will coordinate a distributed team of specialist consultants and workstream leads, run the governance cadence with the client, own SLA/KPI performance, and be the single point of accountability when something needs to be resolved fast. You are not expected to run individual assessments yourself — you are expected to make sure the specialists who do are aligned, unblocked, and delivering to quality and on time.
This role owns orchestration, governance, and outcomes across the program. It does not include performing individual supplier assessments, screenings, or technical validation work — that sits with the workstream specialist consultants — nor does it include final commercial contract negotiation, which sits with the Client Partner.
Key Responsibilities
• Own end-to-end delivery of the TPRM managed service across all in-scope risk domains, ensuring consistent quality and adherence to agreed SLAs/KPIs
• Coordinate and manage the specialist consultant team — workload prioritization, cross-workstream dependencies, and day-to-day escalation triage
• Run the governance cadence: daily/weekly status calls, monthly operational meetings, Quarterly Business Reviews, and continuous-improvement/innovation forums
• Act as the primary escalation point for client stakeholders when workstream leads cannot resolve an issue directly
• Own consolidated SLA/KPI reporting and dashboards across workstreams, and present progress, risks, and remediation status to client leadership
• Drive process and platform improvement initiatives (e.g., GRC, TPRM, or ESG-rating platforms such as OneTrust or EcoVadis, or equivalent tools) in collaboration with the client’s platform/product owner teams
• Manage change control for scope changes, volume fluctuations beyond agreed tolerance, and any resulting commercial implications, in partnership with the Client Partner
• Own transition and knowledge-transfer planning at contract milestones, renewal, or exit
• Build and maintain a trusted, senior-level relationship with the client’s Program Sponsor, Service Delivery Manager, and Business Owners
What You’ll Need
• Bachelor’s degree in Business, Risk Management, Information Security, or a related field (Master’s a plus)
• 12–15 years of experience in third-party/supplier risk management, managed services delivery, or program management, including at least 6–8 years in a client-facing delivery leadership role
• Proven experience managing multi-domain compliance or risk programs at scale (200+ supplier portfolios)
• Working knowledge across TPRM domains relevant to the engagement — for example cyber security assessments, GDPR/privacy, ESG, geopolitical/sanctions risk, and AI governance — with deep expertise in at least one
• Experience running governance forums (QBRs, steering committees) and managing SLA/KPI-based service contracts
• Familiarity with GRC/TPRM platforms (e.g., OneTrust or equivalent)
• Excellent stakeholder management, executive communication, and escalation-handling skills
Nice to Have
• Experience within telecom, financial services, or another heavily regulated industry
• Prior experience mobilizing or transitioning a new managed service
• PMP, Prince2, or similar program management certification
• Exposure to large enterprise client governance frameworks in regulated sectors
Key Competencies
• Strategic ownership — thinks end-to-end across the program, not just a single workstream
• Strong people leadership — able to manage and develop a distributed, multi-disciplinary team
• Executive-level communication and presence with senior client stakeholders
• Comfortable being the escalation point and making judgment calls under pressure
• Continuous-improvement mindset for process and platform optimization