HirePortal

Third Party Risk Management Manager

  • Auxis
  • Bogotá, Colombia, Colombia
  • COP 120,000,000 – COP 180,000,000

Job Summary

We are seeking an experienced Third-Party Risk Management (TPRM) Manager to lead and evolve our enterprise TPRM program. This role will drive TPRM strategy, operations, reporting, supplier incident management, M&A risk integration, and governance initiatives while ensuring effective execution of OneTrust assessments and BitSight operations. The ideal candidate will leverage automation, AI-enabled solutions, and innovative approaches to enhance efficiency, risk visibility, and decision-making. Strong leadership, stakeholder management, team development, and hiring experience are essential to build a high-performing TPRM function and deliver measurable business outcomes.

Responsibilities

· Lead and evolve the EMEA Third-Party Risk Management (TPRM) program, aligning strategy with regulatory, business, M&A, and InfoSec Supply Chain Risk Management objectives.

· Oversee end-to-end TPRM operations, including due diligence, risk assessments, reassessments, exception management, SLA performance, and operational scalability.

· Develop and deliver executive, regulatory, and operational reporting, providing actionable risk insights and ensuring data accuracy and traceability.

· Lead TPRM integration for M&A activities, including acquisition due diligence, supplier risk assessments, onboarding into TPRM frameworks, and Day-0/30/90 integration objectives.

· Own the supplier security incident management framework, coordinating breach response, impact assessments, remediation, and executive reporting.

· Drive AI, automation, and innovation initiatives to improve efficiency, decision-making, risk visibility, and operational effectiveness across TPRM processes.

· Own and optimize OneTrust TPRM workflows, assessments, questionnaires, control mappings, and platform integrations.

· Govern continuous supplier monitoring through BitSight and similar tools, driving risk-based supplier engagement, remediation, and executive reporting.

· Define, track, and continuously improve TPRM KPIs, KRIs, maturity metrics, and performance reporting.

· Build and lead a high-performing TPRM organization through hiring, workforce planning, mentoring, coaching, succession planning, and stakeholder engagement.

Skills and Experience

Required Qualifications

· 10+ years of experience in Third-Party Risk Management (TPRM), Supply Chain Risk Management, Information Security Risk, Governance, Risk & Compliance (GRC), or related cybersecurity functions.

· Demonstrated experience leading enterprise-scale TPRM programs, operations, and governance frameworks across multiple regions and business units.

· Strong expertise in supplier risk assessments, due diligence, risk reporting, incident management, and regulatory compliance requirements.

· Hands-on experience with OneTrust TPRM, third-party risk assessment methodologies, workflow configuration, and process optimization.

· Experience with continuous monitoring platforms such as BitSight and integrating security posture insights into risk management decisions.

· Proven leadership experience managing teams, driving organizational change, resolving complex stakeholder issues, and influencing executive-level decisions.

· Familiarity with AI tools, workflow automation platforms, and integrating AI into existing systems is preferred.

Preferred Qualifications

· Experience developing automation using Copilot or other Agentic AI frameworks

· Experience leading TPRM activities during mergers, acquisitions, divestitures, and integration programs.

· Knowledge of emerging risks including AI, cloud security, geopolitical risk, privacy, and evolving regulatory requirements.

· Experience implementing automation, AI-driven workflows, analytics, and operational transformation initiatives within TPRM or cybersecurity programs.

· Familiarity with enterprise risk frameworks and standards such as ISO 27001, NIST, SOC 2, PCI DSS, and privacy regulations.

· Experience collaborating with Procurement, Legal, Privacy, Internal Audit, and Enterprise Risk Management teams.

· Strong executive communication skills with a proven ability to present complex risk concepts to senior leadership, boards, and auditors.

Soft Skills

· Strong analytical and problem-solving skills with the ability to manage multiple priorities in a fast-paced environment.

· Experience working within multinational environments with complex IT asset landscapes.

· Attention to detail and accuracy.

· Strong problem-solving and analytical abilities.

· Ability to translate compliance requirements into technical controls.

· Commitment to continuous improvement and maturity enablement of the program.

Skills

  • Third-Party Risk Management
  • OneTrust
  • Bitsight
  • Vendor Risk Assessment
  • Supplier Incident Response
  • M&A Due Diligence
  • Risk Governance

Related jobs

AuxisApply for this job