Skip to main content

Manager, Third Party Risk Management (Remote)

RemoteUnited States only
Published
Role
Unknown
Experience
Senior
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

CrowdStrike is seeking an experienced Manager, Third Party Risk Management (TPRM) to lead a team of four TPRM analysts. This role oversees the full vendor risk lifecycle, drives program improvements with automation and AI integration, and partners with cross-functional teams. The ideal candidate has deep expertise in vendor risk, GRC, and ServiceNow, and a proven ability to lead and develop teams.

Core skills

third party risk management/vendor risk assessment/risk lifecycle managementGRC

Required skills

ServiceNow TPRMNIST CSFISO 27001SOC 2NIST 800-53SIGAI/ML tools

Optional skills

Cloud environmentCrowdStrike products or servicesSoftware Development and Secure Coding best practicesIntegration risk assessmentsThreat modeling third party software componentsGRC products

Required languages

English native or bilingual proficiency

What you'll do

  • Lead, mentor, and developing a team of 4 TPRM professionals, fostering a culture of accountability, continuous learning, and operational excellence
  • Oversee end-to-end third-party risk assessments including inherent risk tiering, due diligence, control evaluations, and residual risk determinations
  • Manage the full vendor risk lifecycle including onboarding, periodic reassessment, and offboarding
  • Partner with Procurement, Legal, IT, Security, and Business stakeholders to embed risk considerations
  • Evaluate vendor security posture, compliance certifications (SOC 2, ISO 27001, etc.), and contractual obligations
  • Define and track KPIs and metrics to demonstrate program maturity and effectiveness
  • Lead implementation of process improvements and automation initiatives in ServiceNow TPRM
  • Evaluate emerging technologies and vendor risk intelligence platforms to enhance the program
  • Develop and maintain TPM policies, standards, and procedures aligned with industry frameworks (NIST, ISO 27001, SOC 2, FAIR, etc.)
  • Prepare and present risk reporting and program status updates to senior leadership
  • Support internal and external audit activities related to third-party risk

What they require

  • 10+ years of experience in Third Party Risk Management, GRC, information security risk, or related controls disciplines
  • 3+ years of people management experience with demonstrated ability to lead and develop teams
  • Deep expertise in vendor risk assessment methodologies, control frameworks, and risk lifecycle management
  • Hands-on experience with ServiceNow Third Party Risk Management (TPRM) module
  • Demonstrated experience driving process improvement, automation, or operational efficiency initiatives
  • Strong understanding of security and compliance frameworks: NIST CSF, ISO 27001, SOC 2, NIST 800-53, SIG
  • Experience with or strong interest in applying AI/ML tools to GRC or risk management workflows
  • Excellent communication and stakeholder management skills to translate technical risk concepts for business audiences
  • Ability to operate effectively in a fast-paced, high-growth environment
  • Proven experience working across teams and global regions
  • Ability to build relationships across functions, with external vendors, and with governmental teams
  • Program and project management experience in scoping, work breakdown, critical path analysis, resourcing, and risk
  • Ability to think strategically about risks and tie to tactical activities

Benefits

  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed - we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward.

On Premises Data Centers
Salary not disclosed