Ralph Lauren IT Third-Party Risk Management (TPRM) Manager
BoF Careers · Nutley, NJ · Yesterday
Information TechnologyFull-time
Essential Duties & Responsibilities
- Manage day-to-day execution of the Third-Party Risk Management program.
- Maintain and enhance TPRM policies, standards, procedures, and governance frameworks.
- Drive program maturity improvements, automation initiatives, and process optimization.
- Establish and monitor TPRM KPIs, KRIs, SLAs, and reporting metrics.
- Lead risk assessments of new and existing third-party providers.
- Review SIG questionnaires, SOC reports, ISO certifications, penetration testing reports, and other security documentation.
- Evaluate information security, privacy, compliance, operational, and resilience risks.
- Document findings, develop risk assessments, and provide recommendations for remediation.
- Facilitate risk acceptance, exception management, and escalation processes.
- Present significant third-party risks to senior leadership and governance committees.
- Ensure consistent application of risk-tiering methodologies and review requirements.
- Support audits, regulatory inquiries, and compliance initiatives.
- Serve as the primary point of contact for business stakeholders regarding third-party risk requirements.
- Partner with Procurement, Legal, Privacy, Architecture, Security Engineering, and business units throughout the vendor lifecycle.
- Provide guidance on security and compliance requirements during vendor onboarding and contract negotiations.
- Develop executive-level dashboards and reporting related to vendor risk posture, assessment volumes, remediation status, SLA performance, and program health.
- Track and report findings, remediation progress, and emerging third-party risks.
- Provide actionable insights to leadership to support informed risk decisions.
- Manage and mentor TPRM analysts and/or external consultants.
- Establish quality standards for risk assessments and deliverables.
- Promote a culture of accountability, operational excellence, and continuous improvement.
Experience, Skills & Knowledge
- Education: Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business Administration, Risk Management, or related field.
- Experience: 7+ years of experience in Information Security, IT Risk Management, Cybersecurity, Compliance, Internal Audit, or Third-Party Risk Management. 3+ years of experience managing TPRM programs or teams.
- Skills: Strong vendor risk assessment and risk analysis capabilities. Knowledge of cybersecurity, privacy, and regulatory requirements. Exceptional stakeholder management and communication skills. Strong reporting, metrics, and executive presentation skills.
- Experience: Experience evaluating security controls and industry standards such as ISO 27001, NIST, SOC 1, SOC 2, PCI DSS, and privacy regulations. Experience with GRC and TPRM platforms (e.g., OneTrust, ServiceNow, Archer, ProcessUnity, AuditBoard).
Preferred Qualifications
- CISSP, CISM, CRISC, CISA, CGEIT, or equivalent certification.
- Experience in retail, consumer products, or global enterprise environments.
- Experience implementing TPRM automation and workflow solutions.
- Knowledge of privacy regulations and data protection frameworks.