Senior Risk Advisor
Jobot Consulting · New York, NY · 4 days ago
On-siteSales$70–$90/hrContract
About Us
We are a well-established, global organization with a diverse portfolio of businesses spanning media, information services, technology, and digital products. Our teams support a broad range of recognized brands and business units, creating an environment that combines the resources and stability of a large enterprise with the variety and complexity of a multi-business organization. Technology plays a critical role in how our businesses operate, innovate, and serve their audiences and customers. Our Governance, Risk & Compliance organization partners closely with business and technology leaders to strengthen decision-making, manage emerging risks, and build scalable programs that support responsible growth.
Why Join Us?
- Enterprise-level impact: Advise leadership and influence risk decisions across a large and highly diverse organization.
- Meaningful ownership: Lead complex risk assessments and help shape how material risks are evaluated, escalated, and addressed.
- Program-building opportunity: Contribute directly to the continued growth and maturity of an enterprise third-party risk management program.
- Exposure to emerging risks: Work on evolving areas such as artificial intelligence governance, automation, data risk, and emerging technologies.
- High visibility: Partner with senior business, technology, procurement, security, and governance stakeholders.
- Varied and challenging work: Support multiple businesses, technologies, and operating models rather than working within a single narrow environment.
- Established organization with room to innovate: Join a stable, respected enterprise while helping modernize and scale its risk management capabilities.
- Collaborative environment: Work with experienced professionals who value thoughtful risk management, practical recommendations, and strong business partnership.
Responsibilities
- Advise senior leadership on enterprise risk posture, business tradeoffs, risk treatment options, and risk acceptance decisions.
- Provide clear, practical recommendations that balance security, operational, regulatory, and business priorities.
- Identify systemic, emerging, and cross-functional risks and influence related prioritization and investment decisions.
- Lead enterprise risk assessments and gap assessments across business processes, applications, technologies, and infrastructure.
- Manage assessments from initial scoping and stakeholder engagement through findings, treatment planning, and closure.
- Own the escalation of material risks and provide recommendations regarding remediation, mitigation, transfer, or formal acceptance.
- Maintain the enterprise risk register and ensure risks, owners, response plans, and target dates remain accurate and current.
- Track remediation activities, follow up with accountable stakeholders, and drive progress toward closure and SLA adherence.
- Incorporate risk data into recurring reporting, executive metrics, dashboards, and risk-focused governance forums.
- Support and help drive the third-party risk management program across vendor onboarding, reassessment, renewal, and offboarding.
- Conduct and contribute to vendor risk assessments across the third-party lifecycle.
- Advise business owners, procurement teams, technology leaders, and other stakeholders on third-party risk decisions.
- Support the escalation and remediation of material vendor risks.
- Identify opportunities to strengthen TPRM processes, improve consistency, and increase overall program maturity.
- Explore opportunities to improve risk management scalability through analytics, automation, and artificial intelligence.
Requirements
- Bachelor’s degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Business Administration, or a related discipline. Equivalent professional experience may be considered in place of formal education.
- Seven or more years of experience in risk management, including meaningful risk advisory, leadership, or enterprise assessment responsibilities.
- Advanced understanding of enterprise risk management principles and experience advising leadership on risk posture, tradeoffs, treatment strategies, and acceptance decisions.
- Demonstrated experience conducting third-party or vendor risk assessments throughout the vendor lifecycle.
- Experience supporting, operating, or helping to advance a third-party risk management program.
- Strong executive communication skills, including the ability to translate complex risk information into clear recommendations for senior leaders and governance committees.
- Experience producing concise risk documentation, executive reporting, metrics, and formal assessment findings.
- Working knowledge of security, privacy, and risk frameworks such as NIST Cybersecurity Framework, NIST 800-53, PCI DSS, HIPAA, or SOC 2.
- Familiarity with GRC and vendor risk platforms such as TruOps, Prevalent, OneTrust, ProcessUnity, or ServiceNow.
- Strong stakeholder management skills and the ability to influence risk decisions across a federated or matrixed organization.
- Ability to manage competing priorities, navigate ambiguity, and drive accountability across multiple business and technology groups.
Preferred Qualifications
- CRISC, CISA, PMI-RMP, CTPRP, CTPRA, CISM, CISSP, or a related risk or security certification.
- Experience building, formalizing, or maturing a third-party risk management program.
- Experience working within a federated, matrixed, decentralized, or multi-business enterprise.
- Familiarity with artificial intelligence governance, responsible AI practices, or emerging technology risk.
- Experience supporting risk committees, governance councils, steering committees, or other executive-level forums.
- Experience applying analytics, automation, or AI to improve risk identification, assessment, monitoring, or reporting.
Pay
$70 - $90 per hour