Senior TPRM Security Lead
About the role
Gong is seeking an experienced Third Party Risk Manager to join our Governance, Risk, and Compliance (GRC) team. In this role, you will own and mature Gong's third-party risk management program, ensuring that vendors, suppliers, and partners meet our security, privacy, compliance, and operational resilience standards. You will establish baselines and controls that Gong can implement to proactively address third-party risk, and apply a risk-based approach to vendor reviews—prioritizing effort based on the criticality, data access, and inherent risk of each vendor. You will build a program that is robust and scalable, evolving to meet the business's needs as Gong grows. You will partner cross-functionally with Procurement, Legal, Security, Privacy, and business stakeholders to assess, monitor, and mitigate risks across the full vendor lifecycle. This role will report directly into the Head of GRC and operate both strategically and very hands-on.
Responsibilities
- Own the end-to-end third-party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.
- Establish baselines and controls that Gong can implement to reduce and manage third-party risk across the vendor portfolio.
- Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality.
- Build a robust and scalable TPRM program that adapts to evolving business needs and supports Gong's growth.
- Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements.
- Partner with Procurement and Legal to embed risk requirements into contracts, data processing agreements, and vendor onboarding workflows.
- Maintain and enhance the TPRM framework, policies, standards, and procedures in alignment with frameworks such as SOC 2, ISO 27001, and relevant privacy regulations (e.g., GDPR, CCPA).
- Manage continuous monitoring of the vendor portfolio, including periodic reassessments, tiering, and tracking of remediation items.
- Administer and optimize TPRM tooling and automation to scale the program.
- Report on third-party risk posture, key metrics, and trends to GRC leadership and relevant stakeholders.
- Support audit and customer assurance activities related to third-party risk.
- Experience handling security agreements between vendors - and holding vendors accountable to such agreements.
Qualifications
- 7+ years of experience in third-party/vendor risk management, GRC, information security, or a related field.
- Demonstrated ability to establish baselines and controls and take a risk-based approach to vendor reviews.
- Strong working knowledge of security and compliance frameworks (SOC 2, ISO 27001, NIST) and data privacy regulations.
- Experience conducting vendor risk assessments and interpreting security documentation (e.g., SOC 2 reports, pen test results, questionnaires).
- Excellent cross-functional collaboration and communication skills, with the ability to translate risk into business terms.
- Experience with TPRM tooling (e.g., Zip).
- Relevant certifications (e.g., CTPRP, CISA, CISSP, CRISC) are a plus.
Benefits
- We offer Gongsters a variety of medical, dental, and vision plans, designed to fit you and your family's needs.
- Wellbeing Fund - flexible wellness stipend to support a healthy lifestyle.
- Mental Health benefits with covered therapy and coaching.
- 401(k) program to help you invest in your future.
- Education & learning stipend for personal growth and development.
- Flexible vacation time to promote a healthy work-life blend.
- Paid parental leave to support you and your family.
- Company-wide recharge days each quarter.
- Work from home stipend to help you succeed in a remote environment.
Pay
The annual salary hiring range for this position is $117,000 - $185,000 USD. Compensation is based on factors unique to each candidate, including, but not limited to, job-related skills, qualification, education, experience, and location. At Gong, we have a location-based compensation structure, which means there may be a different range for candidates in other locations. The total compensation package for this position, in addition to base compensation, may include incentive compensation, bonus, equity, and benefits.