Назад
5 дней назад

Technical Program Manager, Third Party Risk Management

157 000 - 210 000$
Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Technical Program Manager, Third Party Risk Management (Cloud Security/GRC): Building and maturing third-party risk management programs across the vendor lifecycle with an accent on security risk assessments, control evaluation, compliance documentation, and remediation tracking. Focus on maintaining vendor risk records, refining assessment workflows, and coordinating complex security and privacy requirements across engineering, procurement, IT, Legal, and external vendors.

Location: Livingston, NJ; New York, NY; Sunnyvale, CA; or Bellevue, WA

Base salary: $157,000–$210,000 per year, plus discretionary bonus, equity awards, and benefits.

Company

CoreWeave provides cloud infrastructure, technology, and services that help AI labs, startups, and enterprises build and scale AI applications.

What you will do

  • Contribute to the third-party risk management strategy and roadmap in alignment with security, privacy, and business objectives.
  • Execute third-party security risk assessments by reviewing security controls, contract requirements, questionnaires, audit reports, and compliance evidence.
  • Track risk findings and remediation plans to closure with vendors and internal owners.
  • Perform tier-based reassessments of existing vendors and maintain the vendor inventory and risk register in the TPRM platform.
  • Refine assessment questionnaires, workflows, and program documentation.
  • Coordinate communication across engineering, procurement, IT, Legal, vendors, and business stakeholders.

Requirements

  • At least 2 years of hands-on experience in third-party risk management, including building or maturing a TPRM program.
  • Bachelor’s degree in Information Security, Computer Science, or a related field, or equivalent experience.
  • Security certification such as CISA, CRISC, CISSP, or CTPRP.
  • Knowledge of security control frameworks and standards, with experience evaluating compliance documentation and identifying control gaps.
  • Experience supporting third-party security assessments, tracking remediation, and maintaining records in a GRC or TPRM platform.
  • Applicants must satisfy U.S. export-control access requirements for controlled information.

Nice to have

  • Experience working with cloud service providers or hyperscalers.
  • Experience improving TPRM processes or building a program from the ground up.
  • Familiarity with security and privacy requirements in vendor contracts.
  • Experience supporting audits, certifications, or customer security inquiries.

Culture & Benefits

  • Full-time employee benefits include medical, dental, and vision insurance fully paid by CoreWeave.
  • Additional benefits include life and disability insurance, FSA, HSA, tuition reimbursement, ESPP, mental wellness support, family-forming support, parental leave, and childcare support.
  • 401(k) with an employer match and flexible PTO.
  • Catered lunches at office and data center locations.
  • Casual work environment focused on innovative disruption.

Hiring process

  • Compensation is determined based on qualifications, experience, interview performance, and market location.
  • Reasonable accommodations are available for qualified applicants with disabilities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →