AllSTEM Connections is actively recruiting on behalf of one of our valued clients—a leading organization known for innovation and excellence in the digital product space. We are excited to share this opportunity with professionals who are passionate about design systems, user experience, and collaborative product development. If the role aligns with your background and career goals, we encourage you to apply and take the next step toward joining a dynamic and forward-thinking team.
Position Title –Third Party Risk Manager
Hourly Pay Rate (w2 Role) - USD 85/hr - USD 94/hr
Contract End Date -4/9/2027
Hybrid Schedule /Onsite 2 days per week
Location -Plainsboro, NJ 08536
Position Summary
Collaboration with third parties is of strategic value to our organization. This collaboration includes the exchange of confidential information and personal data, and the outsourcing of digital services. Trust and assurance are critical factors in the relationship between our Digital, Data & AI team and its partners and suppliers. This requires the assessment of their capabilities with respect to security, compliance, quality, and risk management.
The TPCRM Risk Manager is responsible for organizing and driving activities around third-party cyber risk management, security, and audits. This role requires a mix of business and technical acumen to influence and communicate with stakeholders across the enterprise. The role also involves creating awareness and educating stakeholders on TPCRM security, while acting as an important link in establishing trusted relationships between our organization and its partners and suppliers — ensuring that the company remains in control of critical data within an increasingly complex security threat landscape.
Primary Responsibilities
Security
- Develop and update TPCRM security standards and documentation
- Continuously assess TPCRM security risks based on an inventory of the vendor landscape and associated risks
- Develop TPCRM security metrics and requirements
- Examine and select tools and techniques to continuously monitor and report on third-party security risks
- Support the management of information security risks throughout the duration of supplier relationships, including communication and metrics reporting
- Support operations of the third-party cyber risk management program
- Ensure alignment with the Danish NIS2 Act by end of 2026
- Ensure all new TPCRM suppliers are assessed by end of 2026
- Ensure all critical or high residual risk TPCRM suppliers are reassessed by end of 2026
- Evaluate the security assurance statements of critical suppliers
- Update, align, and deploy current vendor and TPCRM security requirements in alignment with Procurement, Corporate Compliance, Legal, Privacy, and QA
Audit
- Develop and deploy cyber risk audit as a service by end of 2026
- Develop and maintain strong working relationships with leaders in Digital & AI, Legal, and Global Procurement departments
- Stay ahead of new developments in security and data protection regulations
- Develop and manage the framework and timeline for performing regular audits and the assessment of assurance reports
- Define audit priorities and activities for short-term (one year) and long-term (three year) periods based on the current vendor landscape
- Execute the audit calendar and integrate results into an integrated dashboard
General
- Independently conduct activities related to assigned projects, including implementation of security controls, risk assessments, security risk management processes, risk awareness activities, and maintenance of local networks
- Lead the setup and optimization of security management processes for internal customers
- Participate in project teams, panels, technological platforms, and meetings while maintaining close contact with cross-functional teams
- Guide business teams in relation to security needs and issues
- Guide and mentor newer team members in security systems, processes, and controls
Required Qualifications
Education
- Bachelor's Degree in Computer Science, Management Information Systems (MIS), or a related field
- Equivalent combination of relevant work experience and training will be considered
E_xperience_
- Minimum 5 years of experience in TPCRM, information security, and risk management
- Experience in a Pharma, Biotech, or Healthcare company is preferred; experience in other heavily regulated industries such as Finance is also acceptable
- Active certification in CISA, CRISC, CISM, CISSP, or a relevant equivalent
- Experience working with security and risk management frameworks and regulations including ISO, NIST, GDPR, SOX, and HIPAA
- Experience working with GRC tools such as ServiceNow, Galvanize, Vanta, MetricStream, Archer, or WolfPAC
- Experience in defining and implementing security management processes and controls
- Experience in setting up a TPCRM security improvement roadmap and driving the implementation of corresponding actions and processes
- Experience working in multinational organizations and global virtual teams
- Good understanding of current and emerging cybersecurity and privacy regulations and practices
Knowledge and Skills
- Excellent understanding of vendor management processes and related assurance frameworks including SOC 1 and SOC 2 Type I and Type II audits and auditor reports
- Good knowledge of regulatory compliance frameworks applicable to multinational organizations including FISMA, GDPR, NIST, and GxP
- Strong business acumen with domain-specific knowledge of Pharma or Biotech environments
- Ability to proactively identify and resolve risks by collaborating across multiple teams
- Ability to foster strong relationships with colleagues and business leaders to enable risk mitigation through effective communication of TPCRM risk status to key stakeholders
- Experience leading and contributing to risk assessments, security improvements, and audit remediations
- Ability to support alignment of security operations to policies, standards, and procedures
- Experience contributing to, maintaining, and reporting on Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs)
- Excellent communication skills to connect effectively with different stakeholders across the organization
- Strong ethical standards and willingness to go the extra mile to achieve important goals
- Experience tracking, measuring, and communicating the quality of risk management processes and controls applicable to the IT department
- Strong interpersonal skills including teamwork, facilitation, and negotiation
- Excellent analytical and technical skills
- Excellent written, verbal, and presentation skills
- Excellent planning and organizational skills with strong attention to detail
Pay: $85.00 - $94.00 per hour
Work Location: Hybrid remote in Plainsboro, NJ 08536