FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Cybersecurity TPRM Strategy and Governance SME
Hewlett Packard Enterprise. Define and advance the organization's third-party cybersecurity risk management strategy, operating model, and governance framework .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Expertise in developing and managing Third-Party Cybersecurity Risk Management strategies, frameworks, and governance models, with a strong focus on regulatory compliance and operational resilience. Proven ability to lead strategic initiatives, optimize processes, and provide executive-level reporting on cybersecurity risks and program effectiveness.
Highest-signal resume keywords
Third-Party Risk Management (TPRM)Cybersecurity GovernanceNIST CSFCISSP CertificationRegulatory Compliance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cybersecurity Risk ManagementFramework DevelopmentRisk AssessmentProcess OptimizationMetrics and KPIs EstablishmentRegulatory Requirements TranslationGRC Platform ImplementationVendor Risk AssessmentOperational ResilienceCybersecurity Standards Knowledge
Soft Skills
Analytical SkillsCommunication SkillsStakeholder ManagementExecutive Presentation SkillsMentoring
Tools & Technologies
OneTrustArcherServiceNow
Certifications & Qualifications
CISSPCISMCRISCCISA
Industry Keywords
Supply Chain SecurityCybersecurity RegulationsDORANIS2GDPRSEC Cybersecurity Rules
Tech Stack
Tools & technologiesCloudCyber SecurityServiceNow
About the role
Key responsibilities & impact- Define and advance the organization's third-party cybersecurity risk management strategy, operating model, and governance framework
- Develop and maintain the enterprise Cybersecurity Third-Party Risk Management strategy and operating model
- Define and continuously improve third-party risk-based frameworks, methodologies, standards, and procedures
- Lead the evolution of vendor criticality, inherent risk, residual risk, and due diligence frameworks
- Identify opportunities to streamline, automate, and optimize TPRM processes
- Partner with Procurement, Legal, Compliance, Privacy, Supply Chain, IT, and business stakeholders
- Establish metrics, KPIs, and reporting frameworks to measure program effectiveness, risk exposure, and operational performance
- Provide thought leadership on supply chain security, software supply chain risk, cloud providers, AI-related risks, and operational resilience
- Lead assessments of TPRM tools and technology solutions and drive automation and workflow improvements
- Develop executive-level reporting and presentations on program maturity, risks, and strategic initiatives
- Support enterprise-wide regulatory compliance, cybersecurity governance, and operational resilience initiatives
- Provide guidance and mentoring to less-experienced staff members
Requirements
What you’ll need- Bachelor's or Master's degree in Engineering, Computer Science, Information Security or equivalent
- Typically 6–10 years of experience
- Security certifications preferred: CISSP, CRISC, CISM, etc.
- Demonstrated experience and in-depth knowledge designing or managing TPRM programs, frameworks, and governance models
- Solid knowledge and demonstrated experience of cyber and IT security risks, threats, and prevention measures
- Strong knowledge and demonstrated experience with NIST CSF, NIST 800-53, ISO 27001, and industry best practices
- Knowledge and experience of security fundamentals and technologies
- Experience translating regulatory and security requirements into scalable policies, standards, and operational processes
- Experience leading strategic initiatives, process transformation, and organizational change
- Industry certifications such as CISSP, CISM, CRISC, CISA, or equivalent
- Experience implementing or optimizing TPRM or GRC platforms, including OneTrust, Archer, and ServiceNow
- Knowledge of global regulatory requirements, including DORA, NIS2, GDPR, SEC Cybersecurity Rules, and supply chain cybersecurity regulations
- Strong analytical, communication, stakeholder management, and executive presentation skills
- Excellent written and verbal communication skills; mastery in English
Benefits
Comp & perks- Comprehensive suite of benefits supporting physical, financial, and emotional wellbeing
- Personal and professional development programs
- Career development opportunities
- Flexible work arrangements to manage work and personal needs
- Inclusive workplace culture
- Reasonable accommodation during the application or interview process for applicants with disabilities