What are the responsibilities and job description for the 3rd Party Risk Management Consultant position at Amtex Systems Inc?
3rd Party Risk Management Consultant
Duration: 6 month contract
Location: 3 days in office, McKinney TX - Wednesday to Friday (Mon/Tues home)
JOB DETAILS
We are seeking a seasoned IT Security professional to lead and mature our Third-Party Risk Management (TPRM) program within the Governance, Risk & Compliance (GRC) function. This role is critical to ensuring our vendors and partners meet our security standards and regulatory requirements. The ideal candidate will bring deep expertise in TPRM, a strong understanding of GRC frameworks, and hands-on experience with platforms like AuditBoard or Archer.
Responsibilities
- Lead the end-to-end third-party risk assessment lifecycle, including onboarding, periodic reviews, and offboarding.
- Develop and maintain TPRM policies, procedures, and workflows aligned with regulatory and industry standards (e.g., PCI, NIST, ISO 27001, SOC 2).
- Conduct risk assessments and due diligence for new and existing vendors, identifying control gaps and recommending remediation.
- Collaborate with Procurement, Legal, and Business Units to ensure security requirements are embedded in contracts and vendor selection.
- Monitor and report on third-party risk metrics, trends, and compliance posture to senior leadership.
- Maintain and optimize GRC tools (AuditBoard, Archer) to support risk assessments, documentation, and reporting.
- Support internal and external audits related to third-party risk and overall GRC activities.
- Stay current with emerging threats, regulatory changes, and best practices in third-party risk and cybersecurity governance.
Qualifications
- Minimum 5 years of experience in Third-Party Risk Management within an IT Security or GRC function.
- Strong understanding of risk frameworks and regulatory requirements (e.g., CCPA, HIPAA, PCI-DSS, NIST).
- Hands-on experience with GRC platforms such as AuditBoard and Archer.
- Excellent analytical, communication, and stakeholder management skills.
- Ability to work independently and collaboratively in a fast-paced environment.
- Relevant certifications (e.g., CTPRP, CISA, CISSP, CRISC) are a plus.