Gong logo

Senior TPRM Security Lead

Gong

New York, NYFull-time$117–185K/yrPosted 3w agoVerified open 5 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$117–185K/yr
Location
New York, NY
Schedule
Full-time
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

CTPRPCISACISSPCRISC

Job overview

Gong is hiring a Senior TPRM Security Lead. Gong seeks an experienced third‑party risk manager to own and mature its TPRM program, establishing baselines, applying risk‑based vendor reviews, and partnering cross‑functionally with procurement, legal, security, and privacy to assess and mitigate vendor risks across the lifecycle.

Key focus areas include Own the end‑to‑end third‑party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and off‑boarding., Establish baselines and controls to reduce and manage third‑party risk across the vendor portfolio., and Apply a risk‑based approach to vendor reviews, tiering vendors and scaling due diligence depth based on risk..

Successful candidates bring 7+ Years Experience In Third-Party/Vendor Risk Management, GRC, Information Security, Or Related Field, CTPRP, and CISA. Important skills include Privacy Regulations, Penetration Testing, CISA, Third-Party Risk Management, Cybersecurity, and Establish Baselines And Controls. Preferred (not required): Risk Management, NIST, GRC, and Information Security.

Skills & qualifications

RequiredNice to have

Skills

Privacy RegulationsPenetration TestingCISARisk ManagementNISTGRCInformation SecurityCISSPCross-Functional Team LeadershipISO 27001ComplianceSOC 2Third-Party Risk ManagementCybersecurityEstablish Baselines and ControlsRisk-Based Approach to Vendor ReviewsGDPRCCPAVendor Risk AssessmentsInterpreting Security DocumentationCollaborationCommunication SkillsTranslate Risk Into Business TermsZip

Qualifications

7+ Years Experience in Third-Party/Vendor Risk Management, GRC, Information Security, or Related FieldCTPRPCISACISSPCRISC

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Parental Leave
Paid Time Off

Full job description

Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world’s most successful revenue teams. Powered by the Gong Revenue Graph, AI-powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort. For more information, visit www.gong.io.

At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.

Gong is seeking an experienced Third Party Risk Manager to join our Governance, Risk, and Compliance (GRC) team. In this role, you will own and mature Gong's third-party risk management program, ensuring that vendors, suppliers, and partners meet our security, privacy, compliance, and operational resilience standards. You will establish baselines and controls that Gong can implement to proactively address third-party risk, and apply a risk-based approach to vendor reviews—prioritizing effort based on the criticality, data access, and inherent risk of each vendor. You will build a program that is robust and scalable, evolving to meet the business's needs as Gong grows. You will partner cross-functionally with Procurement, Legal, Security, Privacy, and business stakeholders to assess, monitor, and mitigate risks across the full vendor lifecycle. This role will report directly into the Head of GRC and operate both strategically and very hands-on.

RESPONSIBILITIES

  • Own the end-to-end third-party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.

  • Establish baselines and controls that Gong can implement to reduce and manage third-party risk across the vendor portfolio.

  • Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality.

  • Build a robust and scalable TPRM program that adapts to evolving business needs and supports Gong's growth.

  • Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements.

  • Partner with Procurement and Legal to embed risk requirements into contracts, data processing agreements, and vendor onboarding workflows.

  • Maintain and enhance the TPRM framework, policies, standards, and procedures in alignment with frameworks such as SOC 2, ISO 27001, and relevant privacy regulations (e.g., GDPR, CCPA).

  • Manage continuous monitoring of the vendor portfolio, including periodic reassessments, tiering, and tracking of remediation items.

  • Administer and optimize TPRM tooling and automation to scale the program.

  • Report on third-party risk posture, key metrics, and trends to GRC leadership and relevant stakeholders.

  • Support audit and customer assurance activities related to third-party risk.

  • Experience handling security agreements between vendors - and holding vendors accountable to such agreements.

QUALIFICATIONS

  • 7+ years of experience in third-party/vendor risk management, GRC, information security, or a related field.

  • Demonstrated ability to establish baselines and controls and take a risk-based approach to vendor reviews.

  • Strong working knowledge of security and compliance frameworks (SOC 2, ISO 27001, NIST) and data privacy regulations.

  • Experience conducting vendor risk assessments and interpreting security documentation (e.g., SOC 2 reports, pen test results, questionnaires).

  • Excellent cross-functional collaboration and communication skills, with the ability to translate risk into business terms.

  • Experience with TPRM tooling (e.g., Zip).

  • Relevant certifications (e.g., CTPRP, CISA, CISSP, CRISC) are a plus.

PERKS & BENEFITS

  • We offer Gongsters a variety of medical, dental, and vision plans, designed to fit you and your family’s needs.

  • Wellbeing Fund - flexible wellness stipend to support a healthy lifestyle.

  • Mental Health benefits with covered therapy and coaching.

  • 401(k) program to help you invest in your future.

  • Education & learning stipend for personal growth and development.

  • Flexible vacation time to promote a healthy work-life blend.

  • Paid parental leave to support you and your family.

  • Company-wide recharge days each quarter.

  • Work from home stipend to help you succeed in a remote environment.

The annual salary hiring range for this position is $117,000 - $185,000 USD.

Compensation is based on factors unique to each candidate, including, but not limited to, job-related skills, qualification, education, experience, and location. At Gong, we have a location-based compensation structure, which means there may be a different range for candidates in other locations. The total compensation package for this position, in addition to base compensation, may include incentive compensation, bonus, equity, and benefits. Some of our sales compensation programs also offer the potential to achieve above targeted earnings for those who exceed their sales targets.

We are always looking for outstanding Gongsters! So if this sounds like something that interests you regardless of compensation, please reach out. We may have more roles for you to consider and would love to connect.

We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Gong recruiting email communications will always come from the @gong.io domain. Any outreach claiming to be from Gong via other sources should be ignored.

Gong is an equal-opportunity employer. We believe that diversity is integral to our success, and do not discriminate based on race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, military status, genetic information, or any other basis protected by applicable law.

To review Gong's privacy policy, visit https://www.gong.io/gong-io-job-candidates-privacy-notice/ for more details.

#LI-SM1

You've read the whole posting — now see how you match it.

Senior TPRM Security Lead at Gong | Olive Jobs