Skip to content
Gong logo

Senior TPRM Security Lead

GongRevenue Intelligence company
Austin, United States$117,000 - $185,000 USDSenior
Norwest Venture Partners logo
Norwest Venture Partners
Wing Venture Capital
NextWorld Capital
Coatue logo
Coatue
Index Ventures logo
Index Ventures
Salesforce Ventures logo
Salesforce Ventures
Legal & Compliance

About the role

TL;DR

Own and mature Gong's third-party risk management program, ensuring vendor compliance with security and privacy standards.

  • Gong is seeking an experienced Third Party Risk Manager to join our Governance, Risk, and Compliance (GRC) team.
  • In this role, you will own and mature Gong's third-party risk management program, ensuring that vendors, suppliers, and partners meet our security, privacy, compliance, and operational resilience standards.
  • Key Responsibilities Own the end-to-end third-party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.
  • Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality.
  • Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements.
  • Manage continuous monitoring of the vendor portfolio, including periodic reassessments, tiering, and tracking of remediation items.
  • Report on third-party risk posture, key metrics, and trends to GRC leadership and relevant stakeholders.
  • Requirements 7+ years of experience in third-party/vendor risk management, GRC, information security, or a related field.
  • Strong working knowledge of security and compliance frameworks (SOC 2, ISO 27001, NIST) and data privacy regulations.
  • Experience conducting vendor risk assessments and interpreting security documentation (e.g., SOC 2 reports, pen test results, questionnaires).
  • Excellent cross-functional collaboration and communication skills, with the ability to translate risk into business terms.
  • Experience with TPRM tooling (e.g., Zip).
View original posting →

Required skills

SOC 2GDPRVendor ManagementContract ManagementCompliance Management

Benefits & perks

Medical, Dental, Vision, Wellbeing Fund, Mental Health benefits, 401(k), Education & learning stipend, Flexible vacation time, Paid parental leave, Company-wide recharge days, Work from home stipend

Tech stack

SOC 2GDPRGitLinuxJiraConfluencePythonJavaScriptSQLBashOAuthJWTSAMLOWASPVaultIAMSSOMFA

Similar jobs

Anthropic logo

Safety & Security Counsel

Anthropic logo

Safety & Security Counsel, EMEA

Anthropic logo

Safeguards Policy Analyst, Cyber Harms