Senior Tprm Security Lead

Gong Gong · Enterprise · San Francisco, CA · Information Security

Gong is seeking an experienced Third Party Risk Manager to own and mature their third-party risk management program, ensuring vendors meet security, privacy, compliance, and operational resilience standards. The role involves establishing baselines and controls, applying a risk-based approach to vendor reviews, and partnering cross-functionally to manage risks across the vendor lifecycle. This role reports to the Head of GRC and requires both strategic and hands-on involvement.

What you'd actually do

  1. Own the end-to-end third-party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.
  2. Establish baselines and controls that Gong can implement to reduce and manage third-party risk across the vendor portfolio.
  3. Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality.
  4. Build a robust and scalable TPRM program that adapts to evolving business needs and supports Gong's growth.
  5. Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements.

Skills

Required

  • 7+ years of experience in third-party/vendor risk management, GRC, information security, or a related field.
  • Demonstrated ability to establish baselines and controls and take a risk-based approach to vendor reviews.
  • Strong working knowledge of security and compliance frameworks (SOC 2, ISO 27001, NIST) and data privacy regulations.
  • Experience conducting vendor risk assessments and interpreting security documentation (e.g., SOC 2 reports, pen test results, questionnaires).
  • Excellent cross-functional collaboration and communication skills, with the ability to translate risk into business terms.
  • Experience with TPRM tooling (e.g., Zip).

Nice to have

  • Relevant certifications (e.g., CTPRP, CISA, CISSP, CRISC) are a plus.

What the JD emphasized

  • security, privacy, compliance, and operational resilience standards
  • risk-based approach to vendor reviews
  • robust and scalable TPRM program
  • security, privacy, compliance, financial, and operational domains
  • SOC 2, ISO 27001, and relevant privacy regulations
  • continuous monitoring of the vendor portfolio
  • TPRM tooling and automation
  • audit and customer assurance activities related to third-party risk
  • security agreements between vendors
  • SOC 2, ISO 27001, NIST
  • security documentation (e.g., SOC 2 reports, pen test results, questionnaires)