Knowledge of information security concepts, practices, tools to effectively assess security risk, recommend risk mitigation activities, and communicate to the……
Bachelor’s degree in Computer Science, Information Technology, Risk Management, or a related technical field. Excellent written and verbal communication skills,……
Lead the design, implementation, and ongoing enhancement of the global TPRM programme, ensuring alignment with business objectives and regulatory requirements.…
You will not conduct the exploratory sales calls yourself. Provide a weekly update covering connections made, replies received, content shared, calls booked,……
Excellent communication skills with the ability to convey technical risk findings to non-technical stakeholders, including executives and procurement teams.…
The Information Security Risk Management Director is responsible for leading the design, implementation, and oversight of the organization’s information……
Recommend practical risk mitigation strategies, including compensating controls, secure design changes, and contractual safeguards to support risk-informed……
Bachelor’s degree in Risk Management, Finance, Business Administration, Accounting, or a related field required; advanced degree or professional certification,……
Bachelor’s degree in Risk Management, Finance, Business Administration, Accounting, or a related field required; advanced degree or professional certification,……
At the Manager level, this role operates with minimal supervision, significant independent judgment, and cross-functional influence, contributing to key……
Familiarity with Tanium (implementation/integration best practices). Manage vulnerability tooling and provide remediation guidance and debugging support via API……
Own and drive HealthDrive’s Third-Party Risk Management (TPRM) program end to end, including inbound and outbound security-questionnaire processes — assessing……
Own and drive HealthDrive’s Third-Party Risk Management (TPRM) program end to end, including inbound and outbound security-questionnaire processes — assessing……
Expertise in developing business and technical design specifications for ServiceNow platform implementations. BA/BS Degree in Computer Science, Cyber Security,……
Minimum seven years of experience in GRC, privacy, security, enterprise risk, or technology enablement with increasing management responsibility; experience……
The Senior Cyber Security Engineer provides technical leadership in the design, implementation, and operationalization of enterprise data security and data……
Build, lead, and develop a high performing team of third party risk professionals and technical reviewers. Strong technical fluency across cloud platforms, APIs……
Minimum 5 of years of technical architecture experience across multiple platforms — cloud infrastructure (AWS, Azure, or GCP), enterprise applications, data……
It calls on us to create lasting, positive change for our customers, our communities and our people. B etween 5 - 7 years of relevant experience and post-……
Manage TPRM leadership and governance committees, including preparing materials and helping to develop focused agendas that drive risk identification,……
Proven ability to strategically influence and develop strong relationships with senior executives, regulators, and cross-functional stakeholders.…
CISSP, CISM, CISA, or equivalent industry certification, preferred. With one direct report, the Cybersecurity Manager must be capable of operating independently……
This is a technical leadership role requiring knowledge of emerging AI tools, systems architecture and security practices in a regulated environment.…
These tools comply with local regulations, including bias audits, and we handle all personal data in accordance with state and local privacy laws.…
These tools comply with local regulations, including bias audits, and we handle all personal data in accordance with state and local privacy laws.…
Ability to develop senior level presentations in PowerPoint and leverage MS Excel to perform data analytics and develop reports that will provide insights to……
Orchestrate AI agents for evidence gathering, drift detection, and triage, with human-in-the-loop where assurance demands it. Vision plans via Vision Care.…
6+ years of experience in Information Security, Governance/Risk/Compliance, IT Audit, or a related field, including prior experience leading or mentoring team……
TPRM Governance, Operations, and Reporting Manager (Remote)
Winter Haven, FL
$87K - $139K (Employer provided)
Is your resume a good match?
Use AI to find out how well the skills on your resume fit this job description.
The SouthState story is one of steady growth, deep community roots, and an unwavering commitment to helping our customers move forward. Since our beginnings in the 1930s to becoming a trusted financial partner across the South and beyond - we are known for combining personal relationships with forward-thinking solutions.
We are committed to helping our team members find their success while maintaining the integrity of our values: building trust, fostering lasting relationships and pursuing excellence. At SouthState, individual contributions are recognized, potential is cultivated and team members are inspired to achieve their greater purpose. Your future begins here!
Summary
The Third-Party Risk Governance, Operations, and Reporting Manager is responsible for establishing and maintaining the governance framework, reporting capabilities, and operational oversight of the Bank’s Third-Party Risk Management (TPRM) program. This role assures consistent application of policies, standards, risk framework, regulatory expectations and consideration of emerging risks. The position is critical to strengthening risk transparency, supporting regulatory compliance, and enabling informed decision-making across the third-party lifecycle.
Duties & Responsibilities
Lead the governance framework for the TPRM Program, assuring alignment with regulatory expectations (e.g., OCC guidance), third party risk management best practices, internal policies, and integration of emerging risks.
Develop, maintain, and enhance TPRM policies, standards, and procedures to support a consistent control environment across the bank.
Lead the execution of the TPRM Program Strategy, Roadmap, and Workplan.
Develop and deliver training for the TPRM team and business stakeholders across the bank to assure a clear understanding of the TPRM Program, roles, responsibilities, and expectations.
Identify and execute TPRM reporting and metrics, including the development of dashboards and executive-level reporting that provide clear visibility into third-party risk exposures, trends, and program performance.
Establish and monitor key risk indicators (KRIs), key performance indicators (KPIs), issue, exception management processes to support timely identification, escalation, and remediation of third-party risks.
Oversee governance over critical and high-risk vendors, including oversight of risk profiles, risk tiering, segmentation, and alignment to business resiliency and concentration risk frameworks.
Partner with cross-functional stakeholders (e.g., SOX, MRM, AIGA, Legal, Compliance, IT, and Business Units) to promote adherence to TPRM requirements and embed risk management practices into third-party lifecycle activities, and to identify opportunities to improve the TPRM Program.
Identify, develop, and maintain TPRM technologies, including use of Artificial Intelligence (AI) capabilities, to perform TPRM responsibilities.
Oversee TPRM vendor inventory and reconciliations.
Oversee the vendor exit strategy and fourth party framework.
Lead and facilitate internal audits and regulatory examinations by providing documentation, analysis, and responses related to third-party risk assessments
It is the responsibility of this role to take ownership of all tasks and challenges that they encounter in the operation of their assigned position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Qualifications
Education Requirements
Bachelor’s Degree
Minimum Experience
Required:
Third-party risk management experience that includes Compliance, Information Security, Technology, and Operational process assessments, including 5 or more years recent third-party risk management activities, audit, or related activity.
Demonstrated understanding of the Third-Party Risk Management life cycle and risk assessment activities.
Broad knowledge of the Three Lines of Defense Risk Management and Controls Assessment Models.
Strong business focused decision making and problem-solving skills.
Excellent interpersonal and leadership skills with a demonstrated ability to establish relationships with senior management across all business units.
Provide ability to maintain confidentiality regarding sensitive information.
Familiarity with Governance, Risk, and Compliance suite of tools, preferably Acher.
Familiarity with using AI capabilities, preferably Copilot.
Preferred:
Knowledge of banking industry practices and regulatory requirements.
Knowledge of information security concepts, practices, tools to effectively assess security risk, recommend risk mitigation activities, and communicate to the business unit.
Experience with using Artificial Intelligence capabilities to support risk assessments or related activities.
Licenses & Certifications
At least one of the following: Certified Third-Party Risk Management Professional (C3PRMP), Certified Third Party Risk Professional (CTPRP), Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified in Risk and Information Systems Control (CRISC).
Physical Demands and Work Environment
Physical Demands
Ability to communicate in person, on the phone, and through electronic channels
Ability to use a computer on a frequent basis, including typing and sustained attention to a monitor
Ability to sit, walk, and/or stand for extended periods of time
Ability to bend and reach
Work Environment
Remote or hybrid: For remote or hybrid positions, a secure and distraction-free setting is required, with a reliable internet connection (cable or fiber preferred, mobile hotspots not acceptable). Hybrid positions will report to a physical Company location, as directed by the manager, and that setting will be a typical office environment.
In accordance with Colorado and Virginia law: Pay for this position is anticipated to be between $87,282.00 - $139,425.00 , actual offers to be determined based on applicant’s skills, experience and education.
While the anticipated deadline for the job posting is 08-20-2026, we encourage you to submit your application as we may still consider qualified candidates beyond this date.
Benefits | SouthState Careers
Equal Opportunity Employer, including disabled/veterans.
The minimum salary is $87K and the max salary is $139K.
$87K – $139K/yr (Employer provided)
$113K
/yr Median
Winter Haven, FL
If an employer includes a salary or salary range on their job, we display it as "Employer Provided". If a job has no salary data, Glassdoor displays a "Glassdoor Estimate" if available. To learn more about "Glassdoor Estimates," see our FAQ page.
Working here doesn’t have to be a secret
Sign in to browse authentic reviews, anonymous ratings and salary data before you apply.