SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior TPRM Security Lead

Gong - San Francisco, CA, United States - Hybrid - posted 2026-07-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 117,000 - 185,000 / annual

Gong is a revenue intelligence platform that uses AI to help sales teams win deals. The company is seeking an experienced Third-Party Risk Manager to join the Governance, Risk, and Compliance (GRC) team and own the maturation of Gong's third-party risk management (TPRM) program. In this role, you will be responsible for the end-to-end third-party risk lifecycle, from vendor intake and due diligence through ongoing monitoring and offboarding. You will establish baselines and controls to reduce third-party risk across Gong's vendor portfolio, applying a risk-based approach that prioritizes effort based on vendor criticality, data access, and inherent risk. Your work will span security, privacy, compliance, financial, and operational domains. Key responsibilities include: - Owning the complete TPRM program lifecycle and building a robust, scalable framework that adapts to business growth - Conducting vendor risk assessments and clearly communicating findings and remediation requirements - Establishing vendor tiering and scaling due diligence depth according to risk profiles - Partnering cross-functionally with Procurement, Legal, Security, Privacy, and business stakeholders to embed risk requirements into contracts and workflows - Maintaining TPRM frameworks, policies, and standards aligned with SOC 2, ISO 27001, GDPR, CCPA, and other relevant standards - Managing continuous monitoring of the vendor portfolio, including periodic reassessments and remediation tracking - Administering TPRM tooling and automation to scale the program - Reporting on third-party risk posture, metrics, and trends to GRC leadership - Supporting audit and customer assurance activities You will report directly to the Head of GRC and operate both strategically and hands-on. The role requires 7+ years of experience in third-party/vendor risk management, GRC, information security, or related fields. You should have strong knowledge of security and compliance frameworks (SOC 2, ISO 27001, NIST), data privacy regulations, and experience conducting vendor risk assessments. Experience with TPRM tooling (e.g., Zip) and relevant certifications (CTPRP, CISA, CISSP, CRISC) are valued.

Similar roles