TPRM expert with 7+ years of experience in financial services, specializing in vendor risk management. Expertise in executing comprehensive vendor due diligence and risk assessments, alongside effective remediation strategies. Developed and implemented compliance frameworks such as DORA, while creating automated Power BI dashboards for improved risk visibility. Strong communicator with a focus on building consensus among diverse stakeholders to enhance third-party risk processes.
Third-Party & Vendor Risk Management: Vendor lifecycle oversight (selection, due diligence, onboarding, monitoring, offboarding) in accordance with governance frameworks. Conduct risk assessments (questionnaires, SOC reports, audits) and monitor control effectiveness.
Regulatory Compliance & Controls: Ensure adherence to ICT risk regulations and standards (e.g. DORA for financial resilience, GDPR, NYDFS) by embedding controls into vendor management processes.
Governance & Committee Support: Coordinate TPRM committee meetings and governance forums, convening cross-functional experts (risk, procurement, legal, IT) to drive oversight of high-risk vendors. Prepare committee materials (risk heat maps, scorecards) and track follow-up actions.
Reporting & Data Analytics: Expert in Power BI and Excel for interactive risk dashboards and KPI/KRI tracking (e.g. vendor performance metrics, assessment cycle times). Automated compliance dashboards and reporting to enhance real-time visibility and accuracy.
Process Improvement: Streamlined risk assessment workflows (using tools like R360/SAI360) to reduce manual tasks and cycle time (UpGuard reports cut vendor assessment time by ~50%). Designed IT process controls aligned with ITIL principles and audit requirements.
Tools & Systems: Proficient with GRC and collaboration platforms: SAI360 (R360) for vendor risk, SharePoint/Teams for document management and tracking, ServiceNow/Archer for workflow and issue remediation. Familiar with security assessment tools (CSA CAIQ, SIG, ISO 27001).
Communication & Collaboration: Strong written and verbal skills, capable of presenting complex risk information clearly to executives. Proactive coordinator who builds positive relationships across regional and global teams, driving projects to completion through teamwork
Established TPRM Framework from the ground up for a global organization, aligning with ISO 27001
Conducted over 200 third-party risk assessments annually, identifying critical gaps in cybersecurity, privacy, and business continuity domains
Remediated high-risk vendors by implementing mitigation plans, renegotiating contracts, and enforcing security controls.
Developed risk scoring models to prioritize vendors based on criticality, data access, and regulatory exposure.