About the Role
The Third-Party IT Risk Manager leads and modernizes Wolters Kluwer’s global third-party cyber risk management capability. This role ensures third-party engagements align with the organization’s risk appetite, security standards, and regulatory expectations, while leading the execution of a scalable, intelligence-led TPRM program. It focuses on innovation, leveraging automation, technical validation, and continuous monitoring to provide real-time insight into supplier risk.
Responsibilities
- Lead and evolve Wolters Kluwer’s global Third Party Risk Management (TPRM) program and operating model.
- Modernize TPITRM by shifting from a primarily questionnaire driven approach to a data driven program that incorporates technical validation, continuous monitoring, AI, and risk quantification.
- Lead junior team members across the TPRM function to drive successful outcomes.
- Implement continuous monitoring capabilities to deliver near real time visibility into third party cyber posture, control performance, and emerging risk indicators.
- Design and deploy innovative approaches—including automation and AI assisted techniques—for evidence collection, risk scoring, and exception management.
- Continuously assess emerging tools, data sources, and assurance models to improve risk coverage, reduce assessment friction, and enhance signal quality beyond traditional questionnaires.
- Review and analyze third party contracts to ensure Company requirements, principles, and assets are sufficiently protected.
- Identify technical and functional requirements that do not align or meet Company needs, suggest enhancements, and have them accepted and implemented by the supplier.
- Maintain a centralized, enterprise wide inventory of third party relationships, risk tiers, and risk treatment decisions.
- Provide clear, concise reporting on third party cyber risk posture, trends, and concentration risk to senior leadership.
- Build, lead, and develop a high performing team of third party risk professionals and technical reviewers.
- Foster a culture of accountability, innovation, and constructive challenge consistent with Wolters Kluwer values and operating principles.
Requirements
- Bachelors degree in computer science, information security, management information systems or similar.
- 12+ years of experience in cybersecurity, technology risk, or information security, including significant ownership of third party or supplier cyber risk management in large, complex enterprises.
- 5+ years of leadership (direct managerial experience or functional delivery leading teams).
- Proven experience designing and leading a global TPRM program across the full third party risk lifecycle.
- Demonstrated success modernizing TPRM by implementing risk based approaches that integrate technical validation, automation, and continuous monitoring.
- Demonstrated success owning decisions and outcomes at a senior level independently without formal authority.
- Strong technical fluency across cloud platforms, APIs, identity, data flows, and integration architectures.
- Experience overseeing advanced technical assessments for high risk or critical third parties, such as architecture reviews, vulnerability assessments, penetration testing, and threat modeling.
- Ability to operate effectively in highly distributed, market driven environments.
- Demonstrated leadership experience, including building high performing teams and influencing senior stakeholders across Technology, Procurement, Legal, Privacy, and Enterprise Risk Management.
- Strong executive communication skills, with experience reporting third party cyber risk posture and trends to senior leadership.
- Familiarity with systemic, concentration, and fourth‑party risk.
- Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA.
- Relevant certifications (e.g., CISSP, CISM, CTPRP, CRISC, CISA)
Skills
- Cybersecurity
- Technology risk
- Information security
- Third party risk management
- Supplier cyber risk management
- Technical validation
- Continuous monitoring
- Automation
- AI
- Risk quantification
- Contract review
- Business acumen
- Cloud platforms
- APIs
- Identity
- Data flows
- Integration architectures
- Architecture reviews
- Vulnerability assessments
- Penetration testing
- Threat modeling
- Executive communication
Location
- Hybrid
Work Type
- Hybrid
Experience Level
- 12+ years of experience
- 5+ years of leadership
Education Level
- Bachelors degree in computer science, information security, management information systems or similar.
Salary/Compensations
- $118,300.00 - $207,400.00 USD
Benefits
- Medical, Dental, & Vision Plans
- 401(k)
- FSA/HSA
- Commuter Benefits
- Tuition Assistance Plan
- Vacation and Sick Time
- Paid Parental Leave
About the Company
- Wolters Kluwer offers a wide variety of competitive benefits and programs to help meet your needs and balance your work and personal life.
Equal Opportunity
- To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts.
- Our interview process is designed to assess your individual skills, experiences, and communication style.
- We value authenticity and want to ensure we’re getting to know you—not a digital assistant.
- To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process.
- Please note that use of AI-generated responses or third-party support during interviews will be grounds for disqualification from the recruitment process.
- Applicants may be required to appear onsite at a Wolters Kluwer office as part of the recruitment process.
