Third-Party Risk Sourcing Manager

4 weeks ago


New York, United States New York Times Full time

Third-Party Risk Sourcing Manager The mission of The New York Times is to seek the truth and help people understand the world. That means independent journalism is at the heart of all we do as a company. It's why we have a world-renowned newsroom that sends journalists to report on the ground from nearly 160 countries. It's why we focus deeply on how our readers will experience our journalism, from print to audio to a world-class digital and app destination. And it's why our business strategy centers on making journalism so good that it's worth paying for. About the Role: We are looking for a Third-Party Risk Sourcing Manager to join our Strategic Sourcing team, reporting directly to the Executive Director, Strategic Sourcing. You will lead our daily third-party risk due diligence efforts, collaborating with departments like Technology, and Legal to address risks across a range of domains. You will oversee sourcing enablement services, intake operations, policy implementation, and automation, to support tail-spend sourcing programs. You will focus on coaching and work allocation, with limited direct people leadership responsibilities. We operate under a hybrid remote/in-office policy, requiring three days per week in our New York City office and two days remote. Responsibilities: Third-Party Risk Management Perform initial reviews for low/medium-risk vendors. During these reviews, you will examine evidence to identify gaps and residual risk. This evidence includes SIG/SIG Lite, CAIQ, SOC 2 Type II, ISO 27001, PCI SAQ/AoC, DPAs, BC/DR, and VAPT summaries. Evaluate and escalate high-risk vendors to internal subject matter experts and coordinate mitigation actions and follow up. Lead time-bound risk review meetings and escalations with subject matter experts. You will maintain using risk guides, document decisions and risk acceptance, coordinate mitigations, and track remediation to closure. Manage Third-Party Risk Management (TPRM) inventory and assessment Service level agreements. You will support incident response and vendor issue management. Additionally, you will process metrics involving publishing dashboards that track cycle time, backlog age, assessments, and remediation closure, and delivering partner training. Source Enablement Tail-spend sourcing: Increase delivery velocity with risk-appropriate approaches; apply guides, informal RFx, and negotiation strategies. Intake/help desk: Serve as the front door for sourcing requests; maintain Service level agreements, and measure requester satisfaction. Efficient Contracting: use standard templates and establish fallback positions to manage Legal escalations. Enablement and continuous improvement: Improve adoption of Sourcing templates, and guides; refine Sourcing intake workflows to apply risk-appropriate effort. AI-assisted workflows: Design and operationalize AI-assisted processes (with guardrails) for Sourcing tasks. Demonstrate support and understanding of our value of journalistic independence and a commitment to our mission to seek the truth and help people understand the world. Basic Qualifications: 5+ years of experience in third-party risk management, vendor risk, IT risk, or adjacent governance roles, with hands-on due diligence and assessment experience. Proficiency in reviewing vendor security/privacy evidence. Familiarity with contractual terms in procurement, including limitation of liability, indemnities, confidentiality and Service Level Agreements. Knowledge of TPRM systems (e.g., ProcessUnity, Navex, Whistic) and intake-to-pay systems (preferably Zip). Understanding of external ratings from providers like BitSight, SecurityScorecard, and others. Familiarity with frameworks is important. These include the National Institute of Standards and Technology Cybersecurity Framework, ISO 27001/27701, SOC 2, and PCI DSS. Additionally, knowledge of privacy regulations is necessary, such as the General Data Protection Regulation and California Privacy Rights Act. Experience managing queues against Service level agreements and prioritizing trade-offs. Bachelor's degree or equivalent practical experience. Preferred Qualifications: 5+ years of Experience in Financial Services, or other regulated sectors. CTPRP, CRISC, or relevant security/risk certificates.



  • New York, United States The New York Times Full time

    Join to apply for the Third-Party Risk Sourcing Manager role at The New York Times The mission of The New York Times is to seek the truth and help people understand the world. That means independent journalism is at the heart of all we do as a company. Its why we have a world-renowned newsroom that sends journalists to report on the ground from nearly 160...


  • New York, NY, United States Amalgamated Bank of NY Full time

    Purpose of Position: The Third Party Risk Management Analyst supports the Third Party Risk Management Team in the development and execution of the Bank's Enterprise Third Party Risk Management Program to measure, monitor, assess and report on the control of third party risk throughout the enterprise. Responsibilities include interfacing and collaborating...


  • New York, NY, United States Amalgamated Bank of NY Full time

    Purpose of Position: The Third Party Risk Management Analyst supports the Third Party Risk Management Team in the development and execution of the Bank's Enterprise Third Party Risk Management Program to measure, monitor, assess and report on the control of third party risk throughout the enterprise. Responsibilities include interfacing and collaborating...


  • New York, United States City National Bank Full time

    Third Party Risk Management Lead at City National Bank Opportunity Third Party Risk Management (TPRM) Lead is responsible for providing enterprise-wide third party risk management services, defining, implementing, and maintaining a risk framework, operating model, policies, procedures, governance, and oversight programs for all lines of business and...

  • AVP, Category

    1 day ago


    New York, United States Bayview Asset Management, LLC Full time

    AVP, Category & Third-Party Risk Management Bayview Asset Management, LLC (Founded 1993, investment management firm focused on mortgage and consumer credit). Position Summary The Assistant Vice President (AVP), IT Category & Third-Party Risk Management plays a key role in overseeing the full lifecycle of technology and SaaS vendor relationships across...

  • AVP, Category

    1 day ago


    New York, United States Bayview Fund Management, LLC Full time

    Overview Founded in 1993, Bayview Asset Management is an investment management firm focused on investments in mortgage and consumer credit, including whole loans, asset-backed securities, mortgage servicing rights, and other credit-related assets. About Us Position Summary The Assistant Vice President (AVP), IT Category & Third-Party Risk Management plays a...

  • AVP, Category

    1 day ago


    New York, United States Bayview Asset Management Full time

    Job Description OverviewAbout UsFounded in 1993, Bayview Asset Management is an investment management firm focused on investments in mortgage and consumer credit, including whole loans, asset-backed securities, mortgage servicing rights, and other credit-related assets.Position SummaryThe Assistant Vice President (AVP), Category & Third-Party Risk Management...


  • New York, United States PowerToFly Full time

    Overview At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how...


  • New York, New York, United States Bayview Asset Management Full time

    OverviewAbout UsFounded in 1993, Bayview Asset Management is an investment management firm focused on investments in mortgage and consumer credit, including whole loans, asset-backed securities, mortgage servicing rights, and other credit-related assets.Position SummaryThe Senior Associate, Category & Third-Party Risk Management supports the full lifecycle...


  • New York City Metropolitan Area, United States Madison-Davis, LLC Full time

    Title:AVP, Third-Party Risk ManagementOffice Status:Onsite – New York, NYBase Salary:$120,000 – $155,000 base + bonusOverviewOur client is a U.S.-based banking institution with a strong governance culture and a growing operational footprint. This AVP-level role sits within the independent risk function and is responsible for owning and enhancing the...