
Third-Party Risk Management Program Lead
Key Skills
Job Description
About the Role
We are looking for a TPRM Program Lead to own end-to-end delivery of a Third-Party Risk Management Managed Service for an enterprise client. Engagements typically span multiple risk domains — such as Cyber Security, Privacy (DPIA/DTIA/TOM), ESG, AI-Enabled Supplier Assessment, and Geopolitical Risk — depending on the client’s program scope. This is a delivery leadership role: you will coordinate a distributed team of specialist consultants and workstream leads, run the governance cadence with the client, own SLA/KPI performance, and be the single point of accountability when something needs to be resolved fast. You are not expected to run individual assessments yourself — you are expected to make sure the specialists who do are aligned, unblocked, and delivering to quality and on time.
This role owns orchestration, governance, and outcomes across the program. It does not include performing individual supplier assessments, screenings, or technical validation work — that sits with the workstream specialist consultants — nor does it include final commercial contract negotiation, which sits with the Client Partner.
Key Responsibilities
• Own end-to-end delivery of the TPRM managed service across all in-scope risk domains, ensuring consistent quality and adherence to agreed SLAs/KPIs
• Coordinate and manage the specialist consultant team — workload prioritization, cross-workstream dependencies, and day-to-day escalation triage
• Run the governance cadence: daily/weekly status calls, monthly operational meetings, Quarterly Business Reviews, and continuous-improvement/innovation forums
• Act as the primary escalation point for client stakeholders when workstream leads cannot resolve an issue directly
• Own consolidated SLA/KPI reporting and dashboards across workstreams, and present progress, risks, and remediation status to client leadership
• Drive process and platform improvement initiatives (e.g., GRC, TPRM, or ESG-rating platforms such as OneTrust or EcoVadis, or equivalent tools) in collaboration with the client’s platform/product owner teams
• Manage change control for scope changes, volume fluctuations beyond agreed tolerance, and any resulting commercial implications, in partnership with the Client Partner
• Own transition and knowledge-transfer planning at contract milestones, renewal, or exit
• Build and maintain a trusted, senior-level relationship with the client’s Program Sponsor, Service Delivery Manager, and Business Owners
What You’ll Need
• Bachelor’s degree in Business, Risk Management, Information Security, or a related field (Master’s a plus)
• 12–15 years of experience in third-party/supplier risk management, managed services delivery, or program management, including at least 6–8 years in a client-facing delivery leadership role
• Proven experience managing multi-domain compliance or risk programs at scale (200+ supplier portfolios)
• Working knowledge across TPRM domains relevant to the engagement — for example cyber security assessments, GDPR/privacy, ESG, geopolitical/sanctions risk, and AI governance — with deep expertise in at least one
• Experience running governance forums (QBRs, steering committees) and managing SLA/KPI-based service contracts
• Familiarity with GRC/TPRM platforms (e.g., OneTrust or equivalent)
• Excellent stakeholder management, executive communication, and escalation-handling skills
Nice to Have
• Experience within telecom, financial services, or another heavily regulated industry
• Prior experience mobilizing or transitioning a new managed service
• PMP, Prince2, or similar program management certification
• Exposure to large enterprise client governance frameworks in regulated sectors
Key Competencies
• Strategic ownership — thinks end-to-end across the program, not just a single workstream
• Strong people leadership — able to manage and develop a distributed, multi-disciplinary team
• Executive-level communication and presence with senior client stakeholders
• Comfortable being the escalation point and making judgment calls under pressure
• Continuous-improvement mindset for process and platform optimization
Core Responsibilities
The Program Lead is responsible for the end-to-end delivery of third-party risk management services, ensuring quality and adherence to SLAs across multiple risk domains. They will coordinate distributed specialist teams, manage governance cadences, and act as the primary escalation point for client stakeholders.
Requirements
Candidates must have 12–15 years of experience in risk management or program delivery, with at least 6–8 years in a client-facing leadership role. A bachelor's degree in a relevant field is required, along with deep expertise in at least one risk domain and familiarity with GRC platforms.
About Infosys Consulting - Europe
Industry: Business Consulting and Services
Company size: 1,001-5,000 employees
Infosys Consulting is a global management consulting firm helping some of the world’s most recognizable brands transform and innovate. Our consultants are industry experts that lead complex change agendas driven by disruptive technology. With offices in 20 countries and backed by the power of the global Infosys brand, our teams help the C-suite navigate today’s digital landscape to win market share and create shareholder value for lasting competitive advantage. To see our ideas in action, or to join a new type of consulting firm, visit us at www.InfosysConsultingInsights.com.