← Back to jobs

Third Party Risk Manager

Company
Augustus
Location
New York City, NY
Work type
Full Time
Posted
2026-09-29

Job description

The Role
You own the mechanics that make the TPRM program run day to day. You are the person who keeps the vendor and partner inventory reconciled, moves relationships through onboarding and due diligence, coordinates SME reviews across every function that touches third-party risk, tracks BCDR posture on every critical vendor, and keeps the TPRM issues pipeline current.

You own:

Inventory: maintaining the third-party inventory and running the quarterly reconciliation against payment and contracting data (you do not own payment/contracting controls yourself — you reconcile against them).

Onboarding: running new vendor and partner relationships through intake and onboarding.

Initial & Ongoing Due Diligence: executing initial due diligence at onboarding and ongoing due diligence on the recurring schedule for existing relationships.

Audit Oversight: tracking and coordinating third-party audit requirements and following up on findings.

SME Reviews: coordinating and tracking risk-based reviews with subject matter experts across Information Technology, Information Security, BSA/AML & OFAC, Compliance (Consumer & Regulatory), Credit, Finance, and Legal.

BCDR: collecting and tracking RTO & RPO assessments for critical vendors, and maintaining exit plans.

Fourth Party Due Diligence: extending due diligence downstream to critical fourth parties where required.

Vendor DDQ & Partner DDQ: administering and tracking due diligence questionnaires for both vendor and partner relationships.

SLA: tracking service level agreements and monitoring performance against them.

Issues: maintaining the TPRM issues log from identification through remediation and closure.

Reverse Due Diligence: supporting due diligence requests that come from partners and counterparties assessing Augustus.

Your first 90 days
Weeks 1-4: You learn how third-party risk actually runs today — what's in (and missing from) the inventory, how onboarding and due diligence really move through the pipeline, which SME reviews are current versus overdue, what BCDR and exit plan documentation exists for critical vendors, and where the issues log breaks down.

Weeks 5-8: You take over the operational cadence. Onboarding and due diligence are moving on schedule. The inventory reconciliation is running quarterly without prompting. SME reviews are tracked and chased across all seven functions. DDQs are going out and coming back on time.

Weeks 9-12: You start closing gaps — cleaning up the BCDR and exit plan documentation for critical vendors, tightening fourth-party due diligence coverage, and getting the TPRM issues log to reflect true status. Leadership trusts the inventory and the pipeline status without double-checking them.

Who Will Thrive At Augustus
We believe that throwing smart people with high agency at big problems produces the best outcomes. The people who succeed here share the following traits:

Relentless: You can't leave something broken. You don't stop because it got hard or because no one is watching.

Set The Bar: You're harder on yourself than anyone else would be. You don't need external accountability to care about quality.

Shape The Game: You don't wait for a playbook and you don't need one. You walk into genuinely new territory and figure it out. You move before anyone asked you to.

Systems First: You don't solve problems by adding people or effort. You build systems that make the problem smaller. Your first instinct is to automate, not to handle it manually.

This role is for you if:

You get satisfaction from chasing down documentation, closing out a due diligence file, and keeping an inventory clean and reconciled.

You want to learn TPRM from the inside by running the pipeline, not by reviewing it after the fact.

You're comfortable coordinating with SMEs across seven different functions and holding them to a review deadline without formal authority over them.

You'd rather fix the tracker or tighten the process than send another follow-up email chasing a DDQ response.

You want a role where the scope is real and will grow as you prove you can carry it.

This is not for you if:

You want a fully mature program and tooling handed to you with no gaps to close.

You need someone else to define your daily priorities for you.

You're uncomfortable owning a deadline for something you don't directly control, like a vendor's response time.

You're looking for a purely strategic role with no operational coordination responsibility.

Detail-heavy, document-intensive work across many concurrent relationships drains you rather than satisfies you.

Hard Requirements
Several years of experience in third-party/vendor risk management, procurement risk, compliance, or a related operational/governance function.

Comfortable managing due diligence and review cycles across multiple vendors, partners, and internal SME functions at once.

Strong organizational and documentation skills — inventories, DDQs, and trackers stay accurate under you, not just after you build them.

Working knowledge of, or strong ability to quickly learn, third-party risk concepts including due diligence tiering, BCDR/RTO/RPO, SLA monitoring, and issues management.

Comfortable working with Excel/spreadsheets and reporting tools; experience with GRC or TPRM platforms is a plus but not required.

In New York City, or ready to relocate.

Original source