Find Jobs
Find Jobs Near You – Available Work in Your Location
Senior TPRM - GRC Consultant
Career Insights for Risk Manager
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Texas data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Risk Manager evaluates risk and recommends and manages strategies to mitigate or offset risks that could result in financial losses for a company or organization. Analyzes current risks and assesses potential new risks. Reviews contracts and insurance policies; prepares risk budgets. Communicates risk policies and procedures to staff at all levels of a company.
$100,705 / year median in Texas
Job Description
Senior
TPRM - GRC
Consultant YOH Services LLC 401(k) United States, Texas, McKinney Sep 02, 2026
Senior TPRM and GRC Consultant Third-Party Risk Management Specialist Work Arrangement:
Hybrid, 2-3 days onsite
Location:
Plano Texas or McKinney Texas
Start Date:
Immediate
POSITION SUMMARY IT
Third-Party Risk Management professional to lead and strengthen the TPRM program within the Governance, Risk, and Compliance function.
This position manages the complete third-party risk lifecycle, including vendor onboarding, due diligence, risk assessments, periodic reviews, remediation tracking, ongoing monitoring, and offboarding.
The ideal candidate has extensive experience evaluating technology vendors, identifying security and compliance risks, improving TPRM processes, and working independently with business and technical stakeholders.
Hands-on AuditBoard experience is strongly preferred, although candidates with strong RSA Archer experience will also be considered.
RESPONSIBILITIES
Lead the end-to-end third-party risk management lifecycle for new and existing vendors.
Conduct vendor due diligence, security risk assessments, control reviews, and periodic reassessments.
Evaluate vendor compliance with organizational security requirements and regulatory and industry standards.
Identify control gaps, document risk findings, recommend corrective actions, and track remediation through completion.
Develop, maintain, and improve TPRM policies, procedures, assessment methodologies, workflows, and supporting documentation.
Partner with Procurement, Legal, Information Security, Compliance, and business teams to incorporate security requirements into vendor selection and contracting.
Maintain and optimize AuditBoard or RSA Archer for vendor assessments, workflow management, documentation, issue tracking, and reporting.
Monitor third-party risk metrics, emerging trends, remediation progress, and overall compliance posture.
Prepare risk reports, dashboards, and program updates for senior leadership.
Support internal and external audits involving third-party risk, cybersecurity governance, and regulatory compliance.
Stay current with emerging cybersecurity threats, regulatory changes, and third-party risk management best practices.
REQUIRED QUALIFICATIONS
Minimum of five years of direct Third-Party Risk Management experience within an IT Security, Cybersecurity, Risk Management, or GRC function.
Demonstrated experience managing vendor onboarding, due diligence, risk assessments, control-gap identification, remediation tracking, periodic reviews, and offboarding.
Strong knowledge of cybersecurity frameworks, control standards, and regulatory requirements, including
NIST, ISO 27001, SOC 2, PCI
DSS, HIPAA, and CCPA.
Hands-on experience with AuditBoard, RSA Archer, or a comparable GRC platform.
Experience partnering with Procurement, Legal, Compliance, Information Security, and business stakeholders.
Strong analytical, documentation, reporting, communication, and stakeholder-management skills.
Ability to work independently, manage competing priorities, and deliver results in a fast-paced environment.
Ability to work onsite Wednesday through Friday.
PREFERRED QUALIFICATIONS
Hands-on experience configuring or optimizing AuditBoard TPRM workflows.
Experience developing, implementing, or maturing an enterprise Third-Party Risk Management program.
Experience creating executive-level risk reports, dashboards, and metrics.
CTPRP, CISA, CISSP, CRISC, or another relevant risk or cybersecurity certification.
Estimated Min Rate:
$50.00
Estimated Max Rate:
$65.00 What's In It for You? We welcome you to be a part of the largest and legendary global staffing companies to meet your career aspirations. Yoh's network of client companies has been employing professionals like you for over 65 years in the U.S., UK and Canada. Join Yoh's extensive talent community that will provide you with access to Yoh's vast network of opportunities and gain access to this exclusive opportunity available to you. Benefit eligibility is in accordance with applicable laws and client requirements.
Benefits include:
Medical, Prescription, Dental & Vision Benefits (for employees working 20+ hours per week)
Health Savings Account (HSA) (for employees working 20+ hours per week)
Life & Disability Insurance (for employees working 20+ hours per week)
MetLife Voluntary Benefits
Employee Assistance Program (EAP)
401K Retirement Savings Plan
Direct Deposit & weekly epayroll
Referral Bonus Programs
Certification and training opportunities
Note:
Any pay ranges displayed are estimations. Actual pay is determined by an applicant's experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply. Yoh, a Day & Zimmermann company, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Visit https:
//www.yoh.com/applicants-with-disabilities
to contact us if you are an individual with a disability and require accommodation in the application process. For California applicants, qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. All of the material job duties described in this posting are job duties for which a criminal history may have a direct, adverse, and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. By applying and submitting your resume, you authorize Yoh to review and reformat your resume to meet Yoh's hiring clients' preferences. To learn more about Yoh's privacy practices, please see our
Candidate Privacy Notice:
https://www.yoh.com/privacy-notice Stay Safe During Your Job Search Fraudulent recruiting communications have become increasingly common. Emails from Yoh recruiters will only come from an @yoh.com email address. Yoh will never ask candidates to pay fees, purchase equipment, send gift cards, or transfer funds as part of the recruiting or hiring process. If you receive a communication that appears suspicious or requests payment, contact Yoh directly before responding or sharing personal information.