Senior TPRM Lead- Tooling and Process Engineering (Remote)
United States · Remote · Full-time
- Posted 3d ago
- From CrowdStrike’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 10+ years
- Department
- Legal and Compliance
Opens the listing on crowdstrike.wd5.myworkdayjobs.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed. We're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily.
About this Role:
CrowdStrike is seeking an experienced Technical Lead, Third Party Risk Management (TPRM) to drive the strategy, architecture, and technical execution of our vendor risk ecosystem. Sitting within the GRC organization, this highly specialized individual contributor role is critical to protecting CrowdStrike's customers, data, and operations through rigorous, scalable, and forward-thinking risk practices.
As the technical anchor for the TPRM program, you will design and optimize complex workflows, drive automation initiatives, and oversee the operational cadence of the assessment pipeline. You will serve as the principal subject matter expert for TPRM processes and our platform of record, proactively identifying efficiencies and defining the technical standards for vendor risk evaluations.
The ideal candidate possesses deep hands-on tooling expertise and expert-level process knowledge, constantly searching for ways to engineer a stronger, more automated risk posture that supports a fast-paced, secure environment in the tech industry.
What You'll Do:
- System, Tooling & AI Architecture: Serve as the functional owner, technical architect, and principal subject matter expert for ServiceNow as the TPRM platform of record. Partner with IT to configure, optimize, and expand workflows, while proactively architecting and implementing AI-driven capabilities to enhance risk scoring, continuous vendor monitoring, and system efficiency.
- Operational Leadership: Manage the day-to-day operations of the TPRM assessment pipeline, including dynamic queue and capacity management, rigorous SLA tracking, and conducting final reviews and approvals for vendor assessments to ensure high-quality outputs.
- Process Engineering & Automation: Lead the technical implementation of process improvements (including those identified through continuous improvement/Kaizen events) by developing and expanding automation capabilities within ServiceNow to reduce manual effort.
- Program Design: Architect and optimize the end-to-end vendor risk lifecycle (onboarding, inherent risk tiering, reassessment, offboarding) to ensure seamless, scalable application of TPRM standards.
- Agile Development: Own the management of story creation, act as direct liaison with development team, and provide oversight on sprint and epic development.
- Cross-Functional Integration: Partner deeply with Procurement, Legal, IT, and Security engineering teams to embed technical risk considerations and automated security checks directly into the vendor engagement pipeline.
- Audit & Controls: Oversee third-party control evaluations and audits, process implementation via relevant tooling, and support internal and external audit activities performed by broader team.
- Standards & Frameworks: Develop and maintain technical TPRM policies, standards, and procedures in strict alignment with industry frameworks (NIST, ISO 27001, SOC 2, FAIR).
- Metrics & Reporting: Engineer and track automated KPIs, metrics, and dashboards to demonstrate program maturity and technical effectiveness to senior leadership.
What You'll Need:
- 10+ years of experience in Third Party Risk Management, GRC, information security risk, or related technical controls disciplines.
- Deep Tooling Expertise: Proven, hands-on administrative or architectural experience with the ServiceNow Third Party Risk Management (TPRM) module.
- Technical Leadership: 3+ years of experience acting as a technical lead, process architect, or principal SME driving operational efficiency and automation within a risk or compliance program.
- Framework Fluency: Strong, practical understanding of security and compliance frameworks, including NIST CSF, CSA's CCM, ISO 27001, SOC 2, NIST 800-53, and/or SIG or CAIQ.
- Forward-Thinking Tech: Experience with or a strong background in evaluating and integrating AI/ML tools and emerging threat intelligence platforms into GRC workflows.
- Cross-Functional Execution: Proven experience project-managing complex technical implementations, including scoping, work breakdown, critical path analysis, and quality assurance.
- Strategic Communication: Excellent stakeholder management skills with the ability to translate highly technical risk concepts and system architectures for business audiences and senior leadership.
- Adaptability: Ability to operate and engineer solutions effectively in a fast-paced, high-growth, global technology environment.
Bonus Points:
- Experience operating within a cloud environment and familiarity with CrowdStrike products or services.
- Experience with continuous monitoring through integrating data with security operations teams.
- Practical experience in Software Development and Secure Coding best practices.
- Practical experience performing integration risk assessments and threat modeling for third-party software components.
Benefits of Working at CrowdStrike:
- Market leader in compensation and equity awards
- Comprehensive physical and mental wellness programs
- Competitive vacation and holidays for recharge
- Paid parental and adoption leaves
- Professional development opportunities for all employees regardless of level or role
- Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
- Vibrant office culture with world class amenities
- Great Place to Work Certified across the globe
Compensation:
The base salary range for this position for all U.S. candidates is $125,000 - $180,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.
Skills they ask for
Pick one to see other roles that ask for it.
About CrowdStrike
AI-powered cybersecurity and threat responseCrowdStrike provides cloud-delivered cybersecurity products for detecting and responding to threats across endpoints and other environments.
See all 114 roles at CrowdStrikeMore roles at CrowdStrike
See all 114- Sr. Software Engineer - Sensor - Cloud Runtime Protection (Hybrid)Sunnyvale · Senior · HybridSoftware Development · Senior · HybridSunnyvale, United States1d
- Sr. Engineer - Risk Platform (Hybrid)Sunnyvale · Senior · HybridSoftware Development · Senior · HybridSunnyvale, United States1d
- Product Manager - Advanced Detection (Remote)United States · RemoteProduct Management · RemoteUnited States1d
- Staff Technical Marketing Manager (Staff TMM) – Browser Security (Remote)United States · Staff · RemoteMarketing · Staff · RemoteUnited States1d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.