EOS RPO
Sr. Business Execution Consultant
Program Governance: Develop and maintain the TPRM framework, ensuring alignment with global standards (e.g., NIST, ISO 27001, EBA Guidelines).
Risk Assessment & Tiering: Lead the classification of vendors based on data access, business criticality, and inherent risk.
Due Diligence: Conduct deep-dive assessments of high-risk vendors, reviewing SOC 2 reports, financial statements, and AI safety protocols.
Continuous Monitoring: Utilize automated risk-intelligence tools (e.g., BitSight, SecurityScorecard) to monitor vendor health in real-time, moving beyond static annual surveys.
Contract Negotiation: Partner with Legal and Procurement to embed "right-to-audit" clauses, data protection requirements, and SLA-based risk triggers into contracts.
Nth-Party Visibility: Map and manage downstream risks associated with fourth-party and sub-processor dependencies to prevent supply chain contagion.
Incident Response: Serve as the primary risk lead during third-party breaches, coordinating with the SOC and internal stakeholders for rapid containment.