Third-Party Risk Management Program Manager
C.H. RobinsonAbout the role
C.H. Robinson is seeking a strategic Third-Party Risk Management (TPRM) Program Manager to lead and strengthen our enterprise-wide approach to managing third-party risk, helping protect the organization while enabling informed business decisions. In this role, you will drive the end-to-end TPRM program, partnering across Legal, Information Security, Privacy, Procurement, and business teams to assess, mitigate, and govern vendor risk throughout the supplier lifecycle. You will shape program strategy, influence executive decision-making through meaningful risk insights, and enhance processes that improve compliance, scalability, and operational effectiveness. If you're passionate about building risk-aware partnerships and driving enterprise impact, we encourage you to apply.
At C.H. Robinson, we’re firm believers in the power of in-person collaboration to fuel innovation and propel success. In this role, you will engage with peers on-site two days a week, igniting creativity and driving impactful results. With the flexibility for remote work three days a week, this role strikes the perfect balance between teamwork and autonomy.
**The internal deadline to apply is Wednesday, August 12th at 12:00 pm CST.
Responsibilities:
The duties and responsibilities of this position consist of, but are not limited to, the following:
- Lead and evolve the enterprise Third-Party Risk Management (TPRM) program strategy, governance framework, and roadmap to strengthen risk management practices across the organization
- Establish and maintain risk-based standards, policies, and governance processes that support informed business decision-making
- Manage vendor intake, risk tiering, and due diligence processes for new suppliers, renewals, and significant changes to existing engagements
- Partner with Legal, Information Security, Privacy, Business Continuity, Procurement, and business leaders to assess, manage, and mitigate third-party risks
- Drive cross-functional risk reviews, remediation efforts, and escalation activities to address high-priority vendor risks and compliance concerns
- Monitor third-party risk throughout the vendor lifecycle, ensuring timely follow-up, remediation tracking, and risk acceptance governance
- Develop dashboards, metrics, and executive-level reporting that provide visibility into vendor risk exposure, program performance, and emerging trends
- Identify opportunities to enhance program effectiveness, scalability, and operational efficiency while addressing evolving regulatory and business requirements
- Promote adherence to procurement processes, approved purchasing channels, and vendor governance requirements to reduce organizational risk
- Support sourcing, vendor selection, and contracting activities by ensuring third-party engagements meet risk management standards before execution
Required Qualifications:
- Bachelor’s degree from an accredited college or university and/or equivalent working experience
- Minimum of 6-8 years’ experience in Third-Party Risk Management, Vendor Risk, or Supplier Governance, Procurement, Sourcing, Compliance, Audit, and/or Information Security
Preferred Qualifications:
- Experience in Third-Party Risk Management, Vendor Risk, Supplier Governance, or enterprise risk program management
- Experience in Procurement, Sourcing, Compliance, Audit, Information Security, Privacy, or Business Continuity
- Strong understanding of the third-party risk lifecycle and risk concepts, including inherent and residual risk
- Experience operating in cross-functional, matrixed environments
- Demonstrated ability to influence senior stakeholders, drive remediation accountability, and escalate material risks without direct authority
- Experience preparing leadership-level reporting, risk summaries, decision options, and audit-ready documentation
- Experience implementing risk acceptance, remediation tracking, issue management, or governance reporting processes
- Experience in a Procurement-led or intake-to-pay operating model
- Familiarity with TPRM and procurement platforms (e.g., Coupa, Levelpath, ServiceNow, CyberGRX)
- Certifications such as CTPRP, CRISC, CISA, or similar
- Strong program management, governance, and process ownership mindset
- Ability to translate technical and regulatory risk into business impact
- Excellent stakeholder coordination, influence, and escalation management across multiple functions
- Ability to challenge incomplete reviews, unresolved remediation, or risk acceptance gaps while maintaining a business-enabling approach
- Detail-oriented with strong documentation and audit discipline <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s