The GPI IT Compliance team is seeking an experienced professional to oversee and manage various tasks related to GPI's IT/OT Third Party Risk Management practices and technologies. This role will ...
The GPI IT Compliance team is seeking an experienced professional to oversee and manage various tasks related to GPI's IT/OT Third Party Risk Management practices and technologies. This role will ...
Thisteam defines and governs the firm's global third-party risk management (TPRM) program, spanning various third-party types and risk domains. While day-to-day execution is led by the Operations ...
Thisteam defines and governs the firm's global third-party risk management (TPRM) program, spanning various third-party types and risk domains. While day-to-day execution is led by the Operations ...
Third Party Cybersecurity GRC Advisor
Atlanta, GA · Hybrid
$106K - $144K/yr
Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the ...
Third Party Cybersecurity GRC Advisor
Atlanta, GA · Hybrid
$106K - $144K/yr
Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the ...
Perform non-performing Third Party metric root cause analysis and prepare and manage Go to Green plans * Review and challenge data transmission registrations (DTRs) and Third Party risk assessments ...
Perform non-performing Third Party metric root cause analysis and prepare and manage Go to Green plans * Review and challenge data transmission registrations (DTRs) and Third Party risk assessments ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Anticipated End Date: 2026-06-12 Position Title: Sr. Third Party Cybersecurity GRC Analyst Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Anticipated End Date: 2026-06-12 Position Title: Sr. Third Party Cybersecurity GRC Analyst Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianaplis ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianaplis ...
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
This position will also be responsible for oversight and program management of third-party risk management and Business Continuity Planning activities for the organization. They will report on these ...
This position will also be responsible for oversight and program management of third-party risk management and Business Continuity Planning activities for the organization. They will report on these ...
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking For (Minimum Qualifications) * Minimum of 5 years of experience in procurement, vendor management, or ...
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking For (Minimum Qualifications) * Minimum of 5 years of experience in procurement, vendor management, or ...
Senior Manager - Cybersecurity Governance, Risk & Compliance (GRC)
Atlanta, GA · On-site
$106K - $144K/yr
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Senior Manager - Cybersecurity Governance, Risk & Compliance (GRC)
Atlanta, GA · On-site
$106K - $144K/yr
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Third Party Risk Management information
See Georgia salary details
$43.5K - $52.6K
4% of jobs
$52.6K - $61.7K
6% of jobs
$61.7K - $70.8K
11% of jobs
$74.2K is the 25th percentile. Wages below this are outliers.
$70.8K - $79.9K
11% of jobs
The median wage is $87.1K / yr.
$79.9K - $89K
23% of jobs
$89K - $98.1K
13% of jobs
$104.1K is the 75th percentile. Wages above this are outliers.
$98.1K - $107.2K
12% of jobs
$107.2K - $116.3K
8% of jobs
$116.3K - $125.4K
6% of jobs
$125.4K - $134.4K
4% of jobs
$134.4K - $143.5K
2% of jobs
$43.5K
$94.2K
$143.5K
How much do third party risk management jobs pay per year?
What is a Third Party Risk Management job?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What is the highest paying risk management job?
What is the role of a third party Risk Manager?
What is 3rd party risk management?
What are some common challenges faced in a Third Party Risk Management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in the Third Party Risk Management position, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.
Is TPRM a good career?

Full-time
Posted 21 hours ago
Graphic Packaging International rating
6.8
Based on 120 frontline employees who took The Breakroom Quiz
74th of 110 rated packaging manufacturers
Job description
Graphic Packaging International, LLC (GPI) fosters a culture that protects, preserves, and enhances our reputation. The GPI IT Compliance team is seeking an experienced professional to oversee and manage various tasks related to GPI's IT/OT Third Party Risk Management practices and technologies.
This role will encompass Third Party Risk practices being deployed to manufacturing facilities with the intent to minimize GPI's risk exposure related to third parties in the GPI ecosystem. This position is responsible for deploying risk management practices to the IT/OT footprint at GPI, and to provide leadership with transparency into GPI's risk exposure for both IT and OT respectively specific to third parties. This role involves establishing new processes with focus on Industrial Control Systems, MES systems and all OT systems in use at GPI manufacturing facilities (plants and mill locations) across the globe.
Lead, IT/OT - Third Party Risk Management is expected to:
- Coordinate with external providers and internal technology teams regarding platform development, enhancements, integration and issue resolution
- Liaise with global risk and compliance groups and OT engineers and leaders related to due diligence matters and system requests or changes
- Collaborate across IT and manufacturing facilities with cross functional teams to escalate and resolve issues and risks identified and tracked
- Represent the IT Compliance Office with business teams, partners, and other GPI stakeholders, and with external third parties
- Identify key performance indicators to be used for management reporting at GPI
- Manage reporting and analyzing metrics for key performance indicators identified for GPI
- Identify risks, exceptions to policy or standards and other risk related issues for tracking and reporting or escalations to leadership
- Define and oversee processes and standards of operation performed by global IT/OT resources
Responsibilities
- Gain comprehensive knowledge and understanding of relevant policies, guidelines and compliance program elements which will be deployed to IT/OT processes to achieve risk minimization objectives
- Manage and perform monitoring activities on the IT/OT TPRM program activities, including use of the IT Risk Management and Third Party Risk Management modules within the GPI GRC system (OneTrust)
- Perform data analysis for ongoing monitoring of control violations, risk assessment activities, and reporting to management and senior leaders on key performance indicators on a recurring cadence
- Effectively interpret and document testing and monitoring results and develop recommendations for improvements and enhancements to reduce GPI risk profile for OT systems
- Utilize and develop data analytics capabilities to evaluate and improve third party management decisions, mitigation planning of obsolete technologies, and identifying reporting mechanisms to be leveraged for same
- Identify operational risks for OT third parties that need to be raised to leadership for remediation and risk reduction workstreams
- Oversee training of IT and OT TPRM team members, risk & compliance groups and GPI stakeholders on TPRM practices adopted and deployed at GPI
- Monitor, report and track compliance with policies and practices, including system security and access controls for OT systems and respective third parties
- Collaborate with cross functional engineers, leaders, colleagues, and global partners to achieve alignment on goals and objectives associated with risk reduction workstreams
- Effectively communicate with peers, managers, senior managers, and executive leaders cross functionally as a trusted subject matter expert and advisor for TPRM practices
- Recommend and implement process improvements to meet IT/OT Convergence TPRM, risk & compliance goals on an annual basis.
- Provide system and process training and support to the global IT organization and OT engineers and leaders for the ITRM platform TPRM module(s)
- Design and manage other IT third party assessment templates and workflows
- The role will evolve as IT/OT TPRM discipline expands and changes to meet compliance needs of GPI
Key Skills
- Aptitude to learn and utilize technology to perform and document responsibilities
- Moderate to advanced skills working with technical tools including Microsoft Office applications, specifically Excel, PowerPoint and Word
- Proven ability designing or enhancing third party risk management or compliance-related activities
- Excellent organizational aptitude
- Ability to analyze problems and facilitate solutions
- Excellent written and verbal communication skills
- Ability to think critically, objectively and analytically
- Detail-oriented with strong project management, organization, prioritization and time management skills
- Flexibility in working on several processes or projects simultaneously to meet team goals and responsibilities
- Possess high integrity to handle sensitive and confidential data
- Ability to work accurately and efficiently under pressure
- Proven ability to work independently and drive projects to completion
- Ability to work collaboratively with subject matter resources, often in a virtual and cross border environment
- Confidence and poise to work directly with GPI leadership teams
- Willingness and ability to readily respond to changing circumstances and expectations
- Interest in effectively developing other colleagues and creating a culture of compliance, inclusion and professional growth
Qualifications
- At least 5 years of experience working for a professional services organization providing one or more of the following: regulatory and compliance, audit, consulting, financial advisory, enterprise risk management and other related services
- Substantive direct experience in one or more of the following: third party due diligence, ethics and compliance programs, risk and controls, process management or change management
- Certified Public Accountant, Certified Internal Auditor, Certified Fraud Examiner and/or relevant compliance experience a significant advantage
- Bachelor's degree in accounting, finance, business or related field
- Information Security certifications (CRISC, CISM)
- Functional experience working in a manufacturing environment with MES and ICS systems
- Knowledge of GDPR and CCPA privacy rules associated to accessing, classifying, transferring, or modifying data in its lifecycle
Required Experience
At Graphic Packaging International (NYSE: GPK), we produce the box you may have poured your child's cereal from this morning, the microwaveable tray that heated your lunch, the paper cup that held your coffee throughout the day, and the carrier of those bottles of craft beer you may enjoy tonight! We're one of the largest manufacturers of paperboard and paper-based packaging for some of the world's most recognized brands of food, beverage, foodservice, household, personal care and pet care products. Headquartered in Atlanta, Georgia, we are a team of collaborative, innovative, passionate individuals who are committed to providing consumer packaging that makes a world of difference.
With almost 18,000 employees working in more than 70 locations in North and South America, Europe and the Pacific Rim, we strive to be an environmentally responsible leader in our industry and in the communities where we operate. We are committed to workplace diversity and offer compensation and benefits programs that are among the industry's best to reward the talented people who make our company successful.
If this sounds like something you would like to be a part of, we'd love to hear from you. Learn more about us at www.graphicpkg.com.
Inspired Packaging. A World of Difference.
Graphic Packaging is an Equal Opportunity Employer. All candidates will be evaluated on the basis of their qualifications for the job in question. We do not base our employment decision on an employee's or applicant's race, color, religion, age, gender or sex (including pregnancy), national origin, ancestry, marital status, sexual orientation, gender identity, genetic identity, genetic information, disability, veteran/military status or any other basis prohibited by local, state, or federal law.Click here to view the EEO is the Law Poster
What Graphic Packaging International employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Graphic Packaging
Sourced by ZipRecruiter
Industry
Plastics and rubber products manufacturing
Company size
10,000+ Employees
Headquarters location
Atlanta, GA, US
Year founded
1978