Skip to content

Open nowPosted 45 days ago

Manager, Third Party Risk Management

arrive74 open roles

Where
Bengaluru
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowManager, Third Party Risk Managementarrive · Bengaluru
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on arrive's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.1%14 days
  5. 34.4%30 days
This job: posted 45 days ago

The posting

We’ve signed up to an ambitious journey. Join us!

As Arrive, we guide customers and communities towards brighter futures and more livable cities, it isn’t a challenge just anyone could take on. Luckily, we have something to help us make it happen. Our people and our values. We Arrive Curious, Focused and Together. Just as our entire brand is inspired by the North Star, the shining light leading travelers to their destinations since time began, our values guide us. They help us be at our best. For our customers. For the cities and communities we serve. For ourselves. As a global team, we are transforming urban mobility. Let’s grow better, together.

Role Overview:

We are seeking an experienced Third-Party Risk Management (TPRM) Manager to own and mature Arrive’s global third-party risk program.

Reporting to the Risk & Compliance Lead, this role will serve as the single point of accountability for third-party security risk across the Arrive Group. This is a strategic governance role focused on enabling business growth while ensuring vendors, partners, and suppliers meet Arrive’s security, resilience, and regulatory expectations.

The ideal candidate will combine strong vendor risk assessment expertise, regulatory alignment experience, and senior stakeholder management capability in a global environment.

Key Responsibilities:

Vendor Risk Assessments & Due Diligence

- Lead security risk assessments for new and existing third parties (SaaS, cloud, fintech vendors, payment processors).

- Review and analyze vendor certifications and assurance artifacts (ISO 27001, SOC 1/2, PCI DSS, GDPR documentation).

- Evaluate third-party control effectiveness and document risk findings.

- Drive remediation tracking and closure with vendors and internal stakeholders.

- Maintain and mature standardized third-party assessment frameworks.

Risk-Based Decision Support

- Translate technical findings into business-aligned risk insights.

- Advise leadership on risk acceptance, mitigation, and compensating controls.

- Maintain a defensible third-party risk register and reporting structure.

- Support procurement decisions through risk scoring and tiering models.

Regulatory & Contractual Alignment

- Partner with Legal and Procurement to embed security requirements in contracts (MSA, DPA, security addendums).

- Ensure alignment with ISO 27001, PCI DSS, GDPR, NIS2, SOC, and other regulatory frameworks.

- Validate subcontractor and supply-chain security obligations.

- Support customer due diligence and regulatory inquiries related to vendor security.

Program Governance & Continuous Improvement

- Own and continuously enhance the TPRM lifecycle (onboarding, assessment, monitoring, offboarding).

- Define and track KPIs for vendor risk posture (coverage, remediation time, risk trends).

- Support internal and external audits by providing third-party assurance evidence.

- Leverage GRC or TPRM tools to automate workflows and reporting.

- Scale the TPRM program in line with business growth and geographic expansion.

Continuous Improvement

- Drive ongoing enhancement of the TPRM framework, processes, and tooling to align with evolving regulatory and business requirements.

- Identify gaps and implement process efficiencies to strengthen risk mitigation and stakeholder experience.

- Monitor industry best practices and emerging risks to proactively refine the third-party risk management program.

Reporting

- Design and implement TPRM KPIs and KRIs to measure third-party risk exposure, assessment coverage, remediation timelines, and control effectiveness.

- Develop executive dashboards and periodic reporting to provide data-driven insights to senior leadership and governance forums.

- Monitor performance against defined risk thresholds and drive accountability through structured reporting and escalation mechanisms.

Stakeholder & Cross-Functional Collaboration:

- Act as primary security liaison for Procurement, Legal, IT, and Business Units.

- Provide clear guidance on third-party security expectations.

- Drive a security-enablement mindset across the organization.

- Present risk updates to senior leadership and governance forums.

Required Skills:

- 12+ years of experience in information security, risk management, GRC, or third-party risk management.

- Proven experience leading or owning a Third-Party Risk Management program in a complex, global organization.

- Strong understanding of ISO 27001,NIS2, SIG, and vendor risk frameworks.

- Proven experience assessing SaaS, cloud, and technology vendors.

- Experience partnering with Legal and Procurement teams.

- Experience maintaining risk registers and executive-level reporting.

- Strong stakeholder communication and presentation skills.

- Experience supporting audits and regulatory compliance activities.

Preferred Experience:

- Experience implementing or managing a TPRM platform/tool.

- Exposure to NIS2, revDSG, or other European regulatory frameworks.

- Experience in fintech, payments, SaaS, or high-growth digital environments.

- Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor.

- Experience aligning vendor risk programs with enterprise risk frameworks (NIST, CIS).

Why Join Arrive?

- Work on global-scale payment systems impacting millions of users.

- Be part of a growing India engineering team with strong ownership.

- Collaborate with diverse, international teams.

- Opportunity to influence architecture, strategy and team growth.

- Build technology that directly improves urban mobility and sustainability.

ABOUT ARRIVE

Arrive, including brands like EasyPark, Flowbird, RingGo, ParkMobile and Parkopedia, is a leading global mobility platform. Present in over 90 countries and 20,000 cities, the company helps people and decision-makers make smarter decisions about urban mobility and ease the experience of travel worldwide. Arrive delivers a unique combination of the core ingredients to make cities more livable: from smart payments and optimized car parks to data-driven traffic reduction and support for reinvestment in public transport and green space. It’s about more than function, it’s about saving time and simplifying the experience of travel for everyone. Travel is more than a journey, it’s how you Arrive.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against arrive's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on arrive's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    arrive's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.