Skip to content

Open nowPosted 37 days ago

Global Third-Party Risk & Compliance Manager

Clinigen24 open roles

Where
Shah Alam
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGlobal Third-Party Risk & Compliance ManagerClinigen · Shah Alam
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Clinigen's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 37 days ago

The posting

Clinigen’s third‑party ecosystem is wide and includes suppliers, service partners, consultants, distributors, and other intermediaries who can create ABAC, fraud, sanctions, reputational and operational risk if not properly assessed and controlled. This role provides the organisation’s front‑door integrity control: ensuring that third parties are vetted and monitored, risk is visible, escalations are handled consistently, and decisions are documented and auditable.

The role is also accountable for ensuring that third‑party due diligence is not a one‑off event — but a lifecycle process with ongoing monitoring and clear remediation steps, consistent with modern regulatory expectations

Key Responsibilities:

1) TPRM Operating Model Ownership (Global)

  • Own and maintain Clinigen’s TPRM framework and operating standards (scope, risk tiers, minimum due diligence requirements, escalation thresholds, evidence expectations).
  • Ensure consistent application across regions and business units, partnering with Procurement, Legal, Finance, Quality and operations to align the “who/what/when” of onboarding and approvals.
  • Ensure the TPRM programme supports “adequate procedures” expectations under global anti‑bribery, sanctions, and financial crime frameworks.
  • Support remediation actions, conditions of engagement, and contractual controls where third‑party risks are identified, working with Legal and Procurement

2) NAVEX RiskRate Platform Ownership (End‑to‑End)

  • Run the third‑party compliance workflow in NAVEX RiskRate: initiation, duplicate checks, questionnaires, screening outputs, risk decisions, approvals, and documentation standards.
  • Maintain process discipline so third parties are not engaged prior to approval, and ensure stakeholders understand timelines and required inputs.
  • Drive continuous improvements to workflows, templates, and automation, and act as the business owner for enhancements needed to scale.
  • Ensure data quality, completeness, and consistency within the third‑party system of record to support reporting, audit readiness, and decision‑making
  • Apply independent judgement and appropriate challenge where business urgency conflicts with third‑party risk requirements

3) Due Diligence & Risk Assessment (Proportionate, Risk‑Based)

  • Oversee initial risk screening and due diligence, ensuring appropriate depth of review depending on risk tier (including standard/enhanced due diligence as triggered by risk tiering).
  • Ensure that third‑party onboarding includes robust review of identity, ownership, location risk, services risk, and reputational indicators, and that findings are documented in the system of record.
  • Manage “go / no‑go” escalation where red flags exist; ensure decisions are risk‑informed, consistent, and defensible.

4) Sanctions & Trade Sanctions Controls

  • Ensure third‑party sanctions screening is performed and maintained, including appropriate escalation where potential matches arise and alignment to Clinigen sanctions requirements.
  • Support the organisation’s trade/export sanctions controls (including appropriate routing and escalation for sanctioned jurisdictions and commodity/HS code issues where required by policy).
  • Maintain clear records and audit trails for sanctions decisions and escalations.

5) Ongoing Monitoring & Lifecycle Management (Third‑Party Specific)

  • Own the ongoing screening/monitoring approach for third parties, including how alerts are reviewed, triaged, resolved and evidenced (TPRM lifecycle management).
  • Ensure periodic refresh, re‑screening and re‑due diligence occurs where required (e.g., risk changes, contract renewals, market expansion, scope changes).
  • Support off‑boarding/termination and ensure controls prevent continued engagement with blocked or terminated third parties.

6) Third‑Party Risk Intelligence, Reporting & Insight

  • Produce third‑party risk reporting for senior stakeholders: pipeline volumes, aged cases, bottlenecks, high‑risk concentrations, recurring red flags, and remediation themes (TPRM only).
  • Provide actionable intelligence to enable better business decisions (e.g., procurement interventions, process controls, contract gating improvements).

7) Stakeholder Enablement (Process Adoption Without Owning E&C Training)

  • Provide targeted process enablement and practical guidance to business requestors and procurement/finance stakeholders on “how to onboard third parties correctly” and how to avoid retrospective onboarding.
  • Maintain clear user guidance and practical comms for third‑party onboarding expectations (TPRM communications only)

8) GxP / Quality Interfaces (No Duplication of QA Vendor Qualification)

  • Ensure appropriate hand‑offs to Quality for GxP vendor qualification steps, and ensure compliance approval is aligned with QA requirements (without duplicating QA’s technical assessments).

Additional Duties:

The above list is not exhaustive. Duties may evolve based on business needs, and the post‑holder is expected to work flexibly to support a scalable, defensible Third‑Party Risk Management capability aligned to Clinigen’s Ethics & Compliance programme

Requirements

  • Experience in pharma, life sciences, healthcare services, or similarly regulated environments where third‑party risk (ABAC, fraud, sanctions, reputational risk) is material.
  • Experience using third‑party due diligence systems and structured workflows (RiskRate/NAVEX or comparable platforms).
  • Experience working with sanctions compliance expectations and controls (screening, escalation, record‑keeping, and programme components).
  • Familiarity with risk‑based “adequate procedures” expectations including due diligence and monitoring & review principles is beneficial
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Clinigen's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Clinigen's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Clinigen's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.