Position Overview:
Clients s Governance, Risk & Compliance (GRC) organization is seeking a Risk Advisor to advise leadership on risk posture and tradeoffs and to lead enterprise risk assessments and treatment decisions across client s businesses and technology functions.
The Risk Advisor also supports and helps drive Hearst s third-party risk management (TPRM) program, contributing to vendor risk assessments, escalations, and remediation across the vendor lifecycle. Client operates in a federated environment. Success in this role depends on strong stakeholder management and the ability to influence risk decisions without centralized authority.
What You ll Do:
" Advise leadership on enterprise risk posture, tradeoffs, and risk acceptance, with clear recommendations.
" Identify systemic and emerging risks and influence prioritization and investment decisions.
" Lead risk assessments and gap assessments across business processes and technologies, from initiation through treatment planning.
" Own escalation of material risks, with recommendations for treatment or acceptance.
" Maintain the enterprise risk register, keeping risks and response plans current.
" Track remediation and follow up to closure and SLA adherence.
" Integrate risk data into recurring reporting and metrics for leadership and risk-focused governance forums.
" Support and help drive the third-party risk management program, contributing to vendor risk assessments across onboarding, reassessment, and renewal.
" Advise business owners and procurement on third-party risk decisions, and support escalation and remediation tracking for vendor risks.
" Contribute to TPRM process improvements and program maturity.
What We re Looking For
Required
" Bachelor s degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Business Administration, or a related discipline. Equivalent experience may be considered in lieu of formal education.
" 7+ years in risk management, including risk leadership or advisory experience.
" Advanced understanding of enterprise risk management, with experience advising leadership on risk posture, tradeoffs, and acceptance.
" Demonstrated experience with third-party/vendor risk assessments across the vendor lifecycle, and the ability to support and help drive a TPRM program.
" Strong executive communication skills, including clear risk documentation and reporting to leadership and governance forums.
" Working knowledge of security and risk frameworks such as NIST CSF, NIST 800-53, PCI-DSS, HIPAA, or SOC 2, applied to enterprise and third-party risk.
" Familiarity with GRC and vendor risk platforms such as TruOps, Prevalent, OneTrust, ProcessUnity, or ServiceNow.
" Strong stakeholder management, with the ability to influence risk decisions without centralized authority.
" Identify opportunities to improve risk management scalability through analytics, automation, and AI.
Preferred
" CRISC, CISA, or PMI-RMP; CTPRP, CTPRA, CISM, or CISSP a plus.
" Experience building or maturing a third-party risk management program.
" Experience operating in federated, matrixed, or multi-business enterprise environments.
" Familiarity with AI governance or emerging technology risk
" Experience supporting risk-focused governance forums or steering committees.