Jobs Companies Gong.io Senior TPRM Security Lead

About this Senior TPRM Security Lead role at Gong.io

Gong.io · Onsite · Austin | Chicago | New York City | Salt Lake City | San Francisco

Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world’s most successful revenue teams. Powered by the Gong Revenue Graph, AI-powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort. For more information, visit www.gong.io.

At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.

Gong is seeking an experienced Third Party Risk Manager to join our Governance, Risk, and Compliance (GRC) team. In this role, you will own and mature Gong's third-party risk management program, ensuring that vendors, suppliers, and partners meet our security, privacy, compliance, and operational resilience standards. You will establish baselines and controls that Gong can implement to proactively address third-party risk, and apply a risk-based approach to vendor reviews—prioritizing effort based on the criticality, data access, and inherent risk of each vendor. You will build a program that is robust and scalable, evolving to meet the business's needs as Gong grows. You will partner cross-functionally with Procurement, Legal, Security, Privacy, and business stakeholders to assess, monitor, and mitigate risks across the full vendor lifecycle. This role will report directly into the Head of GRC and operate both strategically and very hands-on.

RESPONSIBILITIES
  • Own the end-to-end third-party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.
  • Establish baselines and controls that Gong can implement to reduce and manage third-party risk across the vendor portfolio.
  • Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality.
  • Build a robust and scalable TPRM program that adapts to evolving business needs and supports Gong's growth.
  • Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements.
  • Partner with Procurement and Legal to embed risk requirements into contracts, data processing agreements, and vendor onboarding workflows.
  • Maintain and enhance the TPRM framework, policies, standards, and procedures in alignment with frameworks such as SOC 2, ISO 27001, and relevant privacy regulations (e.g., GDPR, CCPA).
  • Manage continuous monitoring of the vendor portfolio, including periodic reassessments, tiering, and tracking of remediation items.
  • Administer and optimize TPRM tooling and automation to scale the program.
  • Report on third-party risk posture, key metrics, and trends to GRC leadership and relevant stakeholders.
  • Support audit and customer assurance activities related to third-party risk.
  • Experience handling security agreements between vendors - and holding vendors accountable to such agreements.
QUALIFICATIONS 
  • 7+ years of experience in third-party/vendor risk management, GRC, information security, or a related field.
  • Demonstrated ability to establish baselines and controls and take a risk-based approach to vendor reviews.
  • Strong working knowledge of security and compliance frameworks (SOC 2, ISO 27001, NIST) and data privacy regulations.
  • Experience conducting vendor risk assessments and interpreting security documentation (e.g., SOC 2 reports, pen test results, questionnaires).
  • Excellent cross-functional collaboration and communication skills, with the ability to translate risk into business terms.
  • Experience with TPRM tooling (e.g., Zip).
  • Relevant certifications (e.g., CTPRP, CISA, CISSP, CRISC) are a plus.
PERKS & BENEFITS 
  • We offer Gongsters a variety of medical, dental, and vision plans, designed to fit you and your family’s needs.
  • Wellbeing Fund - flexible wellness stipend to support a healthy lifestyle.
  • Mental Health benefits with covered therapy and coaching.
  • 401(k) program to help you invest in your future.
  • Education & learning stipend for personal growth and development.
  • Flexible vacation time to promote a healthy work-life blend.
  • Paid parental leave to support you and your family.
  • Company-wide recharge days each quarter.
  • Work from home stipend to help you succeed in a remote environment.

The annual salary hiring range for this position is $117,000 - $185,000 USD. 

Compensation is based on factors unique to each candidate, including, but not limited to, job-related skills, qualification, education, experience, and location. At Gong, we have a location-based compensation structure, which means there may be a different range for candidates in other locations. The total compensation package for this position, in addition to base compensation, may include incentive compensation, bonus, equity, and benefits. Some of our sales compensation programs also offer the potential to achieve above targeted earnings for those who exceed their sales targets. 

We are always looking for outstanding Gongsters! So if this sounds like something that interests you regardless of compensation, please reach out. We may have more roles for you to consider and would love to connect.

We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Gong recruiting email communications will always come from the @gong.io domain. Any outreach claiming to be from Gong via other sources should be ignored.


Gong is an equal-opportunity employer. We believe that diversity is integral to our success, and do not discriminate based on race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, military status, genetic information, or any other basis protected by applicable law.

To review Gong's privacy policy, visit https://www.gong.io/gong-io-job-candidates-privacy-notice/ for more details.

#LI-SM1

Ready to apply to Gong.io?
Apply to Gong.io

Similar jobs

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Gong.io

See all jobs at Gong.io →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free