Senior TPRM Security Lead
Gong.io
Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world’s most successful revenue teams. Powered by the Gong Revenue Graph, AI-powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort. For more information, visit www.gong.io.
At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.
Gong is seeking an experienced Third Party Risk Manager to join our Governance, Risk, and Compliance (GRC) team. In this role, you will own and mature Gong's third-party risk management program, ensuring that vendors, suppliers, and partners meet our security, privacy, compliance, and operational resilience standards. You will establish baselines and controls that Gong can implement to proactively address third-party risk, and apply a risk-based approach to vendor reviews—prioritizing effort based on the criticality, data access, and inherent risk of each vendor. You will build a program that is robust and scalable, evolving to meet the business's needs as Gong grows. You will partner cross-functionally with Procurement, Legal, Security, Privacy, and business stakeholders to assess, monitor, and mitigate risks across the full vendor lifecycle. This role will report directly into the Head of GRC and operate both strategically and very hands-on.
RESPONSIBILITIES
- Own the end-to-end third-party risk lifecycle: intake, due diligence, risk assessment, onboarding, ongoing monitoring, and offboarding.
- Establish baselines and controls that Gong can implement to reduce and manage third-party risk across the vendor portfolio.
- Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality.
Don't want to miss the next one?
Subscribe to daily email alerts for roles matching your interests.

