You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential. The Senior Consultant, Third Party Risk Management (TPRM) is the front door for new third party engagements. This role co-leads the intake and review of net new vendors, serves as the liaison and “shepherd” across Business Leadership, Procurement, Legal, InfoSec and other stakeholders to create a seamless experience. The role is central to maintaining CNA’s standards for vendor onboarding and risk control throughout the lifecycle. JOB DESCRIPTION: Core Responsibilities Manage the intake and reviews for all net‑new vendors entering the organization; validate scope, data flows, service criticality, and inherent risk indicators at the point of request. Operate the intake workflow across Workday Strategic Sourcing (WSS) and ProcessUnity (PU); ensure requests are properly classified and routed. Collaborate with Procurement to align intake with sourcing milestones (RFP/RFI, contract negotiation) Produce Reporting metrics on intake volumes, SLA adherence, inherent risk distribution, and critical third party supplier activities. Apply a pragmatic triage model (e.g., exempt items; existing supplier/same scope; existing supplier/new scope; new supplier/new scope) to focus effort on where risk is highest and eliminate unnecessary reviews. Function as the liaison across Procurement, Legal, InfoSec/Tech Risk, Privacy, Business/Operational Resiliency, and Finance to orchestrate TPRM activities within the contracting process, ensuring a seamless and efficient stakeholder experience. Co-lead end‑to-end risk assessments for high‑impact/new vendors: scoping, risk tiering (IRQ), due‑diligence review (DDQ), and control validation (remote or on‑site), with audit‑ready documentation. Coordinate reviews with SMEs (InfoSec, Compliance, Resiliency, Finance); synthesize control gaps and propose remediation, acceptance, or compensating controls in line with the TPRM policy. Provide coaching to business owners, managed service providers and vendors on completing questionnaires, evidence expectations, and timelines; handle escalations and sensitive assessments with discretion. Lead incremental workflow improvements in WSS/PU and support roadmap initiatives (e.g, Intake Optimization, IRQ refresh, scaled issue management, and risk‑intelligence integrations).
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed