Position Overview: Autodesk’s Third-Party Risk Management (TPRM) team plays a vital role in identifying, assessing, and monitoring Autodesk’s third-party risk posture. TPRM partners with ESE (IT), Procurement, Purchasing, Legal, Trust, Vendor Management, and other group verticals to reduce risk. A key priority is enabling our business leaders through education to address and mitigate third-party risks. You will oversee the entire third-party risk lifecycle, conducting robust due diligence during onboarding, performing comprehensive re-assessments, and managing offboarding procedures. You will evaluate emerging risks introduced by technologies such as Artificial Intelligence (AI), Large Language Models (LLMs), data lakes, and data warehouses. You must collaborate across teams and influence decision-makers to mitigate risks while enabling secure business growth. This is an exciting opportunity to drive innovation through developing risk quantification, use of cutting-edge tooling, and strategic partnerships within Autodesk’s vast and diverse global third-party ecosystem. This role will act as a people leader, program leader, and senior individual contributor all in one. As such, we are looking for someone who can balance wearing all three hats and is excited about: * Growing and building the knowledge and capabilities of their direct reports to expand on our existing agile innovative remote team culture * Shifting between the longer-term strategic vision of the program in collaboration with key stakeholders and delivering on day-to-day operational activities as an experienced and extremely knowledgeable senior individual contributor Responsibilities: * Establish team goals and work with direct reports on strategies for executing, measuring progress, and sharing results * Assessing third-party vendors during due diligence and re-assessment, focusing on trust risks (security, data privacy, resilience, trusted AI, and compliance risks) * Operating and improving Autodesk’s third-party risk management systems, including leveraging tools like OneTrust for workflows and developing models for risk quantification * Partner with Legal, Trust, and business owners to embed comprehensive Trust (security, privacy, resilience, trusted AI) requirements directly into contracts, ensuring alignment with policies and compliance frameworks (e.g., GDPR, CCPA, SOC2, NIST, etc) * Liaising with high-risk vendors to understand their security posture, advocate for aligned improvements, and provide advisory on identified risks * Developing and maintaining processes that enhance the efficiency and scalability of third-party evaluations, continuous monitoring, and offboarding procedures * Maintain a comprehensive third-party risk register and presenting findings, trends, and action plans for senior leadership * Working with internal teams to investigate and respond to third-party related security incidents, defining escalation procedures and remediation requirements * Responsible for the management of all employees in the section including staffing and scheduling, compensation, performance management, training and development * Attract retain and motivate the team to achieve management business objectives. Demonstrated leadership skills to train, develop and coach others in the execution of the program * Actively mentor and train teammates on Third-Party Risk Management processes, governance, and frameworks * Generate innovative ideas and challenge the status quo * Demonstrate 'critical thinking' to analyze complex workflows and big picture themes, make decisions and problem solve without requiring ongoing direction setting * Ability to problem solve and identify solutions to third party risks that are appropriate based on business context and risk materiality * Passionate about rapid value creation through quick wins and long-term balanced value creation * A strong change manager with the tenacity to follow through to closure * Being a good communicator is crucial to the role as we look to paint exciting visuals for overall program designs and operating models to influence partners and leadership Minimum Qualifications: * 7+ years of progressive experience in third-party security or as a principal third-party security assessor, or GRC engineer role, preferably within a technology company * 3+ years of people leadership experience in a globally distributed, hybrid, or remote environment * Professional certifications such as CISSP, CCSP, CCSA, CISM, CIPP/US, CIPP/E, CIPM, CIPT * Hands-on experience with TPRM tools (e.g., OneTrust, ZENGRC, ServiceNOW, BitSight, SecurityScorecard) * Familiarity with security concepts, including IAM, firewalls, APIs, vulnerabilities (CVE), software supply chain risks, data lakes and data warehouses * Proven ability with automation of processes through scripting, AI, or tooling * Strong verbal and written communication and stakeholder engagement skills with experience effectively communicating synchronously and asynchronously in a remote/hybrid environment * Proven ability to influence decision-makers and articulate complex technical risks and control concepts to non-technical stakeholders, including senior executives and audit committees Preferred Qualifications: * Experience negotiating vendor contracts and working to define Trust requirement (security, resilience, AI, privacy) clauses * Familiarity with and/or hands-on experience applying risk quantification frameworks (e.g., FAIR) and risk metrics in reporting * Experience building risk management programs leveraging automation, AI, and continuous monitoring techniques * Familiarity with AI concepts, tools, policies, and best practices, particularly concerning LLM security risks like prompt injection, training data poisoning, and insecure output handling #LI-AD1
Autodesk is changing how the world is designed and made. Our technology spans architecture, engineering, construction, product design, manufacturing, media, and entertainment, empowering innovators everywhere to solve challenges big and small. From greener buildings to smarter products to more mesmerizing blockbusters, Autodesk software helps our customers to design and make a better world for all. Over 100 million people use Autodesk software like AutoCAD, Revit, Maya, 3ds Max, Fusion 360, SketchBook, and more to unlock their creativity and solve important design, business and environmental challenges. Our software runs on both personal computers and mobile devices and taps the infinite computing power of the cloud to help teams around the world collaborate, design, simulate and fabricate their ideas in 3D. We provide exceptional compensation/benefit packages and we’d love for you to join us. We’re proud to be an equal opportunity employer and we consider all qualified applicants without regard to race, gender, disability, veteran status or other protected category. To see our culture in action, check out #AutodeskLife. We are headquartered in the San Francisco Bay Area and have more than 10,000 employees worldwide.
Get notified when new jobs are added by Autodesk