Oracle Security is seeking an experienced individual contributor to support and mature the intake function within the Third-Party Risk Management program.
This role will serve as a key front-door control point for third-party risk demand, helping ensure supplier, product, service, SaaS, tooling, and integration requests are identified early, triaged consistently, and routed to the appropriate TPRM path. The role will work across onboarding, procurement, security architecture, legal, privacy, business stakeholders, and other security teams to determine whether a supplier requires standard assessment support, deeper risk review, reuse of an existing assessment, or supplier incident / breach follow-up.
The successful candidate will help shift TPRM earlier into the supplier lifecycle, improve visibility of third-party technology and service risk, reduce ad hoc intake, and support scalable decision-making across Oracle’s broad supplier ecosystem.
Internal Responsibilities
Intake and Triage
- Manage incoming third-party risk requests from onboarding, procurement, security architecture, business stakeholders, security teams, and related intake channels.
- Review supplier, product, service, and engagement details to determine whether TPRM involvement is required.
- Validate whether incoming requests contain sufficient information to support triage, routing, and assessment scoping.
- Identify whether the request relates to a new supplier, existing supplier, changed scope, new integration, sensitive data, customer-impacting service, or elevated-risk activity.
- Route requests into the appropriate TPRM path: no action / reuse, standard assessment, deep dive, or breach / incident support.
- Help reduce fragmented, informal, or late-stage demand by establishing a more consistent front-door process.
Assessment Reuse and Routing
- Check whether an existing TPRM assessment, supplier profile, tiering decision, or risk output can be reused.
- Determine whether the supplier’s current use case materially changes the previous risk position.
- Reduce duplicate assessments by ensuring existing risk decisions are leveraged where current and applicable.
- Escalate higher-risk, unclear, or materially changed requests for deep-dive consideration.
- Ensure downstream teams receive concise, actionable TPRM outputs that allow work to continue without unnecessary rework.
Supplier Entry-Point Integration
- Support integration of TPRM into supplier approval workflows.
- Help identify third-party IT tools, SaaS, integrations, and services that should trigger TPRM review.
- Partner with Security Architecture, Procurement, Legal, Privacy, and LoB stakeholders to improve early supplier risk detection.
- Capture and categorize intake demand signals to support future automation, reporting, and control improvement.
- Help move TPRM from reactive assessment support toward earlier supplier lifecycle control.
Operational Governance and Data Quality
- Maintain accurate intake records, supplier routing decisions, assessment status, and key risk indicators in approved tracking systems.
- Support the development of intake rules, triage criteria, minimum data requirements, decision trees, and process documentation.
- Identify recurring intake gaps, unclear ownership points, and opportunities to simplify or automate routing.
- Help maintain linkage between intake, supplier tiering, assessment activity, findings, continual monitoring services, and future capabilities.
- Support clean handoffs between intake, standard assessment activity, deep-dive work, and breach / incident follow-up.
Breach and Incident Signal Support
- Support initial supplier-risk triage for supplier breach, ransomware, malware, certificate compromise, data exposure, and other third-party incident signals.
- Help determine whether Oracle may be impacted by a supplier event.
- Gather key information such as affected services, data exposure, compromise window, containment evidence, Oracle dependencies, and recommended actions.
- Route supplier incident matters to the appropriate internal teams where deeper security, legal, privacy, customer, product, or infrastructure review is required.
- Ensure supplier incident signals feed back into reassessment, findings management, continual monitoring, and supplier risk records.
External Responsibilities
Intake and Triage
- Manage incoming third-party risk requests from onboarding, procurement, security architecture, business stakeholders, security teams, and related intake channels.
- Review supplier, product, service, and engagement details to determine whether TPRM involvement is required.
- Validate whether incoming requests contain sufficient information to support triage, routing, and assessment scoping.
- Identify whether the request relates to a new supplier, existing supplier, changed scope, new integration, sensitive data, customer-impacting service, or elevated-risk activity.
- Route requests into the appropriate TPRM path: no action / reuse, standard assessment, deep dive, or breach / incident support.
- Help reduce fragmented, informal, or late-stage demand by establishing a more consistent front-door process.
Assessment Reuse and Routing
- Check whether an existing TPRM assessment, supplier profile, tiering decision, or risk output can be reused.
- Determine whether the supplier’s current use case materially changes the previous risk position.
- Reduce duplicate assessments by ensuring existing risk decisions are leveraged where current and applicable.
- Escalate higher-risk, unclear, or materially changed requests for deep-dive consideration.
- Ensure downstream teams receive concise, actionable TPRM outputs that allow work to continue without unnecessary rework.
Supplier Entry-Point Integration
- Support integration of TPRM into supplier approval workflows.
- Help identify third-party IT tools, SaaS, integrations, and services that should trigger TPRM review.
- Partner with Security Architecture, Procurement, Legal, Privacy, and LoB stakeholders to improve early supplier risk detection.
- Capture and categorize intake demand signals to support future automation, reporting, and control improvement.
- Help move TPRM from reactive assessment support toward earlier supplier lifecycle control.
Operational Governance and Data Quality
- Maintain accurate intake records, supplier routing decisions, assessment status, and key risk indicators in approved tracking systems.
- Support the development of intake rules, triage criteria, minimum data requirements, decision trees, and process documentation.
- Identify recurring intake gaps, unclear ownership points, and opportunities to simplify or automate routing.
- Help maintain linkage between intake, supplier tiering, assessment activity, findings, continual monitoring services, and future capabilities.
- Support clean handoffs between intake, standard assessment activity, deep-dive work, and breach / incident follow-up.
Breach and Incident Signal Support
- Support initial supplier-risk triage for supplier breach, ransomware, malware, certificate compromise, data exposure, and other third-party incident signals.
- Help determine whether Oracle may be impacted by a supplier event.
- Gather key information such as affected services, data exposure, compromise window, containment evidence, Oracle dependencies, and recommended actions.
- Route supplier incident matters to the appropriate internal teams where deeper security, legal, privacy, customer, product, or infrastructure review is required.
- Ensure supplier incident signals feed back into reassessment, findings management, continual monitoring, and supplier risk records.