YOUR IMPACTYou will work out of one of our offices in Atlanta, Darien, Denver, London, New Jersey, New York, Philadelphia, or Washington, DC to lead strategy and program oversight across multiple third-party risk verticals, including suppliers and client-facing collaborators.
You will be responsible for shaping and advancing a unified, end-to-end TPRM framework that supports a diverse and global third-party ecosystem. You will own the design and evolution of the firm's third-party risk lifecycle, including risk identification, onboarding due diligence, risk tiering, ongoing monitoring, issue management, and offboarding governance.
You will ensure that the framework is consistently applied across third-party segments, while incorporating tailored approaches for different risk profiles and engagement models. You will ensure that onboarding processes are efficient, auditable, and aligned with firm risk appetite and user experience expectations.
You will be part of Optimize, McKinsey's global procurement capability, enhancing and protecting the firm's resources and reputation by making responsible buying easy and creating leading solutions and experiences across our third-party ecosystem.You will be joining the Third-Party Risk Strategy pillar of Optimize's Third Party Risk & Social Responsibility team. Thisteam defines and governs the firm's global third-party risk management (TPRM) program, spanning various third-party types and risk domains.
While day-to-day execution is led by the Operations team, you will be accountable for program performance and alignment to strategy. You will assess whether service levels, controls, and processes are operating effectively across verticals, and drive improvements where gaps are identified.
You will define and monitor key program metrics, including service levels, onboarding cycle times, risk coverage, and remediation effectiveness. You will use these insights to optimize performance, reduce risk exposure, and improve the overall third-party experience.
You will partner closely with the governance pillar to inform the development of policies, standards, and control requirements, providing input based on program insights, operational performance, and emerging risks. You will ensure that policies and standards are effectively translated into scalable processes, tools, and workflows across the third-party risk lifecycle. You will stay ahead of evolving regulatory expectations and industry frameworks (e.g., NIST, ISO, SOC, and relevant regulatory guidance), assessing implications for the program and driving necessary enhancements to maintain alignment.
You will own the evolution of third-party risk tooling and digital capabilities, including governance of TPRM platforms, onboarding workflows, data sources, and reporting infrastructure. You will drive the use of data, automation, and analytics to enhance scalability, transparency, and decision-making.
In addition to strategy development, you will lead execution of complex, global initiatives to enhance program capabilities, improve processes, and implement changes across the firm. You will play a key role in strengthening risk management capabilities, including supporting documentation, training, and fostering a strong risk-aware culture.
You will report to the Director of Third Party Risk Strategy and work closely with global stakeholders including Ethics & Compliance, Finance, Legal, Client Service Risk focused specifically on suppliers and client-facing collaborators (CFCs) external entities the firm engages with to deliver products and services, including suppliers, and ecosystem partners. You will be based out of London, Philadelphia, New York, New Jersey, Atlanta, Boston, Miramar, Tampa, or Washington DC office.
YOUR QUALIFICATIONS AND SKILLS- 10+ years in third-party risk management, compliance, or a related field, ideally within a global organization
- Deep expertise in third-party risk management frameworks, including lifecycle design, onboarding processes, and internal control environments across multiple third-party segments
- Experience designing, governing, or advancing enterprise risk programs, with accountability for program performance and outcomes, ideally in a professional services or consulting environment
- Strong understanding of global regulatory expectations and industry frameworks related to third-party risk (e.g., NIST, ISO, SOC, and relevant regulatory guidance)
- Experience with TPRM/GRC platforms and driving digital enablement, including workflow design, data, reporting, and automation
- Exceptional analytical and problem-solving skills, with the ability to translate complex data into actionable insights
- Excellent judgment and exceptional integrity, as well as distinctive interpersonal and collaborative skills
- Proven ability to lead large, cross-functional initiatives and drive execution in complex, global environments
- Curious mindset and demonstrated ability to learn new concepts and ideas, and to apply those concepts across multiple content areas
- Strong professional computing skills, including Microsoft Office products (i.e. Excel, PowerPoint, Visio)
- Comfortable with ambiguity in a work-setting, knowing how to address and manage unpredictable outcomes
- Superior communication & interpersonal skills, including the ability to present to a global audience on a regular basis, build and maintain highly effective and collaborative relationships
Please review the additional requirements regarding essential job functions of McKinsey colleagues.
Our unwavering commitment to integrity drives everything we do, guiding us to always act in the best interests of our clients, our people, and the communities we serve.