Senior Director, Enterprise Third Party Risk
Vertex Pharmaceuticals
August 09, 2026
Remote friendly (Boston, MA)
United States
Corporate Functions
Senior Director, Enterprise Third Party Risk Leader
Key Duties & Responsibilities:
- Lead an end-to-end (E2E) enterprise third-party risk management program, including a Central Risk Management team; ensure processes are implemented and sustained and reporting aligns with corporate/risk policies.
- Oversee supplier criticality assessments across the supplier lifecycle; use criticality dimensions to prioritize fit-for-purpose risk.
- Oversee third-party risk assessments and updates for critical suppliers using a central risk tool; ensure required inputs and automate/maintain other metrics.
- Maintain a centralized supplier risk repository (risk/action plans/timelines/ownership) and produce regular multidimensional risk reports.
- Maintain and update a risk appetite matrix and risk mitigation action list with business lead input.
- Coordinate and participate in joint reviews of mitigation actions; support escalation governance committees.
- Ensure E2E support via appropriate tools/technology (centralized supplier risk register; automated assessment/tracking).
- Lead within a hybrid centralized/federated operating model and manage matrixed resources.
- Partner with strategic sourcing/business owners to integrate supplier landscape into risk strategy and manage risks via mitigations, mitigation timelines, and risk acceptance.
- Own enterprise third-party risk process, policies, and procedures; ensure governance/RACIs and inherent/residual monitoring and reporting.
- Develop risk metrics/KPIs and oversee reporting on program outcomes; establish best practices and drive continuous improvement.
Required Education:
- University degree in Accounting, Finance, or Risk Management.
- Certified professional certifications preferred.
Required Experience:
- 12+ yearsβ risk experience; large multinational publicly held company experience preferred.
Required Knowledge & Skills:
- Strong third-party risk policies/process knowledge; excellent communication with senior leaders and third parties.
- Enterprise mindset; strong analytical/process/project management and continuous improvement skills.
- Ability to lead cross-functional teams, influence, and maintain high-level stakeholder relationships.
- Ability to establish and lead effective governance program.
Pay Range:
- $220,000 - $330,000
Key Duties & Responsibilities:
- Lead an end-to-end (E2E) enterprise third-party risk management program, including a Central Risk Management team; ensure processes are implemented and sustained and reporting aligns with corporate/risk policies.
- Oversee supplier criticality assessments across the supplier lifecycle; use criticality dimensions to prioritize fit-for-purpose risk.
- Oversee third-party risk assessments and updates for critical suppliers using a central risk tool; ensure required inputs and automate/maintain other metrics.
- Maintain a centralized supplier risk repository (risk/action plans/timelines/ownership) and produce regular multidimensional risk reports.
- Maintain and update a risk appetite matrix and risk mitigation action list with business lead input.
- Coordinate and participate in joint reviews of mitigation actions; support escalation governance committees.
- Ensure E2E support via appropriate tools/technology (centralized supplier risk register; automated assessment/tracking).
- Lead within a hybrid centralized/federated operating model and manage matrixed resources.
- Partner with strategic sourcing/business owners to integrate supplier landscape into risk strategy and manage risks via mitigations, mitigation timelines, and risk acceptance.
- Own enterprise third-party risk process, policies, and procedures; ensure governance/RACIs and inherent/residual monitoring and reporting.
- Develop risk metrics/KPIs and oversee reporting on program outcomes; establish best practices and drive continuous improvement.
Required Education:
- University degree in Accounting, Finance, or Risk Management.
- Certified professional certifications preferred.
Required Experience:
- 12+ yearsβ risk experience; large multinational publicly held company experience preferred.
Required Knowledge & Skills:
- Strong third-party risk policies/process knowledge; excellent communication with senior leaders and third parties.
- Enterprise mindset; strong analytical/process/project management and continuous improvement skills.
- Ability to lead cross-functional teams, influence, and maintain high-level stakeholder relationships.
- Ability to establish and lead effective governance program.
Pay Range:
- $220,000 - $330,000