Third-Party Cyber Risk Manager
Security and resilience, a mid-level role
What does Third-Party Cyber Risk Manager do?
Evaluates vendors, suppliers, cloud providers and technology partners for cybersecurity and operational risk, and now for the AI they embed and the data it touches.
What it decides: Which suppliers may hold which data, under which contractual and technical conditions.
The competencies employers name
- AI vendor due diligence and third-party riskcore, depth expected
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
5 graded topics teach this
- Contract terms that allocate AI riskcore, depth expected
Turns controls into enforceable obligations: data use, change notice, audit rights, incident duties, subcontractors, IP, exit and deletion.
4 graded topics teach this
- AI security fundamentalsrequired, working knowledge
Understands prompt injection, data poisoning, model theft, insecure integrations and excessive agent privileges, and the controls that reduce each.
17 graded topics teach this
- AI resilience, continuity and exit planningrequired, working knowledge
Plans for a vendor failure, an unsafe model change or a suspended service: rollback, manual fallback, data export and safe decommissioning.
3 graded topics teach this
- Data classification, access and retentionrequired, working knowledge
Classifies information, applies least privilege, sets retention and acceptable-use rules, and controls what may enter a prompt, a log or an embedding.
19 graded topics teach this
- AI risk and impact assessmentrequired, working knowledge
Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.
14 graded topics teach this
- Buying AI wellpreferred, working knowledge
Writes requirements, runs a fair evaluation, pilots within limits, and refuses a demo as evidence.
15 graded topics teach this
- Cross-functional facilitation and influencerequired, working knowledge
Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.
20 graded topics teach this
Where it is taught
Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.
- The AI Lobbyist: Certified AI Policy Strategist21 topics
- Certified AI Practitioner: Workplace Foundations16 topics
- Certified AI Transformation Professional (CATP)15 topics
- Certified AI Data Governance Professional (CADGP)14 topics
- EU AI Act Implementation Expert9 topics
- Certified Agentic AI Governance Professional (CAAGP)7 topics
- Certified AI Governance Professional (CAIGP)6 topics
Check your readiness for this role
Add what you already have (optional)
Roles that feed into it
- Third-Party Risk Analyst
- Security Assessor
- Procurement Analyst
- Cybersecurity Risk Analyst
Where it leads
- AI Vendor Risk Manager
- Director of Third-Party Risk
Backgrounds that reach it fastest
What postings tend to name
Frameworks: NIST CSF, ISO/IEC 27001, DORA, NIST AI RMF GOVERN 6.
Credentials often listed: CTPRP, CRISC, CISSP, CISA. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.
Questions
- What is new about third-party risk when the supplier ships AI?
- The product can change under you. Model updates, new subprocessors, altered training practices and customer data used to improve the product are risks a point-in-time security questionnaire misses.