Skip to main content

Third-Party Cyber Risk Manager

Security and resilience, a mid-level role

What does Third-Party Cyber Risk Manager do?

Evaluates vendors, suppliers, cloud providers and technology partners for cybersecurity and operational risk, and now for the AI they embed and the data it touches.

What it decides: Which suppliers may hold which data, under which contractual and technical conditions.

The competencies employers name

  • AI vendor due diligence and third-party riskcore, depth expected

    Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.

    5 graded topics teach this

  • Contract terms that allocate AI riskcore, depth expected

    Turns controls into enforceable obligations: data use, change notice, audit rights, incident duties, subcontractors, IP, exit and deletion.

    4 graded topics teach this

  • AI security fundamentalsrequired, working knowledge

    Understands prompt injection, data poisoning, model theft, insecure integrations and excessive agent privileges, and the controls that reduce each.

    17 graded topics teach this

  • AI resilience, continuity and exit planningrequired, working knowledge

    Plans for a vendor failure, an unsafe model change or a suspended service: rollback, manual fallback, data export and safe decommissioning.

    3 graded topics teach this

  • Data classification, access and retentionrequired, working knowledge

    Classifies information, applies least privilege, sets retention and acceptable-use rules, and controls what may enter a prompt, a log or an embedding.

    19 graded topics teach this

  • AI risk and impact assessmentrequired, working knowledge

    Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.

    14 graded topics teach this

  • Buying AI wellpreferred, working knowledge

    Writes requirements, runs a fair evaluation, pilots within limits, and refuses a demo as evidence.

    15 graded topics teach this

  • Cross-functional facilitation and influencerequired, working knowledge

    Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.

    20 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

Add what you already have (optional)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

Where it leads

Backgrounds that reach it fastest

What postings tend to name

Frameworks: NIST CSF, ISO/IEC 27001, DORA, NIST AI RMF GOVERN 6.

Credentials often listed: CTPRP, CRISC, CISSP, CISA. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

What is new about third-party risk when the supplier ships AI?
The product can change under you. Model updates, new subprocessors, altered training practices and customer data used to improve the product are risks a point-in-time security questionnaire misses.