The project is part of a next-generation SaaS technology platform operating in the transportation and supply chain logistics domain. The company behind the platform has decades of industry experience and is recognized as an employer of choice, with a strong culture of innovation and technical excellence.
The platform delivers a suite of data-driven software solutions used daily by millions of customers who rely on accurate, real-time insights to make informed business decisions and improve profitability. At its core, the system supports one of the largest digital marketplaces in its industry, processing hundreds of millions of transactions annually and maintaining a massive database representing hundreds of billions of dollars in global market activity.
The technology stack is built to handle extreme scale, high availability, and data accuracy, enabling customers to operate efficiently in a fast-moving, competitive environment. Engineering teams work on highly distributed systems, advanced data processing pipelines, and analytics-driven services that continuously evolve to meet growing market demands.
You will own AI security governance, Enterprise Risk Management, Third Party Vendor Management end to end, taking partially developed processes and bringing them to a higher level of structure, consistency, automation, and maturity:
Enterprise Risk Management
Maintain and iterate on DAT's enterprise risk management program, keeping the risk register and risk narrative current.
Automate the ongoing collection of security scorecards and risk scoring data to reduce manual, periodic review.
Adjust risk scoring methodology as the threat landscape, business lines, and acquired entities evolve.
AI Security Risk Assessment Program
Design and implement an AI security risk assessment program integrated into DAT's procurement workflow.
Define scoring criteria for AI specific risk, including model access, training data use, data retention, subprocessor exposure, and degree of autonomy.
Partner with Procurement to build an intake and approval gate so AI risk screening happens automatically as part of the buying process.
Apply the same assessment criteria to existing vendors adding or expanding AI capabilities within tools DAT already uses.
Vendor Risk Management Program
Build DAT's vendor risk management program from the ground up, starting with a complete inventory of DAT's vendor footprint, including vendors inherited through acquisition (TruckerTools, Outgo, Convoy).
Design a vendor tiering and ongoing monitoring model, including reassessment triggers and monitoring cadence.
Treat AI adoption as a first class risk dimension in vendor tiering.
Establish workflows for surfacing, tracking, and remediating vendor risk, including contract review triggers, security scorecard integration, and clear ownership per vendor relationship.
Evaluate vendors introduced through M&A activity against the same risk bar as directly sourced vendors.
Program Design Principle
Default to automation or AI leverage as the first design choice across all three programs, building a manual process only when no scalable automated alternative exists.
Required
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience.
6-8 years of experience in GRC, enterprise risk management, or third-party/vendor risk management, with a track record designing or maturing a program rather than only operating within one already built.
Strong experience designing or maturing enterprise level risk management programs, including hands on Third Party / Vendor Risk Management (TPRM/VRM) work.
Experience conducting and designing security risk assessments, and maintaining enterprise risk registers with scoring and treatment or ownership.
Knowledge of security governance frameworks and enterprise security risk methodologies, including NIST CSF.
Experience establishing governance processes, policies, standards, or risk frameworks, rather than simply following existing ones.
Understanding of AI security and AI related enterprise risks, including how to evaluate the security implications of vendors incorporating AI into their products.
Ability to take an immature or partially established program and independently move it toward a mature operating model.
Strong process design and stakeholder management skills, able to work with Security, Procurement, Legal, technical teams, and business leadership.
Preferred
Experience with GRC or TPRM automation platforms (such as Archer, ServiceNow, JIRA, AuditBoard, or LogicGate).
Experience integrating risk or vendor risk programs across previously acquired companies into a single unified program.
CTPRP (Certified Third-Party Risk Professional), CISM, CISSP, or CISA.