Jennifer Caffrey (Terribile)

GRC Program Manager (Third Party Risk) @ MongoDB | Strategic Communications, Compliance Management

New York City Metropolitan Area

About

As a GRC Program Manager at MongoDB with over 12 years of experience, I specialize in governance, risk, and compliance with a focus on third-party risk management. My expertise lies in compliance management, strategic communications, and data management, ensuring robust vendor oversight and risk mitigation. I am committed to fostering efficient and scalable processes that align with organizational goals. At MongoDB, I contribute to enhancing third-party risk frameworks while leveraging my CTPRP certification to promote compliance excellence and operational efficiency.

Experience

  • GRC Program Manager (Third Party Risk) at MongoDB
    Oct 2021 - Present · 4 yrs 9 mos

  • Chubb (1 yr 11 mos)
    • Third Party Cyber Risk Assessor
      Dec 2019 - Oct 2021 · 1 yr 11 mos

    • Information Security Analyst
      Dec 2019 - Oct 2021 · 1 yr 11 mos

      • Led global project assessing all Chubb call centers; reported findings to CISO and CEO. • Conducted risk assessments and remediation aligned with ISO27001 & NIST frameworks. • Partnered with business units across APAC/Far East to strengthen onboarding processes. • Leveraged Bitsight, Dun and Bradstreet and other tools for continuous monitoring and remediation. • Recommended termination of third parties unwilling to align with Chubb’s security standards.

  • CIT (3 yrs 8 mos)
    • Assistant Vice President of Third Party Oversight at CIT
      Dec 2018 - Dec 2019 · 1 yr 1 mo

    • Assistant Vice President Third Party Management
      May 2016 - Dec 2019 · 3 yrs 8 mos

  • ADP (6 yrs)
    • Third Party Security Assessor
      Aug 2014 - Feb 2016 · 1 yr 7 mos

    • Security Analyst
      Aug 2014 - Feb 2016 · 1 yr 7 mos

      • Assessed vendors against ISO27001, SOC2, and PCI standards; reduced backlog of high-risk vendors by 50% in 3 months. • Conducted on-site assessments of data centers and processing facilities. • Partnered with Privacy SMEs to ensure compliance with international and domestic laws. • Spearheaded incident-related projects minimizing ADP data loss from vendor breaches.

    • Third Party Security Advocate
      Jul 2013 - Aug 2014 · 1 yr 2 mos

  • Nordstrom (3 yrs 11 mos)
    • Assistant Manager of Mens Furnishings
      May 2006 - Mar 2010 · 3 yrs 11 mos

    • Intern
      May 2008 - Aug 2008 · 4 mos