Salary
💰 $148,300 - $194,600 per year
Tech Stack
Cyber SecurityUnity
About the role
- Oversee the vendor onboarding process, beginning with inherent risk assessments and tailored due diligence questionnaires.
- Direct continuous monitoring of critical and high-risk vendors using third-party risk intelligence tools (e.g., RiskRecon).
- Manage the function that responds to cybersecurity questionnaires MassMutual receives as a third party to other organizations.
- Provide executive-level reporting on third-party cyber risk posture, metrics, and emerging risks.
- Partner with BISOs, platform engineering, and security control owners to ensure vendor cyber risk is accurately identified and managed.
Requirements
- Bachelor’s degree in information technology, Cyber Security, or a related field.
- 8+ years of experience in cybersecurity, including 4+ years in a leadership role focused on third-party risk management, or vendor assurance.
- Authorized to work in the US without requiring sponsorship now and in the future.
- Knowledge of regulatory frameworks (NIST CSF 2.0, CRI Profile, etc.).
- Strong analytical skills for measuring program effectiveness and driving continuous improvement.
- Demonstrated experience in managing risk assessments, due diligence, and continuous monitoring processes.
- Familiarity with vendor risk intelligence platforms (e.g., RiskRecon) and GRC tools (e.g., Archer, Process Unity).
- Excellent communication and stakeholder engagement skills, including executive-level reporting.
- CISSP, CTPRP, or related certifications preferred.
- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Professional development opportunities
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
cybersecuritythird-party risk managementvendor assurancerisk assessmentsdue diligencecontinuous monitoringanalytical skillsprogram effectivenessregulatory frameworksvendor risk intelligence
Soft skills
leadershipcommunicationstakeholder engagementexecutive-level reportingcontinuous improvement