Manage and evolve the vendor risk assessment program.
Design the due diligence process, implement risk mitigation strategies, and work with procurement and legal to ensure contractual security clauses are enforced.
Manage vendor cybersecurity risk across the global supply chain.
Implement frameworks such as NIST CSF and develop risk scores based on vendors’ impact and criticality to the business.
Champion third-party cybersecurity risk across the organization.
Conduct continuous monitoring, lead incident response coordination for vendor-related breaches, and provide executive reporting.
Report regularly to senior leadership, including CISO, on the state of third-party security risk.
Maintain a risk register of critical vendor findings, ensure timely remediation, and track SLAs.
Serve as the primary contact for vendor security discussions, due diligence support, and ongoing relationship management.
Provide guidance to business units and project teams during vendor selection and procurement processes.
Optionally, review vendor Data Protection Impact Assessments (DPIAs) and participate in privacy-related risk analysis.
Requirements
Bachelor’s degree, or equivalent experience.
Certifications a plus.
10+ years related experience.
Experience in project management, from conception to delivery.
Experience in managing large, complex projects and large teams.
Experience managing consultants/contractors at scale.
Extensive experience with a variety of security control tools and processes.
Benefits
Competitive healthcare, dental & vision insurance
401(k) matching after one year of employment
Generous time off + company holidays
Merchandise discount
Learning & Development programs
Much more!
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.