5 дней назад
Senior Manager, Third Party Risk (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Manager, Third Party Risk (Cybersecurity): Building and maturing an enterprise third-party risk management program for vendors handling protected health and sensitive personal data with an accent on vendor lifecycle governance, security assessments, user access reviews, and regulatory compliance. Focus on assessing high-risk vendors, driving audit readiness across ISO 27001, ISO 27701, ISO 42001, and HITRUST, and enforcing least-privilege access across employees, contractors, and vendors.
Location: Remote in the United States, with occasional travel to headquarters in Houston, Texas, for meetings, vendor audits, or conferences.
Company
Clinical genetic testing laboratory handling protected health information and sensitive personal information.
What you will do
- Lead and continuously mature the enterprise third-party risk management program for upstream and downstream vendors.
- Own vendor intake, inherent-risk scoring, risk-tier assignment, security and privacy assessments, onboarding, monitoring, reassessment, and offboarding.
- Conduct vendor audits and maintain risk heat maps, remediation tracking, and a centralized vendor risk record.
- Develop and manage quarterly User Access Reviews across applications, including privileged and administrator accounts.
- Drive audit readiness and evidence collection for ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, GDPR, and related requirements.
- Produce risk metrics and collaborate with Security, Privacy, Compliance, Legal, Procurement, and application teams.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience.
- 6–8 years of experience in information security, risk, or compliance, including experience creating and running vendor management programs.
- Hands-on audit experience with ISO 27001, ISO 27701, and ISO 42001, plus demonstrated HITRUST experience.
- Experience managing recurring User Access Review programs and least-privilege access controls.
- Knowledge of vendor risk assessment methodologies, including SIG questionnaires, risk scoring, and risk tiering.
- Must be based in the United States; occasional travel to Houston headquarters is required.
Nice to have
- CTPRP, CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer certification.
- Experience with GRC platforms such as TrustArc and vendor risk tooling.
- Experience in healthcare, clinical laboratory, or another HIPAA- and PHI-regulated environment.
- People- or program-management experience coordinating cross-functional assessments.
Culture & Benefits
- Remote work arrangement with occasional travel for meetings, vendor audits, and conferences.
- Opportunity to support a culture of integrity, service, respect, and professional conduct.
- Collaboration across Security, Privacy, Compliance, Procurement, Legal, and business teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Senior Manager, GRC (Healthcare)
170 000 - 201 000$
11 дней назад
Cyber GRC Analyst (Cybersecurity)
11 дней назад
Policy and Compliance Lead (Cybersecurity)
130 000 - 160 000$
6 дней назад
Senior Manager, GRC Technology, Metrics, and Automation (Cybersecurity)
124 400 - 207 400$
DeepL
11 дней назад
Senior Information Security Manager (Cybersecurity)
9 дней назад
Senior Security Compliance Engineer (Cybersecurity)
139 200 - 196 000$