Назад
Company hidden
5 дней назад

Senior Manager, Third Party Risk (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Manager, Third Party Risk (Cybersecurity): Building and maturing an enterprise third-party risk management program for vendors handling protected health and sensitive personal data with an accent on vendor lifecycle governance, security assessments, user access reviews, and regulatory compliance. Focus on assessing high-risk vendors, driving audit readiness across ISO 27001, ISO 27701, ISO 42001, and HITRUST, and enforcing least-privilege access across employees, contractors, and vendors.

Location: Remote in the United States, with occasional travel to headquarters in Houston, Texas, for meetings, vendor audits, or conferences.

Company

Clinical genetic testing laboratory handling protected health information and sensitive personal information.

What you will do

  • Lead and continuously mature the enterprise third-party risk management program for upstream and downstream vendors.
  • Own vendor intake, inherent-risk scoring, risk-tier assignment, security and privacy assessments, onboarding, monitoring, reassessment, and offboarding.
  • Conduct vendor audits and maintain risk heat maps, remediation tracking, and a centralized vendor risk record.
  • Develop and manage quarterly User Access Reviews across applications, including privileged and administrator accounts.
  • Drive audit readiness and evidence collection for ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, GDPR, and related requirements.
  • Produce risk metrics and collaborate with Security, Privacy, Compliance, Legal, Procurement, and application teams.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience.
  • 6–8 years of experience in information security, risk, or compliance, including experience creating and running vendor management programs.
  • Hands-on audit experience with ISO 27001, ISO 27701, and ISO 42001, plus demonstrated HITRUST experience.
  • Experience managing recurring User Access Review programs and least-privilege access controls.
  • Knowledge of vendor risk assessment methodologies, including SIG questionnaires, risk scoring, and risk tiering.
  • Must be based in the United States; occasional travel to Houston headquarters is required.

Nice to have

  • CTPRP, CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer certification.
  • Experience with GRC platforms such as TrustArc and vendor risk tooling.
  • Experience in healthcare, clinical laboratory, or another HIPAA- and PHI-regulated environment.
  • People- or program-management experience coordinating cross-functional assessments.

Culture & Benefits

  • Remote work arrangement with occasional travel for meetings, vendor audits, and conferences.
  • Opportunity to support a culture of integrity, service, respect, and professional conduct.
  • Collaboration across Security, Privacy, Compliance, Procurement, Legal, and business teams.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →