Назад
Company hidden
обновлено 6 дней назад

IT Security Manager (Cyber Risk & Audit)

145 600 - 187 200$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Security Manager (Cyber Risk & Audit): Designing and leading third-party cyber risk and audit programs, including vendor assessments, continuous monitoring, security requirements, and executive risk reporting, with an accent on TPCRM strategy, governance, and regulatory frameworks. Focus on building a cyber risk audit-as-a-service capability, integrating security requirements into Procurement, Legal, and Compliance workflows, and translating technical findings into business risk decisions.

Location: Plainsboro, New Jersey, 08536, United States

Salary: $145,600 annually

Company

hirify.global provides staffing and employment services for technical professionals.

What you will do

  • Develop and maintain the third-party cyber risk management strategy, security standards, documentation, metrics, and supplier security requirements.
  • Select and deploy continuous monitoring tools, evaluate SOC 1/2 assurance statements, and manage high-risk vendors according to risk appetite.
  • Build a cyber risk audit-as-a-service capability and create a one-to-three-year roadmap for program maturity.
  • Establish the third-party audit lifecycle, manage audit findings, and integrate results into executive dashboards.
  • Partner with Procurement, Legal, Privacy, Compliance, and leadership teams to support risk-based business decisions.

Requirements

  • Bachelor’s degree in Computer Science, MIS, or a related field.
  • At least five years of experience in third-party cyber risk management, information security, and risk management.
  • At least one of the following certifications: CISA, CRISC, CISM, or CISSP.
  • Deep experience with ISO 27001, NIST, GDPR, and SOC 1/2 frameworks.
  • Hands-on experience with GRC platforms such as ServiceNow, Archer, MetricStream, Vanta, or similar tools.

Nice to have

  • Experience driving security roadmaps for large-scale, multinational organizations.
  • Ability to translate technical security findings into business risk implications.
  • Strong facilitation, negotiation, and cross-functional influence skills.

Culture & Benefits

  • Strategic collaboration across Procurement, Legal, Privacy, Compliance, and leadership functions.
  • For temporary assignments lasting 13 weeks or longer: major medical, dental, vision, and 401(k) benefits.
  • Statutory sick pay where required.
  • Reasonable accommodations are available during the employment process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →