Назад
Company hidden
обновлено 1 час назад

Senior Manager, Third-Party Cyber Risk & Audit (TPCRM) (Cybersecurity)

145 600 - 187 200$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Manager, Third-Party Cyber Risk & Audit (TPCRM) (Cybersecurity): Designing and leading a vendor risk management strategy, third-party security assessments, continuous monitoring, and audit programs with an accent on security governance, compliance frameworks, and executive risk reporting. Focus on building a cyber risk audit-as-a-service capability, integrating supplier requirements into Procurement, Legal, and Compliance workflows, and translating technical findings into business risk decisions.

Location: Plainsboro, New Jersey, United States

Salary: $145,600–$187,200 per year

Company

hirify.global provides staffing and professional services, including temporary assignments and employment opportunities.

What you will do

  • Develop and maintain third-party cyber risk management standards, documentation, metrics, and supplier security requirements.
  • Select and deploy continuous monitoring tools and evaluate security assurance reports such as SOC 1 and SOC 2.
  • Build a cyber risk audit-as-a-service capability and execute a one-to-three-year program maturity roadmap.
  • Establish the third-party audit lifecycle, manage findings, and integrate results into executive dashboards.
  • Collaborate with Procurement, Legal, Privacy, and Compliance teams to embed vendor security requirements into enterprise workflows.
  • Advise leadership and support risk-based decisions by communicating technical security findings as business risk implications.

Requirements

  • Bachelor’s degree in Computer Science, MIS, or a related field.
  • At least five years of experience in third-party cyber risk management, information security, and risk management.
  • At least one of the following certifications: CISA, CRISC, CISM, or CISSP.
  • Deep experience with ISO 27001, NIST, GDPR, and SOC 1/2 security and risk frameworks.
  • Hands-on experience with GRC platforms such as ServiceNow, Archer, MetricStream, Vanta, or similar tools.
  • Strong facilitation, negotiation, stakeholder management, and business communication skills.

Nice to have

  • Experience driving security roadmaps for large-scale, multinational organizations.
  • Experience influencing leaders across virtual, multinational teams.

Culture & Benefits

  • For temporary assignments lasting 13 weeks or longer: major medical, dental, vision, and 401(k) benefits.
  • Statutory sick pay is provided where required.
  • Reasonable accommodations are available throughout the employment process.
  • Employment practices include E-Verify participation in certain locations and equal opportunity protections.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →