Назад
Company hidden
обновлено 13 дней назад

IT Security Manager - Third-Party IT Risk Manager

118 300 - 207 400$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Security Manager - Third-Party IT Risk Manager (Cybersecurity/TPRM): Leading and modernizing a global third-party cyber risk management program with an accent on continuous monitoring, technical validation, automation, AI, and risk quantification. Focus on building scalable assurance models, assessing high-risk suppliers, strengthening third-party contracts, and reporting cyber risk to senior leadership.

Location: USA - Riverwoods, Illinois; hybrid work with possible onsite interviews

Salary: $118,300–$207,400 USD per year, plus bonus eligibility

Company

hirify.global provides information, software, and services for professional and business customers.

What you will do

  • Lead and modernize the global third-party IT risk management program and operating model.
  • Shift the program from questionnaire-driven assessments to data-driven assurance using technical validation, continuous monitoring, AI-assisted techniques, and risk quantification.
  • Implement monitoring, automation, evidence collection, risk scoring, exception management, and emerging supplier-risk intelligence capabilities.
  • Review third-party contracts, identify security gaps, and negotiate requirements and enhancements with suppliers.
  • Maintain the enterprise inventory of third-party relationships, risk tiers, and treatment decisions.
  • Build and lead a high-performing team while reporting third-party cyber risk trends and concentration risk to senior leadership.

Requirements

  • Bachelor’s degree in computer science, information security, management information systems, or a similar field.
  • 12+ years of experience in cybersecurity, technology risk, or information security, including ownership of third-party or supplier cyber risk in complex enterprises.
  • 5+ years of leadership experience, including direct management or functional delivery leadership.
  • Experience designing and leading a global TPRM program across the full third-party risk lifecycle.
  • Technical fluency across cloud platforms, APIs, identity, data flows, and integration architectures, plus experience with architecture reviews, vulnerability assessments, penetration testing, and threat modeling.
  • Strong executive communication and stakeholder-influence skills across Technology, Procurement, Legal, Privacy, and Enterprise Risk Management.

Nice to have

  • Knowledge of systemic, concentration, and fourth-party risk.
  • Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA.
  • Relevant certifications such as CISSP, CISM, CTPRP, CRISC, or CISA.

Culture & Benefits

  • Hybrid work environment with an emphasis on accountability, innovation, and constructive challenge.
  • Medical, dental, and vision plans.
  • 401(k), FSA/HSA, commuter benefits, and tuition assistance.
  • Vacation, sick time, and paid parental leave.

Hiring process

  • Interviews are conducted without AI tools, virtual backgrounds, or external prompts.
  • In-person interviews may be required at a hirify.global office.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →