обновлено 13 дней назад
IT Security Manager - Third-Party IT Risk Manager
118 300 - 207 400$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
IT Security Manager - Third-Party IT Risk Manager (Cybersecurity/TPRM): Leading and modernizing a global third-party cyber risk management program with an accent on continuous monitoring, technical validation, automation, AI, and risk quantification. Focus on building scalable assurance models, assessing high-risk suppliers, strengthening third-party contracts, and reporting cyber risk to senior leadership.
Location: USA - Riverwoods, Illinois; hybrid work with possible onsite interviews
Salary: $118,300–$207,400 USD per year, plus bonus eligibility
Company
provides information, software, and services for professional and business customers.
What you will do
- Lead and modernize the global third-party IT risk management program and operating model.
- Shift the program from questionnaire-driven assessments to data-driven assurance using technical validation, continuous monitoring, AI-assisted techniques, and risk quantification.
- Implement monitoring, automation, evidence collection, risk scoring, exception management, and emerging supplier-risk intelligence capabilities.
- Review third-party contracts, identify security gaps, and negotiate requirements and enhancements with suppliers.
- Maintain the enterprise inventory of third-party relationships, risk tiers, and treatment decisions.
- Build and lead a high-performing team while reporting third-party cyber risk trends and concentration risk to senior leadership.
Requirements
- Bachelor’s degree in computer science, information security, management information systems, or a similar field.
- 12+ years of experience in cybersecurity, technology risk, or information security, including ownership of third-party or supplier cyber risk in complex enterprises.
- 5+ years of leadership experience, including direct management or functional delivery leadership.
- Experience designing and leading a global TPRM program across the full third-party risk lifecycle.
- Technical fluency across cloud platforms, APIs, identity, data flows, and integration architectures, plus experience with architecture reviews, vulnerability assessments, penetration testing, and threat modeling.
- Strong executive communication and stakeholder-influence skills across Technology, Procurement, Legal, Privacy, and Enterprise Risk Management.
Nice to have
- Knowledge of systemic, concentration, and fourth-party risk.
- Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA.
- Relevant certifications such as CISSP, CISM, CTPRP, CRISC, or CISA.
Culture & Benefits
- Hybrid work environment with an emphasis on accountability, innovation, and constructive challenge.
- Medical, dental, and vision plans.
- 401(k), FSA/HSA, commuter benefits, and tuition assistance.
- Vacation, sick time, and paid parental leave.
Hiring process
- Interviews are conducted without AI tools, virtual backgrounds, or external prompts.
- In-person interviews may be required at a office.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Third Party Risk Management Director
116 600 - 217 300$
14 дней назад
Senior Information Security Analyst (Cybersecurity)
94 400 - 129 800$
12 дней назад
Vice President, IT Governance, Risk & Compliance (Cybersecurity)
220 000 - 330 000$
13 дней назад
Security Architecture Manager (Cybersecurity)
138 000 - 219 000$
13 дней назад
Manager, Risk and Comliance
111 200 - 190 300$
13 дней назад
Sr Manager - Cyber Defense (Cybersecurity)
136 500 - 241 500$