IT Security Manager - Third-Party IT Risk Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
IT Security Manager - Third-Party IT Risk Manager (Cybersecurity): Leading and modernizing the global third-party cyber risk management capability with an accent on shifting from questionnaire-centric models to data-driven, intelligence-led programs. Focus on implementing continuous monitoring, automation, and AI-assisted techniques to provide real-time insight into supplier risk.
Location: USA - Riverwoods, IL (Hybrid)
Salary: $118,300.00 - $207,400.00 USD
Company
A global provider of professional information services and software solutions for clinicians, accountants, and other professionals.
What you will do
- Lead and evolve the global Third Party Risk Management (TPRM) program and operating model to ensure it is scalable and risk-based.
- Modernize TPITRM by transitioning to a data-driven program incorporating technical validation, continuous monitoring, and AI.
- Review and analyze third-party contracts to ensure company assets and requirements are sufficiently protected.
- Maintain a centralized enterprise-wide inventory of third-party relationships, risk tiers, and treatment decisions.
- Provide reporting on third-party cyber risk posture, trends, and concentration risk to senior leadership.
- Manage and develop a high-performing team of third-party risk professionals and technical reviewers.
Requirements
- Bachelor's degree in Computer Science, Information Security, Management Information Systems, or similar.
- 12+ years of experience in cybersecurity, technology risk, or information security.
- 5+ years of leadership experience (direct managerial or functional delivery).
- Proven experience designing and leading a global TPRM program in large, complex enterprises.
- Technical fluency in cloud platforms, APIs, identity, data flows, and integration architectures.
- Must be able to appear onsite at a office as part of the recruitment process.
Nice to have
- Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA.
- Relevant certifications such as CISSP, CISM, CTPRP, CRISC, or CISA.
- Familiarity with systemic, concentration, and fourth-party risk.
Culture & Benefits
- Comprehensive Medical, Dental, and Vision plans.
- Retirement and savings options including 401(k), FSA, and HSA.
- Commuter benefits and Tuition Assistance Plan.
- Paid vacation, sick time, and parental leave.
Hiring process
- Interviews are conducted strictly without the assistance of AI tools or external prompts.
- Requirement to remove virtual backgrounds during interviews to ensure authenticity.
- Process includes in-person interviews at a company office.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →