August 18
• The role will focus on conducting third-party vendor security assessments and managing supply chain threats. • Assess, track, measure, and report third-party cyber risk across the global organization. • Lead the third-party cyber risk management lifecycle, from executing onboarding security reviews to the offboarding of vendors. • Develop an annual calendar of third-party re-assessment cyber security reviews on cyber risk presented to the organization. • Define and introduce required third-party security assessments based on services consumed by the organization. • Identify and create appropriate cyber security risk MI across the third-party vendor estate. • Identify and implement improvements in current third-party processes and procedures. • Conduct third-party cyber security assessments and identify controls to mitigate cyber risks. • Follow established third-party cyber security risk management program guidelines. • Collaborate with internal business teams and various risk/compliance subject matter experts. • Conduct reviews of IS clauses included in third-party contracts. • Design and deliver training and education of staff in third-party risk management processes. • Perform other cyber security risk duties as needed. • Lead the third-party cyber risk team members and supervise junior team members.
• A bachelor’s degree from an accredited college or university • At least 3- 5 years’ management experience • 5+ years’ experience as a skilled practitioner in third-party or cyber/IS Risk Management • Skilled practitioner in identifying cyber security risks in cloud services and providing mitigating controls • Skilled practitioner in the mitigation and/or remediation of cybersecurity vulnerabilities • Strong practitioner knowledge of third-party risk strategies and best practices • Relevant industry certifications e.g., CRISC, CISM, CISA, ISO/IEC 27001 Lead Auditor • Working knowledge and experience with industry standards and best practice including the ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and NIST Cybersecurity Framework
• Work from home
Apply Now