Service Manager – Supplier Security Due Diligence & Monitoring Service
New
J
JobgetherCybersecurity / IT
United StatesFull-TimeManager
Salary120,000 - 193,725 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years in information security, technology risk, third-party risk management, or related fields; 3+ years in leadership.
- Required Skills
- Risk Management
Requirements
- 7+ years of experience in information security, technology risk, third-party risk management, supplier risk management, governance, contracting, procurement, or related fields.
- 3+ years of leadership experience managing teams, services, programs, or operational functions.
- Demonstrated ability to evaluate cybersecurity and technology risks using sound risk-based decision-making principles.
- Strong understanding of supplier risk management practices, security controls, governance frameworks, and risk mitigation strategies.
- Experience collaborating across Legal, Procurement, Business, Security, and Risk Management functions.
- Proven ability to interpret cybersecurity requirements and apply them within contractual and business contexts.
- Strong written, verbal communication, stakeholder management, and executive presentation skills.
- Experience supporting supplier contract negotiations involving cybersecurity and privacy requirements preferred.
- Knowledge of third-party risk management programs and supplier security assessment methodologies preferred.
- Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, NIST 800-53, ISO 27001, CIS Controls, and SOC reporting preferred.
- Experience with enterprise risk management, governance processes, and risk acceptance workflows preferred.
- Professional certifications such as CISSP, CISM, CRISC, ITIL, PMP, or similar credentials are a plus.
Responsibilities
- Lead the daily operations and strategic direction of the supplier security due diligence and monitoring service.
- Manage and develop a team responsible for supplier security contracting support and risk-based decision-making.
- Review supplier security assessments and monitoring outcomes to guide contractual negotiations and risk decisions.
- Translate cybersecurity requirements into practical contractual positions, fallback language, and appropriate risk mitigation strategies.
- Ensure consistent application of enterprise security standards across supplier agreements and business engagements.
- Oversee documentation, tracking, and governance of contractual exceptions, security deviations, and risk accommodations.
- Escalate supplier security positions that exceed established risk tolerances through appropriate governance and approval processes.
- Partner with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier challenges.
- Establish service-level objectives, operational metrics, reporting frameworks, and quality management practices.
- Drive continuous improvement initiatives to increase scalability, consistency, and stakeholder satisfaction.
View Full Description & ApplyYou'll be redirected to the employer's site