Service Manager – Supplier Security Due Diligence & Monitoring Service

New
J
JobgetherCybersecurity / IT
United StatesFull-TimeManager
Salary120,000 - 193,725 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
7+ years in information security, technology risk, third-party risk management, or related fields; 3+ years in leadership.
Required Skills
Risk Management

Requirements

  • 7+ years of experience in information security, technology risk, third-party risk management, supplier risk management, governance, contracting, procurement, or related fields.
  • 3+ years of leadership experience managing teams, services, programs, or operational functions.
  • Demonstrated ability to evaluate cybersecurity and technology risks using sound risk-based decision-making principles.
  • Strong understanding of supplier risk management practices, security controls, governance frameworks, and risk mitigation strategies.
  • Experience collaborating across Legal, Procurement, Business, Security, and Risk Management functions.
  • Proven ability to interpret cybersecurity requirements and apply them within contractual and business contexts.
  • Strong written, verbal communication, stakeholder management, and executive presentation skills.
  • Experience supporting supplier contract negotiations involving cybersecurity and privacy requirements preferred.
  • Knowledge of third-party risk management programs and supplier security assessment methodologies preferred.
  • Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, NIST 800-53, ISO 27001, CIS Controls, and SOC reporting preferred.
  • Experience with enterprise risk management, governance processes, and risk acceptance workflows preferred.
  • Professional certifications such as CISSP, CISM, CRISC, ITIL, PMP, or similar credentials are a plus.

Responsibilities

  • Lead the daily operations and strategic direction of the supplier security due diligence and monitoring service.
  • Manage and develop a team responsible for supplier security contracting support and risk-based decision-making.
  • Review supplier security assessments and monitoring outcomes to guide contractual negotiations and risk decisions.
  • Translate cybersecurity requirements into practical contractual positions, fallback language, and appropriate risk mitigation strategies.
  • Ensure consistent application of enterprise security standards across supplier agreements and business engagements.
  • Oversee documentation, tracking, and governance of contractual exceptions, security deviations, and risk accommodations.
  • Escalate supplier security positions that exceed established risk tolerances through appropriate governance and approval processes.
  • Partner with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier challenges.
  • Establish service-level objectives, operational metrics, reporting frameworks, and quality management practices.
  • Drive continuous improvement initiatives to increase scalability, consistency, and stakeholder satisfaction.
View Full Description & ApplyYou'll be redirected to the employer's site
120,000 - 193,725 USD per year
Apply Now