Information Security Program Manager
Core
Lead comprehensive risk assessments and manage security compliance for third-party vendors and service providers to ensure organizational resilience.
Role type
Senior IC Information Security Program Manager (Third-Party Risk)
Builds
Vendor risk profiles, remediation plans, and automated assessment processes
Domain
Cybersecurity, Third-Party Risk Management, Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Third-party risk assessment, vendor governance, security questionnaire evaluation, audit report analysis (SOC 2, ISO 27001), risk classification, cross-functional collaboration, process automation, team mentorship
Preferred skills
Experience with Coupa, OneTrust, JIRA, Coverbase; CISA, CISM, CISSP, or CRISC certifications
Technologies
Coupa, OneTrust, JIRA, Coverbase
Responsibilities
Lead and conduct comprehensive risk assessments of new and existing third-party vendors; Evaluate third-party security questionnaires and audit reports; Coordinate with vendors to verify security controls and remediation plans; Classify vendors according to risk tiers; Partner with Procurement, Legal, and InfoSec teams to improve supplier security processes; Manage and mentor contractors and junior team members; Identify opportunities to automate parts of the assessment process
Seniority
Senior, hands-on IC with mentorship responsibilities