Live opening · Posted 7 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
1. About Our Client:
The organization operates within the information security and risk management sector, focusing on securing technology systems and business processes against vulnerabilities and compliance risks. It addresses challenges related to third-party and internal IT risk assessments, ensuring adherence to security policies and standards to protect company information and assets. The organization manages complex relationships with service providers and collaborates across departments to maintain an effective security posture.
2. About the Opportunity:
The Senior Manager, Information Security (Vendor Security Risk) role is responsible for executing thorough third-party risk assessments and supporting the overall security program. This position evaluates vendor control environments, documents risk findings, and ensures compliance with security policies. It plays a key role in managing vendor relationships, escalating risks, and guiding security strategies to protect organizational assets.
3. Responsibilities:
Conduct periodic reassessments of vendors based on risk tiering and data sensitivity
Review vendor-provided security evidence and identify control gaps and risks
Support management of service provider relationships and outcomes
Collaborate with IT and business stakeholders to develop security strategies
Plan, direct, and coordinate compliance activities related to technology projects
Communicate effectively with all organizational levels
Manage shifting priorities and multiple concurrent assessments
Oversee and validate documentation to ensure compliance with security and privacy requirements
Identify and escalate significant control deficiencies or risk conditions
Perform structured security risk assessments of third-party providers
Document control gap analyses and risk assessments clearly
Review control exception requests and provide risk-based recommendations
Interpret security findings from vendors and internal sources
Lead or participate in infrastructure compliance initiatives
Monitor compliance with security policies and report risks
Administer processes and tools for third-party risk and compliance tracking
Assess threats, vulnerabilities, and recommend mitigation measures
Provide advice and advocate for policy changes within information security
Oversee the information assurance program of information systems
Submit timely reports and document project progress accurately
Manage multiple assessments and prioritize deliverables
4. Requirements:
Bachelor’s degree in Information Systems or related field, or equivalent experience/certification
7+ years of information technology leadership with security policy implementation and governance
3+ years of direct experience in third-party risk management
Current information security certification such as CRISC, CISM, CISA, or CISSP
Preferred: Security certifications like GWAPT, GPEN, AWS Architect, PCI experience
Proven ability to engage stakeholders at various organizational levels
Experience executing vendor risk assessments within a defined framework
Ability to escalate high-risk scenarios with clear risk summaries and recommendations
Strong skills in analyzing control evidence and documenting risks
Experience in technical leadership in outsourced environments
Excellent communication and problem-solving skills
Experience assessing security controls of cloud service providers and SaaS vendors
Knowledge of OWASP Top 10, SANS 25, and vulnerability management
5. Pay Range and Compensation Package:
The pay range and compensation package for this role will be determined based on the candidate’s experience, skills, and other relevant factors.
Equal Opportunity Statement: Our client is an equal opportunity employer. They celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, or national origin.
Note:
RemoteHunter is a recruitment partner of this role. Please note that all employment decisions, including candidate assessment, interviews, hiring, compensation, and employment terms, are made exclusively by the hiring employer.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.