Information Security Program Manager

Added
7 days ago
Type
Full time
Salary
Salary not provided

Related skills

cybersecurity jira iso27001 soc 2 nist csf

πŸ“‹ Description

  • Lead and conduct third-party risk assessments focusing on cybersecurity and compliance.
  • Evaluate security questionnaires, SOC 2, ISO 27001/2, and risk docs.
  • Coordinate with vendors to request and verify security controls and remediation plans.
  • Oversee risk remediation efforts with suppliers for timely resolution.
  • Classify vendors by risk tiers and maintain a vendor risk profile database.
  • Partner with Procurement, Legal, Privacy, and InfoSec to improve supplier security.

🎯 Requirements

  • Bachelor's degree in CS, InfoSec, Cybersecurity, Risk Mgmt, or related.
  • 5-8 years in third-party risk assessment in cybersecurity or information risk.
  • Knowledge of ISO27001/2, ISO27017/18, FedRAMP, SOC 2, PCI DSS, NIST CSF.
  • Solid understanding of risk assessment methodologies and best practices.
  • Able to synthesize risk findings for technical and non-technical audiences.
  • Detail-oriented, process-driven, able to manage multiple assessments.
  • Experience with Coupa, OneTrust, JIRA, Coverbase.
  • Certifications such as CISA, CISM, CISSP, CRISC (plus).

🎁 Benefits

  • Inclusive culture that fosters belonging and growth across global teams.
  • Equal opportunity employer with nondiscrimination and inclusive hiring.
  • Commitment to accessibility and reasonable accommodations.
Share job

Meet JobCopilot: Your Personal AI Job Hunter

Automatically Apply to Business & Management Jobs. Just set your preferences and Job Copilot will do the rest β€” finding, filtering, and applying while you focus on what matters.

Related Business & Management Jobs

See more Business & Management jobs β†’