





Strong employer brand, mid-level generalist title, metro location, and broad requirements increase competition.
Specialized third-party cybersecurity and compliance expertise makes background fit highly industry-specific.
Explicit 5–8 years and mandatory third-party security/risk expertise raise filtering rigor.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and conduct comprehensive third-party risk assessments focusing on cybersecurity and regulatory compliance, including evaluation of security questionnaires and audit reports.
Manage risk remediation efforts with suppliers to ensure timely resolution and maintain a detailed vendor risk profile database with risk tier classification.
Collaborate cross-functionally with Procurement, Legal, Privacy, and InfoSec to improve supplier security processes and identify opportunities to automate risk assessment workflows.
Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Risk Management, or related field.
5-8 years of professional experience in third-party risk assessment within cybersecurity or information risk management.
Strong knowledge of information security frameworks and regulatory compliance such as ISO 27001, SOC 2, FedRAMP, PCI DSS, NIST CSF.
Work Experience Required: 5-8 years in third-party risk assessment within cybersecurity or information risk management.
Experienced in coordinating and synthesizing security risks across vendors and internal teams, capable of managing multiple concurrent assessments.
Process-driven with the ability to lead remediation efforts and improve operational efficiency through automation initiatives.
Skilled at communicating complex risk findings effectively to both technical and non-technical stakeholders within a cross-functional environment.