Head of Cyber Third Party and Risk Management

MassMutual
Bloomfield, New Jersey, United States
Full-time
We are sorry. The job offer you are looking for is no longer available.

Overview : We are seeking an experienced and strategic leader to join our organization as the Head of Cyber Third Party and Risk Management.

In this critical role, you will be responsible for overseeing and enhancing our third-party cyber risk management program, governance, security awareness and training, and ensuring the security of our business information assets.

You will lead efforts to assess, mitigate, and monitor risks associated with third-party vendors and drive information security risk management across MassMutual’s critical business units / entities.

Key Responsibilities : Leadership and Strategy : Develop and execute a comprehensive third-party risk management strategy aligned with organizational objectives, regulatory requirements, and industry best practices.

Define and implement cyber security strategies, policies, and standards to protect company assets and data. Third-Party Risk Management : Lead the assessment and ongoing monitoring of third-party vendors and partners to identify potential risks and vulnerabilities.

Establish risk assessment frameworks, methodologies, and scoring models to evaluate the security posture of third parties.

Vendor Due Diligence and Contract Management : Implement robust due diligence processes for assessing the security capabilities of prospective vendors and partners.

Collaborate with legal and procurement teams to incorporate security requirements into vendor contracts and agreements. Risk Mitigation and Remediation : Develop and oversee the implementation of risk mitigation strategies and controls to address identified vulnerabilities and risks with third parties.

Monitor and track remediation efforts to ensure timely resolution of security issues impacting third-party relationships.

Cyber Security Governance : Develop and enforce cyber security policies, standards, and guidelines across the organization.

Ensure compliance with regulatory requirements and industry standards (e.g., ISO 27001, NIST CsF) related to information security.

Security Awareness and Training : Establish a world class enterprise cyber security awareness and training program. Develop relevant metrics to measure the efficiency and effectiveness of the security awareness and training program, facilitate appropriate resource allocation, and increase the maturity of the program.

Cross-Functional Collaboration : Collaborate with internal stakeholders including IT, law, compliance, privacy procurement, and senior leadership to integrate third-party risk management and information security into business processes.

Communicate security risks and recommendations to senior management, advocating for necessary investments and resources.

Required Skills and Qualifications : Bachelor’s degree in computer science, Information Technology, Business Administration, or related field;

advanced degree preferred. Proven experience (8+ years) in third-party risk management, information security, or related cybersecurity roles, with at least 5 years in a leadership capacity.

Deep understanding of third-party risk management frameworks (e.g., NIST SP 800-161, ISO 27001), regulatory requirements, and industry standards.

Strong knowledge of information security principles, practices, and technologies, including data protection, encryption, access control, and identity management.

Excellent leadership and people management skills, with the ability to lead and mentor a diverse team of professionals. Experience working with business process reengineering and IT solutioning;

experience working on project teams bringing together both business & technology. Capable of explaining technical concepts to a non-technical audience.

Effective communication skills, with the ability to articulate complex security concepts to non-technical stakeholders and influence decision-making at all levels.

Preferred Qualifications : Industry certifications such as CISSP, CISM, CRISC, or related certifications in risk management and cybersecurity.

Experience in financial services, healthcare, or other regulated industries with stringent security and privacy requirements.

Familiarity with emerging technologies and trends in cybersecurity, such as cloud security, IoT security, and DevSecOps practices.

LI-MC1 MassMutual is an Equal Employment Opportunity employer Minority / Female / Sexual Orientation / Gender Identity / Individual with Disability / Protected Veteran.

We welcome all persons to apply. Note : Veterans are welcome to apply, regardless of their discharge status.If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.

14 hours ago
Related jobs
Promoted
MassMutual
Elizabeth, New Jersey

Third-Party Risk Management: Lead the assessment and ongoing monitoring of third-party vendors and partners to identify potential risks and vulnerabilities. Overview: We are seeking an experienced and strategic leader to join our organization as the Head of Cyber Third Party and Risk Management. In ...

Promoted
JPMorgan Chase & Co.
Jersey City, New Jersey

As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. As a Compliance, Conduct and Operational Risk (CCOR) Associate within the global/regional Compliance teams, you will establish effective partnerships with Line of Business (LOB) and other...

Promoted
MassMutual
Fort Lee, New Jersey

Team Management:Lead and mentor a team of vulnerability management and application security professionals, fostering a culture of excellence, innovation, and collaboration. BISO and Enterprise Advisory Services:Working closely with business leaders, technology leaders, and privacy professionals to a...

Promoted
Oakleaf Partnership
Jersey City, New Jersey

The role will require the ability to provide strategic insights and thought leadership across a wide array of compensation and benefit topics, oversee a series of consultants and vendors, partner with human resources, finance, technology, legal and risk professionals as well as be at the forefront o...

Promoted
MassMutual
Kearny, New Jersey

Third-Party Risk Management: Lead the assessment and ongoing monitoring of third-party vendors and partners to identify potential risks and vulnerabilities. Overview: We are seeking an experienced and strategic leader to join our organization as the Head of Cyber Third Party and Risk Management. In ...

Royal Bank of Canada>
Jersey City, New Jersey

The Internal Audit Senior Manager - Risk Management will provide independent, objective assurance over the design and execution of the Bank’s risk management practices established through Enterprise and Operational Risk’s internal infrastructure, frameworks, policies, management reporting, and board...

Bank of America
Jersey City, New Jersey

Engages in activities to provide independent compliance and operational risk oversight of Front Line Unit or Control Function (FLU/CF) performance and any related third party/vendor relationships in alignment with the Global Compliance - Enterprise Policy, the Operational Risk Management - Enterpris...

SAMSUNG
Ridgefield Park, New Jersey

This role will lead our efforts to identify and mitigate Risks to Samsung’s eCommerce Sales and operations through risk identification, performance monitoring, analysis, and process improvement. Manage risk analyst(s) across locations and set long-term strategy and vision for the Risk management org...

Royal Bank of Canada>
Jersey City, New Jersey

The US IT Risk team is responsible for providing a comprehensive view of IT Risk across Royal Bank of Canada’s US business units - Capital Markets, Wealth Management, Global Asset Management, City National Bank and RBC Bank. Work with Business Unit Risk Leads to understand the risks within each busi...

Bank of America
Newark, New Jersey

Engages in activities to provide independent compliance and operational risk oversight of Global Markets Risk and Financial Risk performance and any related third party/vendor relationships in alignment with the Global Compliance - Enterprise Policy, the Operational Risk Management - Enterprise Poli...