Search jobs > Miami, FL > Permanent > Third party risk manager

Third Party Security Risk Management Manager

Apex Systems
Miami, Florida, US
$120K-$140K a year
Permanent

Third Party Security Risk Management Manager

Apex Systems, a World-Class Technology Solutions Provider, is seeking applicants for the below position on behalf of our client.

Please apply if interested and qualified. Please note that only qualified candidates will be contacted.

Apply below after reading through all the details and supporting information regarding this job opportunity.

Position : Third Party Risk Management Manager

Location : Miami, FL - hybrid 3x a week

Duration : Permanent / Direct-Hire

Rate Range : $120k-$140k

Must Haves :

GRC Tool experience; Onetrust is what we are using but it is not required

Management experience

Experience in Third Party Risk or risk space

Position Overview :

The Third-Party Security Risk Manager is responsible for the management, development, and oversight of the Third Party Security Risk Management (TPSRM) program.

The goal of this role is to effectively identify, evaluate, monitor, and manage information security risks associated with third party business partners that do work for, or have access to the clients data.

Primary activities include assessing third-party security risks, facilitation of the due diligence assessment process, and ensuring contractual requirements are implemented into legal agreements.

Additional responsibilities include managing service level agreements for assessment reviews, working with our resident engineer for troubleshooting and enhancing functionality within the assessment tool (OneTrust), and acting as the primary escalation liaison between the TRPM team and the business owners of third-party relationships.

Strong process management and communication skills are required for this role. A sound knowledge of the industry and TPRM experience will be applied to assist leadership with ongoing strategic efforts, such as integration with surrounding global functions and systems, global program facilitation and reporting capabilities, management of professional services and associated KPIs, and implementation of additional program automation and identified development opportunities.

Essential Functions :

  • Serve as the GCS TPSRM subject-matter-expert to identify, evaluate, and manage risks associated to third parties processing or accessing personal and / or confidential data on the clients behalf.
  • Facilitate TPSRM due-diligence processes across business units; drive appropriate stakeholder participation in the assessment, evaluation, and acceptance of risk.
  • Manage vendor relationships, field inquiries, and oversee / assist in the vendor assessment process utilizing the RiskRecon platform.
  • Assess procedures and controls to ensure compliance with applicable company and industry standards.
  • Development of dashboard and reporting capabilities for the TPRM program; provide leadership and conduct training as required throughout company business units to enhance TPRM awareness and compliance reporting as required (weekly).
  • Support program lead with all additional ongoing strategic projects in place to enhance program maturity.

Qualifications :

  • Education : Bachelor’s degree
  • Major / Discipline : Cybersecurity related
  • Required Certifications : Nice to have : CTPRP, CISSP, CISM, CRISC
  • Required Years and Area of Professional Experience : 5
  • Critical Professional Related Technical / Computer Skills : Excellent oral and written communication, presentation, and collaboration skills.

Strong organization skills with the ability to deal with multiple tasks and projects simultaneously. Experience working with legal to conduct contract language reviews.

Experience with GRC tools used to conduct TPRM due diligence assessments, preferably OneTrust.

  • Other Requirements : Experience with the Microsoft Professional Office Suite, including Teams, SharePoint, and Office.
  • Preferred Education : Master’s in Cybersecurity.
  • Preferred Experience and Type : Possess strong organization and communication skills and can communicate security processes and associated risks to non-technical business stakeholders.

Has a solid understanding of key security frameworks, including NIST CSF, PCI-DSS, SOX, ISO, etc. Candidate will need to develop a deep understanding of the company structure, key stakeholders, products, and policies / standards to facilitate resolution amongst groups with conflicting priorities.

Excellent leadership, project management, and presentation skills. Must be able to work independently and efficiently in a remote working environment.

Knowledge, Skills & Abilities :

Third Party Risk Management, Presentation, Risk Management

Decision Making :

Tactical : Decisions focus on intermediate-term issues. The purpose of decisions made at this level are to help move the client closer to reaching strategic goals.

Outcomes are predictable.

  • Operational : Decisions focus on day-to-day activities within the company. Decisions made at this level help to ensure that daily activities proceed smoothly and therefore help to move the company toward reaching a strategic goal.
  • Standard : These decisions are those that are repetitive decisions on a recurring basis and are commonly related to daily activities.

EEO Employer

Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law.

Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning.

We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package.

Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

J-18808-Ljbffr

17 days ago
Related jobs
Promoted
INSPYR Solutions
Miami, Florida

Title: Third-Party Security Risk Manager. The Third-Party Security Risk Manager is responsible for the. ...

Promoted
Beacon Hill
FL, United States

We are seeking a person with at least 5 years of experience as a Third-Party Security Risk Manager. This person will be responsible for the management, development, and oversight of the Third-Party Security Risk Program. At least 5 years of experience as a Third Party Risk Manager. Can communicate s...

Promoted
BankUnited
Miami, Florida

The Third-Party Risk Manager will be responsible for overseeing and managing BankUnited's Third-Party Risk Management framework. The Manager will work closely with various departments and business lines to ensure that Third-Party Risk Management practices are integrated into all third-party relation...

Vitaver
Miami, Florida

Third Party Risk Management, Presentation, Risk Management experience (5+ years);. Experience communicating security processes and associated risks to non-technical business stakeholders;. Serve as the GCS TPSRM subject-matter-expert to identify, evaluate, and manage risks associated to third partie...

Promoted
VirtualVocations
Olympia Heights, Florida

A company is looking for an Operations Supervisor, Third Party Risk. ...

Promoted
Canonical - Jobs
Miami, Florida

In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and r...

Promoted
Royal Caribbean Group
Miami, Florida

Lead the development of a risk management framework that outlines how risks will be identified, managed and mitigated across Newbuild projects and programs. This may involve creating contingency plans, implementing risk transfer mechanisms, or establishing risk avoidance measures to minimize the imp...

Deloitte
Miami, Florida

As a Senior Consultant in our Cyber Application Security team, you will be responsible for delivering Oracle Cloud Applications Security & Controls implementations and Risk Management Cloud (RMC) modules. If you’re seeking a career implementing, architecting, and—in select cases—handling next genera...

N. Harris Computer Corporation - USA
Florida,Remote
Remote

As the Information Security Risk Management Specialist, you will utilize your wide area of expertise in risk management, security frameworks, regulatory compliance, cybersecurity, vulnerability management, disaster recovery and business continuity planning, incident management, and other areas to pr...

MasTec Inc
Coral Gables, Florida

This position will directly report to the Director of Risk Management and will lead and be accountable for the overall corporate risk accounting functions including but not limited to month and quarter end processes, external audit preparations, and collaborate with Corporate Accounting. Identify op...