Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Third Party Cyber Risk Program Manager image - Rise Careers
Job details

Third Party Cyber Risk Program Manager

We are looking for a highly skilled and dynamic professional to join our team as a Third Party Cyber RIs Assessor & program manager for Third-Party cyber risk assessment responsible for leading and conducting third-party cyber risk assessments for a global client portfolio.

In this position, you will be responsible for leading comprehensive cybersecurity risk assessments for third-party vendors, suppliers, and partners, while simultaneously managing the overall third-party risk assessment program. The ideal candidate will have both technical expertise in cyber risk management, strong program management as well as audit skills to oversee the successful execution of third-party assessments at scale.

While this position is remote, it will have a preference towards people in the Dallas area to be closer to the client stakeholder.

  • Lead and conduct detailed cybersecurity risk assessments (audits) for third-party vendors, including reviewing their information security practices, policies, and controls.
  • Assess third-party vendor security risks across multiple domains, including data protection, network security, identity & access management, and incident response.
  • Identify, evaluate gaps and/or deficiencies in cybersecurity technical and/or policy/procedure controls.
  • Perform thorough due diligence on third-party suppliers and partners, identifying potential vulnerabilities and risks that could impact the organization.
  • Recommend solutions and alternatives to remediate gaps and/or deficiencies in cybersecurity technical and/or policy/procedure controls.
  • Independently lead assessment meetings with clients and third parties to evaluate the implementation of cyber controls.
  • Collaborate closely with global line management and regional colleagues on delivery, client management and internal and client communications.
  • Master client’s proprietary security and contractual standards.
  • Apply recognized cybersecurity frameworks and standards (e.g., NIST, ISO 27001, CIS Controls) in risk assessments and audits.
  • Document findings, assessment processes, and recommended actions in a clear, concise, and actionable manner.
  • Stay up-to-date with the latest trends, threats, and regulatory changes in cybersecurity and risk management

Program Management of Third-Party Cyber Risk Assessments:

  • Execute the third-party risk assessment program to ensure comprehensive coverage across the global client portfolio.
  • Evolve existing processes and methodologies for third-party assessments, ensuring consistency, quality, and efficiency.
  • Oversee the day-to-day execution of the third-party risk assessment program, coordinating across global teams and managing timelines, resources, and priorities.
  • Track progress, assess risks to program timelines, and ensure alignment with organizational goals and business objectives.
  • Regularly report on program status, risk assessments, and findings to senior leadership and other stakeholders.
  • Provide expert insights on the impact of third-party risks to the broader organization and guide executive decision-making.
  • Continuously evaluate and refine third-party risk assessment processes, looking for opportunities to improve efficiency, scalability, and integration with other risk management functions.
  • Lead initiatives to incorporate automation, tools, and platforms that streamline the assessment process and enhance data-driven decision-making.
  • Manage a small global team of assessors or support staff, providing leadership, mentoring, and ensuring successful completion of assessments and program deliverables.
  • Support hiring, training, and development of team members to build a high-performing program management team.
  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field (or equivalent experience).
  • 8+ years of experience in cybersecurity, risk management, or IT auditing, with at least 3 years focused on third-party risk assessments and program management.
  • Proven experience in both hands-on cyber risk assessment and program management in a global environment.
  • Experience working in the Healthcare industry is required.
  • Demonstrable expertise leading the delivery of assessments based on cybersecurity standards and frameworks such as NIST CSF 2.0, IS27001 and 27002, SOC2, Center for Internet Security (CIS) best practices, PCI-DSS, CSA Cloud Controls Matrix, GDPR, HIPAA, HITRUST, etc.
  • Hands-on experience with tools and platforms used for third-party risk assessments, vulnerability scanning, and audit processes
  • Strong understanding of information security domains such as access control, encryption, vulnerability management, network security, and incident response.
  • Evidence of supporting clients overcome cybersecurity challenges in a broad array of sectors which may include, but is not limited to: Technology, Financial Services, and Retail.
  • A deep understanding of governance, standards, and compliance as they pertain to cyber security. 
  • Ability to analyze complex security data and translate findings into industry specific recommendations.
  • Strong communication skills with the ability to effectively present risk findings and recommendations to senior leadership and non-technical stakeholders.

Preferred Qualifications

  • Certifications: CISSP, CISM, CRISC, CISA, SCP, CCNP, ISO 27001 Lead Auditor  or other relevant security or risk management certifications.
  • Experience working in a global organization and understanding of the challenges involved in managing risks across multiple jurisdictions.
  • Experience managing global programs and understanding of the complexities associated with vendor relationships in diverse geographical regions.
  • Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.
  • We operate a discretionary bonus scheme that incentivizes, and rewards individuals based on company and individual performance.
  • Control Risks supports hybrid working arrangements, wherever possible, that emphasize the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working.

Control Risks is committed to a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age or veteran status. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.

Control Risks participates in the E-Verify program to confirm employment authorization of all newly hired employees. The E-Verify process is completed during new hire onboarding and completion of the Form I-9, Employment Eligibility Verification, at the start of employment. E-Verify is not used as a tool to pre-screen candidates. For more information on E-Verify, please visit www.uscis.gov.

Control Risks Glassdoor Company Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Control Risks DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Control Risks
Control Risks CEO photo
Nick Allan
Approve of CEO

Average salary estimate

$115000 / YEARLY (est.)
min
max
$100000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Third Party Cyber Risk Program Manager, Control Risks

At Control Risks, we are searching for a talented Third Party Cyber Risk Program Manager to spearhead our third-party cyber risk assessment initiatives. In this unique role, you’ll lead comprehensive cybersecurity risk assessments across a global portfolio of clients, interacting with various vendors, suppliers, and partners to ensure they meet our stringent security standards. You’ll dive deep into their information security practices, identifying risks and recommending concrete solutions to improve their cybersecurity policies and controls. This is more than just a hands-on assessment role; you’ll manage our overall third-party risk assessment program, collaborating with diverse teams and utilizing your experience in cybersecurity, risk management, and program management. Ideally, you’ll bring at least eight years of experience to the table, including a minimum of three years focused on third-party risk assessments, preferably in the Healthcare industry. You’ll attend meetings with clients, communicating your findings clearly and succinctly while continuously evolving our assessment processes. By staying updated on the latest trends in cybersecurity, you’ll help position Control Risks as a leader in advancing third-party cyber risk management. In this remote role, we appreciate candidates who are preferably based in the Dallas area, allowing for closer interactions with client stakeholders. If you’re ready to take your cybersecurity career to the next level and lead innovative risk management efforts, we’d love to chat with you!

Frequently Asked Questions (FAQs) for Third Party Cyber Risk Program Manager Role at Control Risks
What are the main responsibilities of a Third Party Cyber Risk Program Manager at Control Risks?

As a Third Party Cyber Risk Program Manager at Control Risks, you will lead and conduct detailed cybersecurity risk assessments for third-party vendors, assess their security risks across various domains, and manage the overall third-party risk assessment program. You'll collaborate with clients and internal teams, ensuring your findings are clear and actionable. Additionally, you'll oversee program execution, report on status and findings to senior leadership, and mentor a global team of assessors.

Join Rise to see the full answer
What qualifications are required for the Third Party Cyber Risk Program Manager position at Control Risks?

To be considered for the Third Party Cyber Risk Program Manager role at Control Risks, candidates should have a Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related areas. A minimum of 8 years in cybersecurity, risk management, or IT auditing is required, with at least 3 years dedicated to third-party risk assessments. Experience in the Healthcare industry and familiarity with frameworks like NIST, ISO, and SOC2 is highly preferred.

Join Rise to see the full answer
What experience is considered beneficial for the Third Party Cyber Risk Program Manager role at Control Risks?

For the Third Party Cyber Risk Program Manager position at Control Risks, beneficial experience includes hands-on management of cyber risk assessments in a global context, with an emphasis on compliance and governance in cybersecurity. Familiarity with the complexities of vendor relationships across different geographical regions will also enhance your fit for this role. Relevant certifications like CISSP, CISM, or CISA are considered advantageous.

Join Rise to see the full answer
How does Control Risks support the Third Party Cyber Risk Program Manager in their role?

Control Risks offers a supportive environment for its Third Party Cyber Risk Program Managers through a collaborative culture and by providing access to resources needed for success. The role includes mentorship, formal training opportunities, and a flexible work arrangement that promotes both remote and in-person engagement, emphasizing collective team efforts to drive results.

Join Rise to see the full answer
What can a candidate expect during the interview process for the Third Party Cyber Risk Program Manager position at Control Risks?

Candidates interviewing for the Third Party Cyber Risk Program Manager role at Control Risks can expect a comprehensive process that encompasses discussions of their past experience, technical capabilities, and scenario-based evaluations. The interviews will assess how well candidates can communicate risk findings and interact with clients, alongside understanding their approach to cybersecurity challenges specific to third-party management.

Join Rise to see the full answer
Common Interview Questions for Third Party Cyber Risk Program Manager
How do you conduct a third-party cybersecurity risk assessment?

When asked how to conduct a third-party cybersecurity risk assessment, you should articulate a structured approach that includes identifying the vendor’s security policies, evaluating cybersecurity controls against standards like NIST or ISO, performing gap analysis, and making actionable recommendations to remediate identified risks.

Join Rise to see the full answer
Can you describe your experience with cybersecurity frameworks relevant to this role?

In answering this question, share specific examples of frameworks you've worked with, such as NIST CSF, ISO 27001, or SOC2. Discuss how you’ve applied these frameworks to assess third-party vendors and how they supported compliance and risk management efforts throughout your career.

Join Rise to see the full answer
What strategies would you use to manage multiple risk assessments across a global portfolio?

To manage multiple risk assessments effectively, discuss stressing the importance of strong project management methodologies, prioritizing assessments based on risk profiles, utilizing automation tools to streamline processes, and maintaining clear communication with all stakeholders.

Join Rise to see the full answer
How do you stay current with emerging cybersecurity threats?

When discussing how you stay current with emerging threats, emphasize your engagement in continuous learning through industry seminars, webinars, cybersecurity news, and active participation in professional networks and organizations that focus on risk management and cybersecurity trends.

Join Rise to see the full answer
What tools have you used for third-party risk assessments?

Mention any specific tools you've used, such as vulnerability scanning software, documentation platforms, or specific risk assessment frameworks. Emphasize your hands-on experience and how these tools have assisted in evaluating vendor security practices effectively.

Join Rise to see the full answer
Describe an instance where you identified a severe risk during an assessment. What actions did you take?

When discussing a past risk identification, provide a concrete example illustrating your analysis process, the magnitude of the risk, and the steps you took to address it. Detail how you communicated findings to stakeholders and the outcome of your recommendations.

Join Rise to see the full answer
How would you evaluate the security posture of a vendor in the healthcare sector?

In answering, focus on understanding HIPAA regulations, data protection measures, incident response protocols, and risk management practices specific to the healthcare industry. Highlight the importance of thorough due diligence and compliance oversight during the assessment.

Join Rise to see the full answer
What steps do you take to ensure compliance with cyber risk management standards?

Discuss your approach to ensuring compliance, including conducting regular assessments, staying abreast of regulatory changes, engaging teams in training sessions, and facilitating robust documentation practices that align with industry standards.

Join Rise to see the full answer
How do you manage team dynamics and ensure successful results?

When discussing team management, focus on fostering open communication, leveraging team members' strengths, setting clear expectations, and providing mentorship to cultivate a collaborative environment that drives success in risk assessments.

Join Rise to see the full answer
How would you handle a situation where a vendor is resistant to implementing your recommendations?

You should approach this question by describing your conflict resolution skills, emphasizing the importance of building relationships, understanding the vendor's concerns, and providing rationale behind your recommendations while maintaining a constructive dialogue.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 5 days ago

We are looking for a passionate Digital Marketing Assistant to join Control Risks and contribute to captivating digital marketing strategies.

Photo of the Rise User
Posted 4 days ago

Join Control Risks as the Director of Digital Risks Cyber Assurance to lead impactful cyber assurance engagements and drive business growth in the UK.

Photo of the Rise User
Posted 11 days ago

Become part of the Wachter family as a Physical Security Estimator, enhancing client proposals with your technical expertise.

Photo of the Rise User
Posted 2 days ago

Join Kimley-Horn as an IT Analyst and be a crucial part of our commitment to exceptional client service and employee development.

Photo of the Rise User
Posted 13 days ago

Civista Bank is looking for a Business Systems Specialist to ensure the efficiency of its Lending Systems while collaborating across multiple departments.

Posted 11 days ago

We are looking for a visionary Chief Technology Officer to drive technological innovation at Remote Recruitment.

IBM - Avature Hybrid US, East Baton Rouge County, LA; Louisiana, Baton Rouge, LA
Posted 13 days ago

Join the IBM Consulting team as an SAP HANA ABAP Senior Developer to help innovative companies enhance their business processes through custom solutions.

Photo of the Rise User
Posted 7 days ago

Looking for a Lead IT Technician to drive advanced IT solutions within a collaborative team at Nestlé, focusing on manufacturing systems and support.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as an Information Security Manager to lead technology audits and enhance compliance within a dynamic team.

A highly skilled AWS Enterprise Solutions Architect is required to design end-to-end solutions within the telecom domain, leveraging a rich technological ecosystem.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Customer-Centric
Fast-Paced
Growth & Learning
Medical Insurance
Dental Insurance
401K Matching
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Flex-Friendly
Photo of the Rise User
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

Experts in risk and opportunity Control Risks is a global specialist risk consultancy that helps to create secure, compliant and resilient organisations. Combining unrivalled expertise, experience and reach with the power of data and technology, ...

180 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!