Third-Party Security Manager

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $94.9k - $136.1k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Guild Mortgage

Guild Mortgage

1001 - 5000 employees

Founded 1960

🏗️ Construction

💸 Finance

🏠 Real Estate

Construction • Finance • Real Estate

Guild Mortgage is a U. S. -based mortgage lender and loan servicer that provides a wide range of home financing products and services to consumers and business partners. The company offers purchase and refinance mortgages, including conventional, FHA, VA, USDA, jumbo, renovation, construction, reverse mortgages, HELOCs, and specialty programs and down-payment assistance. Guild Mortgage operates nationwide through local branches and loan officers, supports borrowers with servicing and online account management, and partners with builders, real estate agents, title agents, and correspondents.

📋 Description

• Lead and mature the organization's Third-Party Risk Management (TPRM) program • Develop, maintain, and continuously improve TPRM frameworks, policies, standards, and procedures • Establish risk-based processes for onboarding, reviewing, monitoring, and offboarding third parties • Define vendor risk assessment methodologies and risk scoring criteria • Align third-party risk practices with NIST, SOC 2, ISO 27001, FFIEC, GLBA, PCI-DSS, and applicable privacy regulations • Conduct security, privacy, operational, compliance, and business continuity risk assessments for vendors • Review vendor security documentation, including SOC reports, ISO certifications, penetration test reports, vulnerability management reports, security questionnaires, and continuity plans • Identify control gaps and coordinate remediation plans with vendors and stakeholders • Evaluate fourth-party dependencies and concentration risks • Maintain third-party relationship inventories and risk ratings • Develop continuous monitoring processes for critical and high-risk vendors • Monitor vendor security ratings, threat intelligence, breach activity, financial condition, and compliance status • Track remediation activities and facilitate periodic vendor reviews and reassessments • Partner with Procurement, Legal, Privacy, Compliance, business owners, and Information Security during vendor selection and contract negotiations • Provide vendor risk guidance to business leaders • Present vendor risk findings and recommendations to leadership, risk committees, and executive management • Support internal and external audits of vendor management controls • Establish security and privacy contractual requirements with Legal and Procurement • Review and recommend contract language covering security controls, data protection, breach notification, audit rights, business continuity, and regulatory compliance • Ensure vendor agreements include appropriate security, privacy, and reporting requirements • Develop and maintain TPRM dashboards, KPIs, and executive reporting • Track assessment volumes, remediation status, risk trends, and program maturity metrics • Report regularly to Information Security leadership, Enterprise Risk Management, and audit committees • Support risk quantification and business impact analysis efforts • Mentor and guide less experienced professional contributors

🎯 Requirements

• Bachelor's Degree directly related to the position or equivalent, preferred • Minimum five years' experience • Minimum three years supervisory or leadership experience • Excellent verbal and written communication skills required • Highly organized and detail-oriented • Ability to work in a fast-paced, metrics-driven environment • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications • Commitment to company values • Ability to work Monday–Friday during the business week • Travel of 5% or less • Work is primarily sedentary with frequent use of a computer keyboard and mouse • Ability to learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions • Ability to adhere to and apply established process protocols in a timely manner

🏖️ Benefits

• Medical insurance • Dental insurance • Vision insurance • Life insurance • AD&D insurance • LTD insurance • 401(k) with employer match • Competitive compensation • Pleasant work environment

Apply Now

Similar Jobs

🔥 3 hours ago

Icmarc

-

💼 Consulting

🏥 Healthcare

🛡️ Insurance

Application and AI security engineer securing MissionSquare’s retirement-services software and AI applications. Automating testing, threat modeling, and secure development across multidisciplinary teams.

🔥 3 hours ago

New Charter Technologies

501 - 1000

💼 Consulting

📦 Logistics

📣 Marketing

Security Success Analyst coordinating cybersecurity, compliance, vulnerability management, and incident response. Supporting New Charter’s small-to-medium business clients across the US.

🔥 3 hours ago

Baylor Genetics

501 - 1000

🏥 Healthcare

💼 Consulting

🍽️ Food & Beverage

Senior Information Security Engineer protecting Baylor Genetics’ clinical genomic and health data. Leading SIEM, vulnerability management, identity security, Zero Trust, and incident response.

🔥 3 hours ago

Cornerstone Capital Bank

51 - 200

🏦 Banking

💸 Finance

Senior Security Engineer strengthening Cornerstone Capital Bancorp’s regulated banking cybersecurity program. Leading IAM governance, architecture reviews, vulnerability management, AI security, and third-party risk activities.

🔥 4 hours ago

VIP (Vermont Information Processing)

501 - 1000

🍽️ Food & Beverage

📦 Logistics

☁️ SaaS

Senior Security Engineer hardening beverage-industry technology platforms across VIP’s U.S. operations. Leading segmentation, detection, vulnerability, identity, and incident-response engineering.