J

Service Manager - Supplier Security Due Diligence & Monitoring

Jobgether • United State
Remote
Apply
AI Summary

Lead enterprise supplier cybersecurity risk management and contractual security decisions. Oversee daily operations, team leadership, and cross-functional stakeholder collaboration. Requires 7+ years of cybersecurity risk experience and 3+ years of operational leadership.

Key Highlights
Lead supplier security due diligence and monitoring service
Translate cybersecurity risks into contractual security decisions
Manage cross-functional teams across Legal, Procurement, Cybersecurity, and Risk Management
Key Responsibilities
Lead the daily operations and strategic direction of the supplier security due diligence and monitoring service
Manage and develop a team responsible for supplier security contracting support and risk-based decision-making
Review supplier security assessments and monitoring outcomes to guide contractual negotiations and risk decisions
Translate cybersecurity requirements into practical contractual positions, fallback language, and appropriate risk mitigation strategies
Ensure consistent application of enterprise security standards across supplier agreements and business engagements
Oversee documentation, tracking, and governance of contractual exceptions, security deviations, and risk accommodations
Escalate supplier security positions that exceed established risk tolerances through appropriate governance and approval processes
Partner with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier challenges
Establish service-level objectives, operational metrics, reporting frameworks, and quality management practices
Drive continuous improvement initiatives to increase scalability, consistency, and stakeholder satisfaction
Maintain strong audit trails and governance documentation to support transparent and defensible risk decisions
Promote a service-oriented culture focused on responsiveness, collaboration, and operational excellence
Technical Skills Required
Cybersecurity risk management Supplier risk management Contract negotiation Risk-based decision making
Benefits & Perks
Competitive annual compensation range of $120,000 - $193,725
Fully remote work opportunity within the United States
Monthly connectivity reimbursement
Nice to Have
Experience supporting supplier contract negotiations involving cybersecurity and privacy requirements
Knowledge of third-party risk management programs and supplier security assessment methodologies
Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, NIST 800-53, ISO 27001, CIS Controls, and SOC reporting
Experience with enterprise risk management, governance processes, and risk acceptance workflows
Professional certifications such as CISSP, CISM, CRISC, ITIL, PMP, or similar credentials

Job Description


This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Service Manager - Supplier Security Due Diligence & Monitoring Service based in United States.

The Service Manager - Supplier Security Due Diligence & Monitoring Service will lead a critical enterprise function focused on managing supplier cybersecurity risks and strengthening security governance.

This role operates at the intersection of cybersecurity, legal, procurement, supplier management, and enterprise risk teams.

The successful candidate will oversee a specialized service that translates supplier risk assessments into practical contractual security decisions.

They will help organizations balance business agility with strong information security requirements by guiding negotiations, managing exceptions, and improving governance practices.

This position offers the opportunity to shape a growing security service, influence enterprise risk strategies, and drive operational excellence.

The ideal candidate is a strategic risk leader with strong stakeholder management skills and a passion for building scalable security programs.

Accountabilities

The Service Manager will lead the Supplier Security Due Diligence & Monitoring Service, ensuring consistent, risk-based approaches to supplier security requirements and contractual decisions. This role will manage service delivery, develop operational processes, and partner with cross-functional teams to strengthen supplier risk management practices.

  • Lead the daily operations and strategic direction of the supplier security due diligence and monitoring service.
  • Manage and develop a team responsible for supplier security contracting support and risk-based decision-making.
  • Review supplier security assessments and monitoring outcomes to guide contractual negotiations and risk decisions.
  • Translate cybersecurity requirements into practical contractual positions, fallback language, and appropriate risk mitigation strategies.
  • Ensure consistent application of enterprise security standards across supplier agreements and business engagements.
  • Oversee documentation, tracking, and governance of contractual exceptions, security deviations, and risk accommodations.
  • Escalate supplier security positions that exceed established risk tolerances through appropriate governance and approval processes.
  • Partner with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier challenges.
  • Establish service-level objectives, operational metrics, reporting frameworks, and quality management practices.
  • Drive continuous improvement initiatives to increase scalability, consistency, and stakeholder satisfaction.
  • Maintain strong audit trails and governance documentation to support transparent and defensible risk decisions.
  • Promote a service-oriented culture focused on responsiveness, collaboration, and operational excellence.

Requirements

The ideal candidate brings strong experience in cybersecurity risk management, supplier governance, and operational leadership, with the ability to influence stakeholders across multiple business functions.

  • 7+ years of experience in information security, technology risk, third-party risk management, supplier risk management, governance, contracting, procurement, or related fields.
  • 3+ years of leadership experience managing teams, services, programs, or operational functions.
  • Demonstrated ability to evaluate cybersecurity and technology risks using sound risk-based decision-making principles.
  • Strong understanding of supplier risk management practices, security controls, governance frameworks, and risk mitigation strategies.
  • Experience collaborating across Legal, Procurement, Business, Security, and Risk Management functions.
  • Proven ability to interpret cybersecurity requirements and apply them within contractual and business contexts.
  • Strong written, verbal communication, stakeholder management, and executive presentation skills.
  • Experience supporting supplier contract negotiations involving cybersecurity and privacy requirements preferred.
  • Knowledge of third-party risk management programs and supplier security assessment methodologies preferred.
  • Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, NIST 800-53, ISO 27001, CIS Controls, and SOC reporting preferred.
  • Experience with enterprise risk management, governance processes, and risk acceptance workflows preferred.
  • Professional certifications such as CISSP, CISM, CRISC, ITIL, PMP, or similar credentials are a plus.
  • Ability to build, scale, or transform operational services and governance functions in complex environments.

Benefits

  • Competitive annual compensation range of $120,000 - $193,725, based on experience and qualifications.
  • Fully remote work opportunity within the United States.
  • Comprehensive technology setup including laptop, monitors, headset, keyboard, and mouse.
  • Monthly connectivity reimbursement for eligible remote employees.
  • Health, wellness, and employee support programs.
  • Opportunities to work on high-impact cybersecurity initiatives with enterprise visibility.
  • Career growth opportunities through challenging projects, learning, and professional development.
  • Collaborative culture focused on innovation, teamwork, and meaningful impact.
  • Opportunity to contribute to stronger security practices protecting customers and communities.

How Jobgether Works

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.


Similar Jobs

Explore other opportunities that match your interests

Information Security Architect

Cyber Security
•
1h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Jobgether

United State

Manager of IT Security

Cyber Security
•
2h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

lakeshore learning materials

United State

Identity and Security Operations Engineer

Cyber Security
•
3h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

TEKsystems

United State

Subscribe our newsletter

New Things Will Always Update Regularly