Head of Cyber Third Party and Risk Management
1 month ago
Overview:
We are seeking an experienced and strategic leader to join our organization as the Head of Cyber Third Party and Risk Management. In this critical role, you will be responsible for overseeing and enhancing our third-party cyber risk management program, governance, security awareness and training, and ensuring the security of our business information assets. You will lead efforts to assess, mitigate, and monitor risks associated with third-party vendors and drive information security risk management across MassMutual’s critical business units / entities.
Key Responsibilities:
- Leadership and Strategy:
- Develop and execute a comprehensive third-party risk management strategy aligned with organizational objectives, regulatory requirements, and industry best practices.
- Define and implement cyber security strategies, policies, and standards to protect company assets and data.
- Third-Party Risk Management:
- Lead the assessment and ongoing monitoring of third-party vendors and partners to identify potential risks and vulnerabilities.
- Establish risk assessment frameworks, methodologies, and scoring models to evaluate the security posture of third parties.
- Vendor Due Diligence and Contract Management:
- Implement robust due diligence processes for assessing the security capabilities of prospective vendors and partners.
- Collaborate with legal and procurement teams to incorporate security requirements into vendor contracts and agreements.
- Risk Mitigation and Remediation:
- Develop and oversee the implementation of risk mitigation strategies and controls to address identified vulnerabilities and risks with third parties.
- Monitor and track remediation efforts to ensure timely resolution of security issues impacting third-party relationships.
- Cyber Security Governance:
- Develop and enforce cyber security policies, standards, and guidelines across the organization.
- Ensure compliance with regulatory requirements and industry standards (e.g., ISO 27001, NIST CsF) related to information security.
- Security Awareness and Training:
- Establish a world class enterprise cyber security awareness and training program.
- Develop relevant metrics to measure the efficiency and effectiveness of the security awareness and training program, facilitate appropriate resource allocation, and increase the maturity of the program.
- Cross-Functional Collaboration:
- Collaborate with internal stakeholders including IT, law, compliance, privacy procurement, and senior leadership to integrate third-party risk management and information security into business processes.
- Communicate security risks and recommendations to senior management, advocating for necessary investments and resources.
Required Skills and Qualifications:
- Bachelor’s degree in computer science, Information Technology, Business Administration, or related field; advanced degree preferred.
- Proven experience (8+ years) in third-party risk management, information security, or related cybersecurity roles, with at least 5 years in a leadership capacity.
- Deep understanding of third-party risk management frameworks (e.g., NIST SP 800-161, ISO 27001), regulatory requirements, and industry standards.
- Strong knowledge of information security principles, practices, and technologies, including data protection, encryption, access control, and identity management.
Excellent leadership and people management skills, with the ability to lead and mentor a diverse team of professionals.
- Experience working with business process reengineering and IT solutioning; experience working on project teams bringing together both business & technology. Capable of explaining technical concepts to a non-technical audience.
- Effective communication skills, with the ability to articulate complex security concepts to non-technical stakeholders and influence decision-making at all levels.
Preferred Qualifications:
- Industry certifications such as CISSP, CISM, CRISC, or related certifications in risk management and cybersecurity.
- Experience in financial services, healthcare, or other regulated industries with stringent security and privacy requirements.
- Familiarity with emerging technologies and trends in cybersecurity, such as cloud security, IoT security, and DevSecOps practices.
#LI-MC1
If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.
-
Third Party Risk
1 month ago
New York, United States TEKsystems Full timeJob DescriptionJob DescriptionTop Skills' Details* Knowledgeable in multiple areas of technology, with hands-on experience and technical expertise across all Information Security domains* Experienced with local, national, and international financial services and privacy regulations, such as GLBA, NYDFS, GDPR, CCPA, etc. and credit card industry...
-
Third Party Risk Specialist
4 weeks ago
New York, New York, United States TEKsystems Full timeJob SummaryWe are seeking a highly skilled Third Party Risk Specialist to join our team at TEKsystems. The successful candidate will be responsible for ensuring that third parties adhere to security requirements and will work closely with various stakeholders to achieve this goal.Key ResponsibilitiesProvide Information Security subject matter expertise to...
-
IT Manager, Third Party Risk Professional
4 days ago
New York, New York, United States Brookfield Properties Full timeJob Title: IT Manager, Third Party Risk ProfessionalAbout the Role:We are seeking an experienced IT Manager, Third Party Risk Professional to join our team at Brookfield Properties. As a key member of our Information Security team, you will play a crucial role in overseeing the operational and strategic aspects of our third-party cyber risk program.Key...
-
Director of Third Party Risk Management
1 month ago
New York, New York, United States Broadgate Full timeJob Title: Director - Third Party Risk ManagementBroadgate is seeking a highly skilled Director to lead our Third Party Risk Management team. As a key member of our organization, you will be responsible for developing and implementing strategies to mitigate risks associated with third-party relationships.Key Responsibilities:Develop a comprehensive strategy...
-
Director - Third Party Risk Management
3 months ago
New York, United States Broadgate Full timeJob ResponsibilitiesStrategy Development:• Develop a comprehensive strategy for continuous monitoring of third and fourthparty relationships.• Define goals, objectives, and key performance indicators (KPIs) to measure the effectiveness of the monitoring program.• Stay abreast of industry trends, regulatory requirements, and emerging threats to...
-
Third Party Risk Management Specialist
1 week ago
New York, New York, United States Amalgamated Bank of NY Full timeJob SummaryThe Third Party Risk Management Analyst plays a crucial role in the development and execution of the Bank's Enterprise Third Party Risk Management Program. This program aims to measure, monitor, assess, and report on the control of third-party vendor risk throughout the enterprise.The ideal candidate will have a strong understanding of finance,...
-
Third Party Risk Management Specialist
1 month ago
New York, New York, United States Amalgamated Bank of NY Full timeJob SummaryWe are seeking a highly skilled Third Party Risk Management Analyst to join our team at Amalgamated Bank of NY. The successful candidate will be responsible for supporting the development and execution of our Enterprise Third Party Risk Management Program.Key ResponsibilitiesCollaborate with business stakeholders to ensure compliance with...
-
Third-Party Risk Management Lead
1 month ago
New York, New York, United States Federal Reserve System Full timeJob Title: Third-Party Risk Management, 4th Party Program LeadAt the Federal Reserve System, we are seeking a highly skilled Third-Party Risk Management, 4th Party Program Lead to join our team. As a key member of our Risk Management department, you will be responsible for developing, implementing, and administering the Third-Party Risk Management 4th Party...
-
Third-Party Risk Management Lead
2 weeks ago
New York, New York, United States Federal Reserve System Full timeJob Title: Third-Party Risk Management, 4th Party Program LeadAt the Federal Reserve System, we are seeking a highly skilled Third-Party Risk Management, 4th Party Program Lead to join our team. As a key member of our Risk Management department, you will be responsible for developing, implementing, and administering the Third-Party Risk Management 4th Party...
-
Third Party Risk Specialist
1 week ago
New York, New York, United States TEKsystems Full timeJob SummaryTEKsystems is seeking a highly skilled Third Party Risk Specialist to join our team. As a key member of our Information Security team, you will be responsible for ensuring the security and compliance of third-party vendors and suppliers.Key Responsibilities:Provide Information Security subject matter expertise to internal stakeholders for the...
-
Third-Party Vendor Risk Management Specialist
4 weeks ago
New York, New York, United States IntelliPro Group Inc. Full timeJob DescriptionIntelliPro Group Inc. is seeking a highly skilled Third-Party Vendor Risk Management Specialist to join our team. As a key member of our risk management team, you will be responsible for overseeing the Financial Services Third-Party Vendor Risk Management program.The ideal candidate will have prior experience independently managing Third-Party...
-
AVP Third Party Risk
3 months ago
New York, United States Broadgate Full timeWhat You’ll Do • Support the Maturity of the Third-Party Risk Management Program by providing recommendations and helping to provide strategy deliverables. • Be open to change and provide leadership by leading TPRM staff across the enterprise to welcome/accept change. • Provide periodic reports to management and stakeholders. • Manage vendor...
-
AVP Third Party Risk Management Specialist
1 month ago
New York, New York, United States Broadgate Full timeJob SummaryWe are seeking a highly skilled AVP Third Party Risk Management professional to join our team at Broadgate. As a key member of our Third Party Risk Management team, you will play a critical role in supporting the maturity of our Third Party Risk Management Program.Key ResponsibilitiesSupport the development and implementation of the Third Party...
-
New York, New York, United States IntelliPro Group Inc. Full timeJob DescriptionIntelliPro Group Inc. is seeking a highly skilled Third-Party Vendor Risk Management Specialist to join our team. As a key member of our risk management team, you will be responsible for overseeing the Financial Services Third-Party Vendor Risk Management program.The ideal candidate will have prior experience independently managing Third-Party...
-
New York, New York, United States Brandon Consulting Associates, Inc. Full timeJob DescriptionBrandon Consulting Associates, Inc. is seeking a highly skilled Third Party Vendor Risk Management Specialist to join our team. The ideal candidate will have a strong background in risk management and be able to oversee the company's third-party vendor risk management program. The Specialist will be responsible for identifying, assessing, and...
-
Third Party Risk Measurement Program Manager
4 days ago
New York, New York, United States Tik Tok Full timeJob Summary TikTok is seeking a highly motivated and experienced Privacy Program Manager to lead our Third Party Risk Measurement program. As a key member of our Privacy and Data Protection Office, you will be responsible for identifying, managing, and mitigating risks associated with Bytedance's third parties. Responsibilities • Support the program to...
-
Third Party Risk Measurement Program Manager
5 days ago
New York, New York, United States Tik Tok Full timeAt TikTok, we're committed to creating an inclusive environment where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe, and so does our workplace.We're passionate about inspiring creativity and bringing joy to our users. To achieve this goal, we're dedicated to celebrating our...
-
New York, New York, United States Tik Tok Full timeAbout the RoleWe are seeking a highly motivated and experienced Privacy Program Manager to join our team in Third Party Risk Measurement. As a key member of our Privacy and Data Protection Office, you will be responsible for leading, supervising, and empowering all TikTok's privacy work in an accountable and industry-leading way.Key ResponsibilitiesSupport...
-
New York, New York, United States Tik Tok Full timeJob Title: Privacy Program Manager, Third Party Risk MeasurementTikTok is a leading destination for short-form mobile video, and we're committed to inspiring creativity and bringing joy to our users. As a Privacy Program Manager, Third Party Risk Measurement, you'll play a critical role in ensuring the privacy and security of our users'...
-
New York, New York, United States Tik Tok Full timeJob SummaryTikTok is seeking a highly skilled Privacy Program Manager to lead our third-party risk management efforts. As a key member of our Privacy and Data Protection Office, you will be responsible for identifying, managing, and mitigating risks associated with Bytedance's third-party vendors.Key Responsibilities Support the development of our...