Head of Third-Party Cybersecurity Risk

3 weeks ago


Minnesota, United States PRI Technology Full time

The Head of Third-Party Cybersecurity Risk is tasked with the strategic formulation and operational implementation of the organization’s third-party cybersecurity risk management initiative. This position guarantees that all external partnerships adhere to regulatory mandates, align with corporate cybersecurity protocols, and fulfill the organization’s risk management criteria. The Director will craft and execute the third-party risk management framework while guiding a team of experts to evaluate, oversee, and mitigate risks linked to vendors, suppliers, and other external entities. Here, you will make a significant impact by:

Program Design and Oversight:

  • Establish and execute a robust third-party cybersecurity risk management program.
  • Create and enforce policies and procedures for evaluating and managing external risks.
  • Continuously enhance the program in response to emerging threats and regulatory changes.

Risk Evaluation and Reduction:

  • Perform comprehensive risk evaluations of third-party vendors, including initial assessments and ongoing surveillance.
  • Identify potential weaknesses and propose mitigation strategies.
  • Collaborate with external partners to address and rectify identified risks.

Vendor Engagement:

  • Foster and sustain strong relationships with key external vendors and partners.
  • Ensure that vendor contracts incorporate appropriate cybersecurity stipulations and standards.
  • Work alongside legal and procurement teams to negotiate cybersecurity clauses in agreements.

Incident Response:

  • Assist in the response to cybersecurity incidents involving external vendors.

Reporting and Stakeholder Communication:

  • Provide regular updates to senior leadership on the status of the third-party cybersecurity risk management initiative.
  • Prepare and deliver reports on third-party risk evaluations and mitigation actions.
  • Effectively communicate with internal teams and external vendors regarding cybersecurity risk expectations and requirements.

Compliance with Regulations:

  • Ensure that the third-party cybersecurity risk management initiative complies with relevant regulations and industry standards (e.g., GDPR, CCPA, NIST, ISO).
  • Stay informed on regulatory updates and modify the program as necessary.

Your Qualifications and Skills:

  • Bachelor's degree or higher (completed and verified prior to start) from an accredited institution.
  • A decade of experience in Cybersecurity within a private, public, governmental, or military context.
  • Five years of management and/or supervisory experience.
  • CISSP certification.

Additional qualifications that could enhance your success in this role include:

  • Master's degree in computer engineering, computer systems, or information technology from an accredited institution.
  • 8-10 years of experience in cybersecurity/risk management, with at least 5 years in a leadership role focused on third-party risk management.
  • Strong understanding of cybersecurity frameworks and standards (e.g., NIST, ISO 27001, CIS).
  • Additional certifications such as SANS, ISACA (CGEIT, CISA, CISM, CRISC), and other technology certifications.
  • Exceptional communication, negotiation, and relationship-building abilities.
  • Capability to collaborate effectively with internal teams and external vendors.


  • Minnesota, United States PRI Technology Full time

    The Director of Third-Party Cyber Risk Management at PRI Technology plays a pivotal role in shaping and executing the organization's strategy for managing cyber risks associated with external partners. This position is essential in ensuring that all vendor relationships adhere to regulatory mandates, align with corporate cybersecurity policies, and fulfill...


  • Minnesota, United States PRI Technology Full time

    The Director of Third-Party Cyber Risk Management plays a pivotal role in shaping and executing the organization's strategy for managing cyber risks associated with external partners. This position is crucial for ensuring that all vendor relationships adhere to regulatory standards, align with corporate cybersecurity policies, and fulfill the organization's...


  • Minnesota, United States PRI Technology Full time

    The Director of Third-Party Cyber Risk Management plays a pivotal role in shaping and executing the organization’s strategy for managing cyber risks associated with external partners. This position is essential for ensuring that all external collaborations adhere to regulatory standards, align with corporate cybersecurity policies, and fulfill the...


  • Minneapolis, Minnesota, United States Wipfli LLP Full time

    About the RoleWipfli LLP is seeking a highly motivated and detail-oriented Cybersecurity Intern to join our team. As a Cybersecurity Intern, you will have the opportunity to work alongside our experienced Security Consultants in various areas of cybersecurity, including security testing, network security, social engineering exercises, and governance, risk,...


  • Minneapolis, Minnesota, United States Wipfli LLP Full time

    About the RoleWe are seeking a highly motivated and detail-oriented Cybersecurity Intern to join our team at Wipfli LLP. As a Cybersecurity Intern, you will have the opportunity to work alongside our experienced Security Consultants in one or more of the following areas:Key ResponsibilitiesAssist in security testing, including network security, social...


  • Minneapolis, Minnesota, United States Wipfli LLP Full time

    Cybersecurity Internship Program OverviewWipfli LLP is seeking highly motivated and detail-oriented individuals to join our Cybersecurity Internship Program. As a cybersecurity intern, you will have the opportunity to work alongside our experienced security consultants in one or more of the following areas:Key Responsibilities:Participate in security testing...


  • Minneapolis, Minnesota, United States Wipfli LLP Full time

    About Wipfli LLPAt Wipfli LLP, we value diversity and inclusion in the workplace. Our company culture is built on the principles of respect, empathy, and open communication. We strive to create an environment where everyone feels welcome and empowered to contribute their unique perspectives and skills.Job SummaryWe are seeking a highly motivated and...


  • Minneapolis, Minnesota, United States Boulay Full time

    OverviewWe are in search of a motivated and skilled individual to become a part of our Risk Advisory Division. Our Risk Advisory Team specializes in delivering solutions that assist clients in mitigating risks associated with technology, operations, and regulatory compliance.The team conducts SOC 1/SOC 2 assessments, ISO 27001 certifications, and various...


  • Minnetonka, Minnesota, United States ThisWay Full time

    Position OverviewA leading partner is looking for a Head of Self-Insured Solutions. This role is crucial in steering product strategy, fostering innovation, and ensuring effective collaboration across various teams to enhance the self-insured product line's market presence.Key Responsibilities- Formulate both short-term and long-term product strategies,...


  • Minnesota Lake, United States Ascent Solutions Full time

    Join Ascent Solutions Combine one of the fastest growing industries on the planet with collaboration, intellectual diversity, and a culture of excellence-this is what you get. Soaring cyber risk is here to stay, but so are our consultants. We are builders and technologists with a passion for cybersecurity. Join us on our mission to help the nation's top...


  • Minnesota, United States GeoComm Full time

    Opportunity OverviewWe are in search of a dynamic leader to assume the position of Chief Product Officer at GeoComm. This role is pivotal in steering product oversight, technology advancements, and software development initiatives. If you possess extensive experience and a forward-thinking approach to innovation in cloud technologies and software as a...


  • Minnesota, United States GeoComm Full time

    Exciting Leadership RoleWe are seeking a dynamic and experienced professional to assume the position of Chief Product Officer at GeoComm. This pivotal role involves directing product strategy, software engineering, and technological advancements. If you possess a strong vision for fostering innovation in cloud technologies and software as a service (SaaS)...


  • Minnesota, United States JEFF SMITH & ASSOCIATES, INC. Full time

    Company Overview: Jeff Smith & Associates, Inc. is a specialized recruiting firm dedicated to connecting exceptional talent with opportunities in the Water and Wastewater Treatment sectors.Position Summary: Our client, a pioneering nanobubble technology firm, is on a mission to harness the potential of nanobubbles to improve and safeguard water, food, and...


  • Minnesota, United States JEFF SMITH & ASSOCIATES, INC. Full time

    Company Overview: Jeff Smith & Associates, Inc. is a premier technical recruiting firm specializing in the Water and Wastewater Treatment sectors, dedicated to connecting exceptional talent with leading organizations.Position Summary: Our client, a pioneering company in nanobubble technology, is on a mission to harness the potential of nanobubbles to improve...


  • Minnesota, United States JEFF SMITH & ASSOCIATES, INC. Full time

    Company Overview: Jeff Smith & Associates, Inc. is a renowned technical recruiting firm dedicated to connecting exceptional talent with opportunities in the Water and Wastewater Treatment sectors.Position Summary: Our client, a pioneering company in nanobubble technology, is seeking a skilled Project Manager to spearhead the design, engineering, procurement,...


  • Minnesota, United States Securian Financial Group Full time

    About the RoleThis position is responsible for planning and executing the organization's business operations on a regular basis. Defines, develops, improves, and ensures alignment with operational best practices, processes, and policies to support strategy and goals. Increases the effectiveness and efficiency of support services through Operational...


  • Minnesota, United States Securian Financial Group Full time

    About the RoleThis position is responsible for planning and executing the organization's business operations on a regular basis. The Commercial Mortgage Loan Operations Specialist will define, develop, improve, and ensure alignment with operational best practices, processes, and policies to support strategy and goals. This role will increase the...


  • Minneapolis, Minnesota, United States Fairview Health Services Full time

    Overview:The Head of Technology Asset Management Strategy is tasked with the comprehensive oversight of all hardware, software, and Configuration Management Database (CMDB) assets across Fairview Health Services. This position focuses on direct management and operational execution to guarantee asset efficiency, adherence to financial and regulatory...


  • Minnesota, United States X4 Life Sciences Full time

    Quality Assurance DirectorX4 Life Sciences is committed to enhancing patient outcomes through innovative technology and superior products. In the role of Quality Assurance Director, you will be instrumental in guaranteeing the quality, safety, and regulatory compliance of diagnostic and software-based medical devices. This strategic leadership position...


  • Minnesota, United States X4 Life Sciences Full time

    Quality Assurance DirectorX4 Life Sciences is committed to enhancing patient outcomes through innovative technology and superior quality products. In the role of Quality Assurance Director, you will be instrumental in guaranteeing the quality, safety, and regulatory compliance of diagnostic and software-based medical devices. This leadership position...