Director of Cyber Third-Party Assurance
3 days ago
Full-Time, Boston, Springfield
The Opportunity
As the Director of the Cyber Third-Party Assurance team you will work in a fast-paced, collaborative environment overseeing the onboarding and continuous monitoring of Mass Mutual's third-parties. The Director of Cyber Third-Party Assurance (CTPA) leads the enterprise's vendor and supplier cybersecurity risk management function. This role is responsible for ensuring that third-party engagements meet Mass Mutual's cybersecurity standards and comply with regulatory expectations. The position manages a team responsible for four critical verticals: onboarding new vendors, conducting risk-based assessments of returned questionnaires, actively monitoring critical vendors through continuous oversight and managing third-party risk questionnaires received when Mass Mutual serves as a vendor. This role ensures that there is a consistent, risk-driven approach to protecting the enterprise from supplier-related cyber threats.
- Vendor Onboarding & Due Diligence:
Oversee the vendor onboarding process, beginning with inherent risk assessments and tailored due diligence questionnaires. Lead the review of questionnaire responses, assign risk scores, and determine requirements for follow-up remediation or reassessment. Partner with Procurement, Legal, and Governance to ensure contract language reflects cyber requirements.
- Ongoing Vendor Monitoring:
Direct continuous monitoring of critical and high-risk vendors using third-party risk intelligence tools (e.g., RiskRecon). Oversee periodic reassessments based on vendor tier, risk exposure, and regulatory requirements. Ensure supplier vulnerabilities and incident notifications are addressed and escalated appropriately.
- Third-Party Questionnaire Responses:
Manage the function that responds to cybersecurity questionnaires MassMutual receives as a third party to other organizations. Ensure responses are accurate, consistent, and aligned with enterprise security posture and regulatory expectations.
- Governance, Reporting & Stakeholder Engagement:
Provide executive-level reporting on third-party cyber risk posture, metrics, and emerging risks. Align with Governance, Enterprise Risk Management, and Internal Audit to ensure defensible oversight. Partner with BISOs, platform engineering, and security control owners to ensure vendor cyber risk is accurately identified and managed.
The Team
The Cyber Third-Party Assurance (CTPA) team plays a critical role in protecting Mass Mutual's enterprise by managing cyber and operational risks across its vast supplier ecosystem. This team serves as a strategic partner to the business, providing assurance that our vendors and SaaS providers maintain the highest standards of security, compliance, and resilience. Leveraging advanced tools and regulatory expertise, CTPA delivers proactive risk insights, drives remediation of control gaps, and strengthens the organization's ability to meet stringent expectations from regulators, clients and the board. The team operates at the intersection of governance, procurement, and enterprise risk, ensuring that third-party dependencies do not become enterprise vulnerabilities. By leading this function, the incoming director will directly influence Mass Mutual's risk posture, reputation and ability to innovate securely with trusted partners.
The Impact:
- Protects the enterprise from supplier-related cyber threats and regulatory exposure.
- Strengthens resilience through proactive risk identification, monitoring, and remediation.
- Enhances vendor trust and reputation through a mature, transparent, and defensible third-party cyber risk program.
- Provides leadership with actionable intelligence to inform decision-making.
The Minimum Qualifications
Bachelor's degree in information technology, Cyber Security, or a related field.
8+ years of experience in cybersecurity, including 4+ years in a leadership role focused on third-party risk management, or vendor assurance.
- Authorized to work in the US without requiring sponsorship now and in the future.
The Ideal Qualifications
- Knowledge of regulatory frameworks (NIST CSF 2.0, CRI Profile, etc.).
- Strong analytical skills for measuring program effectiveness and driving continuous improvement.
- Demonstrated experience in managing risk assessments, due diligence, and continuous monitoring processes.
- Familiarity with vendor risk intelligence platforms (e.g., , RiskRecon) and GRC tools (e.g., Archer, Process Unity).
- Excellent communication and stakeholder engagement skills, including executive-level reporting.
- CISSP, CTPRP, or related certifications preferred.
MassMutual is an equal employment opportunity employer. We welcome all persons to apply.
If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.
-
Boston, Massachusetts, United States Vertex Inc. Full time $174,400 - $261,600Job DescriptionAs a key Team Manager and leader in the Strategic Sourcing function, the Director, Strategic Sourcing Enterprise Third-party Risk Process & Governance leader is responsible for leading the operational execution of the end-to-end third party risk process as a key member of the Central Risk Management team. This role is responsible for shaping,...
-
Director of Quality Assurance
4 days ago
Boston, Massachusetts, United States Childrens Services Of Roxbury Full time $80,000 - $120,000 per yearABOUT THE POSITIONThe Quality Assurance Director leads quality assurance, compliance, and training oversight across the Behavioral Health Department. This leadership role ensures CSR's behavioral health programs maintain the highest standards of service quality, regulatory compliance, and effectiveness. The Director supervises the Training & Staff...
-
Sr. Director, Risk
4 days ago
Boston, Massachusetts, United States Acrisure Full time $217,000 - $290,000Job DescriptionSr. Director, Risk – Corporate InsuranceAbout Acrisure A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance,...
-
Senior Cyber Security Engineer
2 days ago
Boston, Massachusetts, United States Recorded Future Full time $127,500 - $191,500 per yearWith 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world's most advanced, and largest, intelligence companyThe Role:Recorded Future supports security teams at some of the most ambitious organizations on the planet. The Senior Cyber Security Engineer - Tech Lead is a function of our Professional Services group,...
-
Staff Attorney
4 days ago
Boston, Massachusetts, United States Plymouth Rock Assurance Full time $80,000 - $150,000 per yearPlymouth Rock Assurance Company seeks a full-time Attorney with a minimum five to seven years of experience with an insurance defense background to take over a BI case load. The office is in Boston, MA. The attorney would be responsible for representing civil defendants in all counties in the state with primary venues Middlesex, Suffolk, Essex and Norfolk...
-
Customer Service Representative
3 days ago
Boston, Massachusetts, United States Plymouth Rock Assurance Full time $45,000 - $50,500 per yearAs a Customer Service Representative, you will work in a dynamic environment where professionalism and commitment to a team environment is highly valued. Representatives manage inbound calls from our customers, agents, and third parties. The representative will also process policy change requests and work independently on project assignments, so attention to...
-
Claims Representative
4 days ago
Boston, Massachusetts, United States Plymouth Rock Assurance Full time $50,000 - $66,000 per yearThe Auto Property Damage Claims Representative is responsible for managing Auto Property Damage claims within our "Auto PD Claim Unit." This role demands a high level of customer service, patience, and professionalism while working in a fast-paced environment with significant phone interaction. Strong customer service, organizational, verbal, and written...
-
Revenue Operations Manager
4 days ago
Boston, Massachusetts, United States Black Kite Full time $100,000 - $120,000 per yearAbout Black KiteCome join the leader in cyber third-party risk intelligence Black Kite gives organizations a comprehensive, real-time view into cyber ecosystem risk so they can make informed risk decisions and improve business resilience while continuously monitoring more vendors, partners, and suppliers in an ever-changing digital landscape. Through an...
-
Director, Security Counsel
2 days ago
Boston, Massachusetts, United States Autodesk Full time $202,300 - $327,250 per yearJob Requisition ID #25WD92672Position OverviewWith Autodesk software, you have the power to Make Anything. The future of making is here, bringing with it radical changes in the way things are designed, made, and used. Autodesk is continually ranked a top place to work by Fortune, Forbes, Glassdoor, and others.As Director, Data Security Counsel, you'll have...
-
Regional Sales Director
4 days ago
Boston, Massachusetts, United States armis Full time $180,000 - $220,000 per yearArmis, the cyber exposure management & security company, protects the entire attack surface and manages an organization's cyber risk exposure in real time. In a rapidly evolving, perimeter-less world, Armis ensures that organizations continuously see, protect and manage all critical assets - from the ground to the cloud. Armis secures Fortune 100, 200 and...