Information Technology Security Manager
Job Description
IT Security Manager – Third Party Cyber Risk Management (Contract)
\n
\n
I'm partnering with a leading biotechnology company seeking an experienced IT Security Manager to support enterprise-wide Third-Party Cyber Risk Management (TPCRM), vendor security governance, cybersecurity audits, and regulatory compliance initiatives.
\n
\n
Requirements
\n
• Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field
\n
• 5+ years of experience in information security, third-party cyber risk management (TPCRM), or IT risk management
\n
• Experience within Pharma, Biotech, Healthcare, or other highly regulated environments
\n
• Strong knowledge of security and compliance frameworks including NIST, ISO 27001, GDPR, SOX, HIPAA, FISMA, and GxP
\n
• Experience conducting vendor security assessments, supplier risk reviews, and third-party security evaluations
\n
• Experience reviewing SOC 1/SOC 2 reports, audit findings, and security assurance documentation
\n
• Experience using GRC platforms such as ServiceNow, Archer, MetricStream, Galvanize, Vanta, or similar tools
\n
• Professional certifications such as CISSP, CISM, CRISC, or CISA preferred
\n
• Experience working within global organizations and cross-functional teams
\n
\n
Responsibilities
\n
• Support and enhance the organization's Third-Party Cyber Risk Management (TPCRM) program
\n
• Develop, maintain, and improve vendor security standards, processes, and documentation
\n
• Conduct security risk assessments and manage supplier remediation activities
\n
• Evaluate vendor security controls, compliance evidence, and assurance reports
\n
• Develop and maintain TPCRM metrics, KPIs, KRIs, and executive reporting
\n
• Monitor and communicate third-party security risks across the business
\n
• Partner with Procurement, Legal, Compliance, Privacy, Quality, and IT stakeholders to align security requirements
\n
• Drive initiatives supporting compliance with evolving cybersecurity regulations, including NIS2
\n
• Develop and execute cybersecurity audit programs and risk-based audit plans
\n
• Track audit findings, remediation efforts, and continuous improvement initiatives
\n
• Support implementation of security controls, risk management processes, and governance frameworks
\n
• Guide business teams on security requirements, risk mitigation, and best practices
\n
\n
Preferred
\n
• Experience building or improving enterprise TPCRM programs
\n
• Strong understanding of vendor assurance frameworks and audit methodologies
\n
• Experience establishing cybersecurity governance and audit functions
\n
• Knowledge of emerging cybersecurity threats, regulations, and industry best practices
\n
• Strong communication, stakeholder management, and presentation skills
\n
• Excellent analytical, organizational, and problem-solving abilities
\n
Location: Remote/Hybrid
\n
Duration: 6-Month Contract
\n
\n
\n
Interviews are starting soon, so if you're interested and would like to be considered, give me a call at (919) 892-9841 as soon as you're available.
