IT Security Manager – Third Party Cyber Risk Management (Contract)
I'm partnering with a leading biotechnology company seeking an experienced IT Security Manager to support enterprise-wide Third-Party Cyber Risk Management (TPCRM), vendor security governance, cybersecurity audits, and regulatory compliance initiatives.
Requirements
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field
- 5+ years of experience in information security, third-party cyber risk management (TPCRM), or IT risk management
- Experience within Pharma, Biotech, Healthcare, or other highly regulated environments
- Strong knowledge of security and compliance frameworks including NIST, ISO 27001, GDPR, SOX, HIPAA, FISMA, and GxP
- Experience conducting vendor security assessments, supplier risk reviews, and third-party security evaluations
- Experience reviewing SOC 1/SOC 2 reports, audit findings, and security assurance documentation
- Experience using GRC platforms such as ServiceNow, Archer, MetricStream, Galvanize, Vanta, or similar tools
- Professional certifications such as CISSP, CISM, CRISC, or CISA preferred
- Experience working within global organizations and cross-functional teams
Responsibilities
- Support and enhance the organization's Third-Party Cyber Risk Management (TPCRM) program
- Develop, maintain, and improve vendor security standards, processes, and documentation
- Conduct security risk assessments and manage supplier remediation activities
- Evaluate vendor security controls, compliance evidence, and assurance reports
- Develop and maintain TPCRM metrics, KPIs, KRIs, and executive reporting
- Monitor and communicate third-party security risks across the business
- Partner with Procurement, Legal, Compliance, Privacy, Quality, and IT stakeholders to align security requirements
- Drive initiatives supporting compliance with evolving cybersecurity regulations, including NIS2
- Develop and execute cybersecurity audit programs and risk-based audit plans
- Track audit findings, remediation efforts, and continuous improvement initiatives
- Support implementation of security controls, risk management processes, and governance frameworks
- Guide business teams on security requirements, risk mitigation, and best practices
Preferred
- Experience building or improving enterprise TPCRM programs
- Strong understanding of vendor assurance frameworks and audit methodologies
- Experience establishing cybersecurity governance and audit functions
- Knowledge of emerging cybersecurity threats, regulations, and industry best practices
- Strong communication, stakeholder management, and presentation skills
- Excellent analytical, organizational, and problem-solving abilities
Location: Remote/Hybrid
Duration: 6-Month Contract
Interviews are starting soon, so if you're interested and would like to be considered, give me a call at as soon as you're available.
Information Technology Security Manager in princeton at Unknown Company
This position is listed as contract and able to be worked remotely.