IT Security Manager - Third-Party IT Risk Manager
$118,300–$207,400 year
On-siteChicago, Illinois, United States or New York City, New York, United States
Job Summary
Lead and modernize Wolters Kluwer's global Third-Party Risk Management program by evolving it from a questionnaire-driven model to a data-driven approach incorporating technical validation, continuous monitoring, and AI. Implement continuous monitoring capabilities to deliver near real-time visibility into third-party cyber posture and emerging risk indicators while designing automation for evidence collection and risk scoring. Maintain a centralized enterprise inventory of third-party relationships and provide clear reporting on risk trends to senior leadership. Build and develop a high-performing team of risk professionals, fostering a culture of accountability and innovation across Global Supply Chain, Procurement, Legal, and Privacy functions.
Required Qualifications
- Bachelors degree in computer science, information security, management information systems or similar
- 12+ years of experience in cybersecurity, technology risk, or information security
- significant ownership of third party or supplier cyber risk management in large, complex enterprises
- 5+ years of leadership (direct managerial experience or functional delivery leading teams)
- Proven experience designing and leading a global TPRM program across the full third party risk lifecycle
- Demonstrated success modernizing TPRM by implementing risk based approaches that integrate technical validation, automation, and continuous monitoring
- Demonstrated success owning decisions and outcomes at a senior level independently without formal authority
- Strong technical fluency across cloud platforms, APIs, identity, data flows, and integration architectures
- Ability to partner credibly with security architects and technical SMEs
- Experience overseeing advanced technical assessments for high risk or critical third parties, such as architecture reviews, vulnerability assessments, penetration testing, and threat modeling
- Ability to operate effectively in highly distributed, market driven environments
- Demonstrated leadership experience, including building high performing teams and influencing senior stakeholders across Technology, Procurement, Legal, Privacy, and Enterprise Risk Management
- Strong executive communication skills, with experience reporting third party cyber risk posture and trends to senior leadership
- Familiarity with systemic, concentration, and fourth‐party risk
- Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA
- Relevant certifications (e.g., CISSP, CISM, CTPRP, CRISC, CISA)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.