Sr. Manager of Cybersecurity, Third Party Risk
Advance Auto Parts
Job Description
Position Summary The Sr. Manager of Cybersecurity Third-Party Risk Management leads the enterprise program responsible for identifying, assessing, monitoring, reporting, and reducing cybersecurity risks introduced by suppliers, vendors, service providers, contractors, technology partners, SaaS platforms, cloud providers, managed service providers, and other third parties. This role exists to establish and mature a risk-based third-party cybersecurity risk management program aligned to enterprise risk appetite and business priorities, ensure cybersecurity due diligence is performed before onboarding, renewal, material change, or expansion of third-party services, provide executive visibility into third-party cyber risk exposure, remediation status, systemic supplier risk, and program maturity, to reduce cyber, regulatory, operational, privacy, resiliency, and reputational risk associated with third-party relationships. This position is a hybrid work model (4 days in office, 1 day work from home) based in our corporate headquarters in Raleigh, NC. Key Responsibilities
Program Governance and Strategy
Position Summary The Sr. Manager of Cybersecurity Third-Party Risk Management leads the enterprise program responsible for identifying, assessing, monitoring, reporting, and reducing cybersecurity risks introduced by suppliers, vendors, service providers, contractors, technology partners, SaaS platforms, cloud providers, managed service providers, and other third parties. This role exists to establish and mature a risk-based third-party cybersecurity risk management program aligned to enterprise risk appetite and business priorities, ensure cybersecurity due diligence is performed before onboarding, renewal, material change, or expansion of third-party services, provide executive visibility into third-party cyber risk exposure, remediation status, systemic supplier risk, and program maturity, to reduce cyber, regulatory, operational, privacy, resiliency, and reputational risk associated with third-party relationships. This position is a hybrid work model (4 days in office, 1 day work from home) based in our corporate headquarters in Raleigh, NC. Key Responsibilities
Program Governance and Strategy
- Lead the enterprise Cybersecurity Third-Party Risk Management program, including strategy, operating model, governance, policies, standards, procedures, assessment methodology, and reporting.
- Develop and maintain risk-based third-party cybersecurity requirements aligned to NIST CSF 2.0, NIST 800-161, SOC 2, PCI DSS, privacy obligations, and enterprise security standards.
- Define and maintain the third-party cyber risk lifecycle, including intake, inherent risk scoring, due diligence, control assessment, remediation, risk acceptance, ongoing monitoring, renewal review, material change review, and offboarding.
- Establish governance forums and escalation paths for high-risk vendors, overdue remediation, policy exceptions, and material cyber risk decisions.
- Continuously improve program maturity, automation, workflow efficiency, stakeholder experience, and audit readiness.
- Oversee cybersecurity risk assessments for new and existing vendors.
- Evaluate vendor controls across identity and access management, network security, cloud security, application security, data protection, encryption, vulnerability management, endpoint protection, logging and monitoring, incident response, disaster recovery, secure SDLC, privacy, and governance.
- Review evidence such as SOC 2 Type II reports, ISO 27001 certificates, bridge letters, penetration test summaries, vulnerability scan results, SIG/CAIQ questionnaires, security policies, architecture diagrams, audit reports, and remediation plans.
- Determine residual risk and provide recommendations for approval, conditional approval, remediation, escalation, risk acceptance, or vendor rejection.
- Partner with Legal, Procurement, Privacy, Compliance, and business teams to ensure cybersecurity requirements are embedded in vendor contracts and statements of work.
- Review and advise on contractual clauses related to security controls, breach notification, incident cooperation, right to audit, data protection, encryption, access control, regulatory compliance, cyber insurance, subcontractors, business continuity, data retention, and secure data destruction.
- Track deviations from standard cybersecurity terms, document risk implications, and route exceptions for appropriate approval.
- Operate ongoing monitoring for high-risk and critical vendors, including security ratings, public breach intelligence, certification expiration, control failures, vulnerability exposure, service disruptions, and material business changes.
- Maintain a centralized view of open vendor cyber findings, remediation commitments, accepted risks, compensating controls, and exceptions.
- Drive remediation of vendor control gaps from identification through validation and closure.
- Escalate overdue or unacceptable vendor risks through cybersecurity governance, procurement governance, enterprise risk forums, or executive leadership as appropriate.
- Partner with business owners to ensure vendor risk decisions are understood, documented, and aligned to enterprise risk appetite.
- Assess cybersecurity risks associated with subcontractors, subprocessors, hosting providers, offshore delivery models, managed service delivery chains, and other fourth-party dependencies.
- Identify concentration risk related to common technology platforms, critical suppliers, geographic dependencies, cloud service providers, and systemic service providers.
- Require transparency into material subcontractors and downstream access to company data or systems.
- Partner with business continuity, resilience, procurement, and enterprise risk teams to evaluate critical supplier resilience and recovery capabilities.
- Develop executive-level metrics, dashboards, and risk narratives showing third-party cyber risk posture, critical vendor coverage, assessment volume, remediation aging, risk acceptance trends, contractual coverage, and program maturity.
- Report third-party cyber risk trends to cybersecurity leadership, enterprise risk committees, , audit stakeholders, and executive leadership.
- Translate technical findings into business risk language that enables informed decisions by senior leaders and business owners.
- Prepare materials for audit, regulatory inquiries, board reporting, and internal governance reviews as needed.
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or equivalent experience.
- 8+ years of experience in cybersecurity, third-party risk management, vendor risk management, technology risk, IT audit, governance/risk/compliance, or related disciplines.
- 3+ years of leadership experience managing people, programs, or cross-functional risk initiatives.
- Demonstrated experience operating cybersecurity risk management processes in a large enterprise, publicly traded, highly regulated, or Fortune 500 environment.
- Strong understanding of cybersecurity control domains, including identity, cloud, network, endpoint, application security, data protection, vulnerability management, logging/monitoring, incident response, and resilience.
- Experience reviewing vendor security evidence, including SOC 2, ISO 27001, SIG/CAIQ, penetration test summaries, vulnerability reports, audit reports, and remediation plans.
- Experience partnering with Procurement and Legal on cybersecurity terms and vendor contract negotiations.
- Ability to communicate cyber risk clearly to technical teams, business stakeholders, executives, legal partners, auditors, and risk committees.
- Strong judgment, prioritization, program management, issue management, and stakeholder influence skills.
- Experience with ServiceNow GRC/IRM, Archer, OneTrust, ProcessUnity, Coupa, Ariba, Prevalent, BitSight, SecurityScorecard, UpGuard, or similar third-party risk platforms.
- Knowledge of NIST CSF 2.0, NIST SP 800-161, ISO 27001, SOC 2 Trust Services Criteria, PCI DSS, SOX, GDPR/CCPA, and SEC cybersecurity disclosure expectations.
- Professional certification such as CISSP, CISM, CRISC, CISA, CCSP, CCSK, CDPSE, ISO 27001 Lead Auditor/Implementer, or third-party risk management certification.
- Experience with critical suppliers, cloud service providers, managed service providers, offshore support models, payment processors, data processors, and operationally critical vendors.
- Experience supporting board, audit committee, enterprise risk committee, or executive-level cybersecurity reporting.
- Experience transforming or scaling a third-party cyber risk program across a complex supplier ecosystem.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Sr. Manager of Cybersecurity, Third Party Risk in Raleigh, NC vacancy
- State Employees' Credit Union in Raleigh seeks a Third Party Risk Management Analyst II to oversee third-party risk management governance and ensure compliance with regulations. The role includes executing due diligence documentation, supporting program management, and...RiskWork at office2 days per week
- ## Third Party Risk Management Analyst IIApplylocations: Raleigh - Salisbury Sttime type: Full timeposted on: Posted Todayjob requisition id: JR-15290**If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!**Position Overview...Risk2 days per week
$35.87 - $51.57 per hour
...serve. Summary : The HCS Compliance Analyst III will be assigned to support the Compliance and Privacy Operations - Third Party Risk Management Department in the Compliance Program and will report directly to the manager of that team. Relevant work assignments may...RiskHourly payFull time- ...following job description: Truist Senior Audit Manager is responsible for providing a... ...of value-added independent and objective risk-based internal audit assurance and advisory... ...principles and practices of technology, cybersecurity, IT infrastructure, IT service...SeniorRiskFull timePart timeWork at officeRelocationShift workDay shift
$35.87 - $51.57 per hour
A healthcare provider in Morrisville, NC is seeking a Compliance Analyst III to support its Compliance and Privacy Operations. This role involves conducting audits, leading investigations, and developing relationships with various teams to ensure compliance with laws and...SeniorRiskHourly payFull time- ...FUJIFILM Biotechnologies #35288-Sr. IT Engineer 1, CSV - Holly... ...supports regulatory agency, and third-party inspections, as needed.... ...lifecycle documentation (e.g., risk and impact assessments, user requirement... ...Systems Assists with managing the allocation of contract CSV...SeniorRiskFull timeContract workLocal area
$145k - $220k
...across AWS and Azure, aligned with enterprise risk appetite and business objectives. Lead... ...Model training, deployment, and lifecycle management. Data protection, privacy, and integrity in AI pipelines. Secure use of third‑party and foundation models. Address emerging...SeniorRisk- Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and...SeniorRisk
- Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and...SeniorRisk
- ...Director, you will assist senior management in the development and... ...the project among interested parties including investors, market research... ...knowledge, taking calculated risks aligned with our convictions... .... No calls or emails from third parties at this time please....SeniorRiskWork experience placementWork at officeLocal area
- ...Description Role Summary The Cybersecurity Compliance Manager is responsible for designing,... ...including: PCI DSS attestations HIPAA risk and compliance reviews Privacy... ...(CDE). Familiarity with third-party risk and vendor compliance monitoring...SeniorRiskLocal area
$31.04 - $44.62 per hour
...organization is seeking an HCS Compliance Analyst I for their Compliance and Privacy Operations. Responsibilities include supporting risk management, conducting audits, and collaborating with various teams. Candidates should have relevant degree and experience in healthcare...RiskHourly payFull time- ...Sr. Cybersecurity Lead New York, New York, United States ATLAS SP... ...comprehensive service across the asset management landscape. ATLAS... ...potential security risks, help develop, implement and... ...Experience managing and influencing third-party security vendors. • Manage...RiskLocal area
$120k - $150k
Description Sr IT Project Manager Salary Range: $120,000.00 to $150,000.00 depending on experience... ..., engineering teams, QA, and third-party vendors to ensure solutions are delivered... ...expectations. Proactively identify delivery risks, issues, and dependencies, and drive...SeniorRiskRemote work$102.5k - $187.9k
...Banking and Capital Markets, Wealth and Asset Management, Insurance, and Real Estate, Hospitality... ...remediation and mitigation of process risk. You will assist engagement teams... ...with client technology professionals or third-party strategic alliances to provide implementation...SeniorRiskWork experience placementSummer holidayFlexible hours- ...COMPANY OVERVIEW Asset Living is a third-party management firm and a proven partner in fostering thriving communities nationwide. Founded... ...personnel, leasing, maintenance, financial, administration & risk management. As an on-site leader, you will supervise all aspects...RiskPermanent employmentFull timeFor contractorsWork at officeNight shiftWeekend work
- ...contentThis site uses cookies from Hitachi and third parties for our own business purposes and to... ...Cookies Policy.#Associate Project Manager page is loaded## Associate Project ManagerApplyremote... ....* Maintain documentation, support risk management, and uphold compliance...RiskFull timeFor subcontractorRemote workRelocation
- Summary The Sr. Intelligence Risk Analyst will lead enterprise‑wide efforts in data‑informed threat... ..., open‑source intelligence, and third‑party feeds). Develop predictive and geospatial... .... Develop and deliver training for management and frontline teams on data driven crime...SeniorRiskShift work
- ...WY The Business Aligned and Category Management team within Enterprise Sourcing is seeking... ...solutions aligned to the Bank's risk appetite. Conducts sourcing events (RFx)... ...savings. Works collaboratively with the Third Party Risk Management (TPRM) team to ensure contract...RiskContract workRemote work
- ...quality ingredient. The Production Shift Manager is responsible for overseeing all... ...unit ahead of the curve. Compliance and Risk Management: Ensure that the business unit... ...restaurants, international licensees, and third‑party bakery customers. The Cheesecake Factory...RiskFull timeCasual workShift work
- ...including incident response and incident management, threat intelligence, threat hunting... ...updates focused on business impact and risk. Provide operational oversight for U.... ...regional service providers and support third party incident response engagements when activated...RiskFull timeLocal areaShift work
$128.1k - $239.6k
...Information Security we blend risk strategy, digital identity,... ...on these pillars: Risk Management and Reduction: Assisting with... ...infrastructure, applications, and third-party dependencies. Improve... ...managing a team. A degree in Cybersecurity, Information Security, Computer...RiskWork experience placementSummer holidayLocal areaFlexible hours$80k
Company Overview Asset Living is a third‑party management firm and a proven partner in fostering thriving communities nationwide. Founded in 19... ...personnel, leasing, maintenance, financial, administration & risk management. As an on‑site leader, you will supervise all...RiskFull timeFor contractorsWork at officeNight shiftWeekend work$286.2k - $326.7k
...- AML (Remote - Eligible)As a Sr. Distinguished Engineer at Capital... ...learning experts, product managers and people leaders. Our Distinguished... ....As our CEO often says, "Risk management is the business,"... ...guarantee and is not liable for third-party products, services,...SeniorRiskFull timePart timeLocal areaRemote work- ...networking media, internal, and 3rd party job boards, we identify qualified candidates... ...Experienced senior project manager in both in-house and third party developed solution implementation... ...project status, meetings, scope changes, risk and issue tracking/mitigation,...RiskContract workShift work
$124k - $335k
...Industry/Sector Asset and Wealth Management Specialism Industry Tax Practice Management... ...of goods and services between related parties, as well as providing advice on tax... ...requirements, management of operational tax risks, and tax implications of investing in...SeniorRiskH1bLocal areaOverseas- ...presents a wide range of risks to the solutions... ...Lenovo developed and 3rd party, using industry-standard... ..., developers, project managers, and testers -... ...security of Lenovo- and third party-developed software... ...related field; or relevant cybersecurity experience of 5+ years...SeniorRiskLocal areaHome office
- ...health authority expectations. May serve as manager delegate with demonstrated experience,... ...timelines, quality milestones, and risk mitigation plans for site readiness. Keep... ...last 10 years, and you can grow with us! Third Party Agency And Recruiter Notice Agencies that...SeniorRisk
$35.87 - $51.57 per hour
...healthcare provider is seeking a Compliance Analyst III to enhance their Compliance Program. You will lead audits, analyze compliance risks, and train staff while ensuring adherence to regulatory requirements. Ideal candidates have 8 years of compliance experience and a...SeniorRiskHourly pay$124.16k - $207.58k
...About the job Sr. Regulatory Professional Job Title:... ...requirements. Proactively manages the changing regulatory environment... ...and mitigates areas of risk. Reviews product labeling... ...coordination with other functions, third parties. Solves a broad range of...SeniorRiskFull timeContract workLocal areaRemote workWorldwideShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Manager of Cybersecurity, Third Party Risk. Be the first to apply!
Related searches
- cyber security lead Raleigh, NC
- director - cyber security Raleigh, NC
- cybersecurity manager Raleigh, NC
- risk management specialist Raleigh, NC
- risk management associate Raleigh, NC
- director credit risk Raleigh, NC
- risk management manager Raleigh, NC
- head of risk management Raleigh, NC
- senior risk manager Raleigh, NC
- operational risk manager Raleigh, NC

