Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Manager of Cybersecurity, Third Party Risk

Advance Auto Parts

Job Description
Position Summary

The Sr. Manager of Cybersecurity Third-Party Risk Management leads the enterprise program responsible for identifying, assessing, monitoring, reporting, and reducing cybersecurity risks introduced by suppliers, vendors, service providers, contractors, technology partners, SaaS platforms, cloud providers, managed service providers, and other third parties.

This role exists to establish and mature a risk-based third-party cybersecurity risk management program aligned to enterprise risk appetite and business priorities, ensure cybersecurity due diligence is performed before onboarding, renewal, material change, or expansion of third-party services, provide executive visibility into third-party cyber risk exposure, remediation status, systemic supplier risk, and program maturity, to reduce cyber, regulatory, operational, privacy, resiliency, and reputational risk associated with third-party relationships.

This position is a hybrid work model (4 days in office, 1 day work from home) based in our corporate headquarters in Raleigh, NC.

Key Responsibilities
Program Governance and Strategy
  • Lead the enterprise Cybersecurity Third-Party Risk Management program, including strategy, operating model, governance, policies, standards, procedures, assessment methodology, and reporting.
  • Develop and maintain risk-based third-party cybersecurity requirements aligned to NIST CSF 2.0, NIST 800-161, SOC 2, PCI DSS, privacy obligations, and enterprise security standards.
  • Define and maintain the third-party cyber risk lifecycle, including intake, inherent risk scoring, due diligence, control assessment, remediation, risk acceptance, ongoing monitoring, renewal review, material change review, and offboarding.
  • Establish governance forums and escalation paths for high-risk vendors, overdue remediation, policy exceptions, and material cyber risk decisions.
  • Continuously improve program maturity, automation, workflow efficiency, stakeholder experience, and audit readiness.
Vendor Cybersecurity Risk Assessments
  • Oversee cybersecurity risk assessments for new and existing vendors.
  • Evaluate vendor controls across identity and access management, network security, cloud security, application security, data protection, encryption, vulnerability management, endpoint protection, logging and monitoring, incident response, disaster recovery, secure SDLC, privacy, and governance.
  • Review evidence such as SOC 2 Type II reports, ISO 27001 certificates, bridge letters, penetration test summaries, vulnerability scan results, SIG/CAIQ questionnaires, security policies, architecture diagrams, audit reports, and remediation plans.
  • Determine residual risk and provide recommendations for approval, conditional approval, remediation, escalation, risk acceptance, or vendor rejection.
Contractual Cybersecurity Requirements
  • Partner with Legal, Procurement, Privacy, Compliance, and business teams to ensure cybersecurity requirements are embedded in vendor contracts and statements of work.
  • Review and advise on contractual clauses related to security controls, breach notification, incident cooperation, right to audit, data protection, encryption, access control, regulatory compliance, cyber insurance, subcontractors, business continuity, data retention, and secure data destruction.
  • Track deviations from standard cybersecurity terms, document risk implications, and route exceptions for appropriate approval.
Ongoing Monitoring and Remediation
  • Operate ongoing monitoring for high-risk and critical vendors, including security ratings, public breach intelligence, certification expiration, control failures, vulnerability exposure, service disruptions, and material business changes.
  • Maintain a centralized view of open vendor cyber findings, remediation commitments, accepted risks, compensating controls, and exceptions.
  • Drive remediation of vendor control gaps from identification through validation and closure.
  • Escalate overdue or unacceptable vendor risks through cybersecurity governance, procurement governance, enterprise risk forums, or executive leadership as appropriate.
  • Partner with business owners to ensure vendor risk decisions are understood, documented, and aligned to enterprise risk appetite.
Fourth-Party and Supply Chain Risk
  • Assess cybersecurity risks associated with subcontractors, subprocessors, hosting providers, offshore delivery models, managed service delivery chains, and other fourth-party dependencies.
  • Identify concentration risk related to common technology platforms, critical suppliers, geographic dependencies, cloud service providers, and systemic service providers.
  • Require transparency into material subcontractors and downstream access to company data or systems.
  • Partner with business continuity, resilience, procurement, and enterprise risk teams to evaluate critical supplier resilience and recovery capabilities.
Metrics, Reporting, and Executive Communication
  • Develop executive-level metrics, dashboards, and risk narratives showing third-party cyber risk posture, critical vendor coverage, assessment volume, remediation aging, risk acceptance trends, contractual coverage, and program maturity.
  • Report third-party cyber risk trends to cybersecurity leadership, enterprise risk committees, , audit stakeholders, and executive leadership.
  • Translate technical findings into business risk language that enables informed decisions by senior leaders and business owners.
  • Prepare materials for audit, regulatory inquiries, board reporting, and internal governance reviews as needed.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or equivalent experience.
  • 8+ years of experience in cybersecurity, third-party risk management, vendor risk management, technology risk, IT audit, governance/risk/compliance, or related disciplines.
  • 3+ years of leadership experience managing people, programs, or cross-functional risk initiatives.
  • Demonstrated experience operating cybersecurity risk management processes in a large enterprise, publicly traded, highly regulated, or Fortune 500 environment.
  • Strong understanding of cybersecurity control domains, including identity, cloud, network, endpoint, application security, data protection, vulnerability management, logging/monitoring, incident response, and resilience.
  • Experience reviewing vendor security evidence, including SOC 2, ISO 27001, SIG/CAIQ, penetration test summaries, vulnerability reports, audit reports, and remediation plans.
  • Experience partnering with Procurement and Legal on cybersecurity terms and vendor contract negotiations.
  • Ability to communicate cyber risk clearly to technical teams, business stakeholders, executives, legal partners, auditors, and risk committees.
  • Strong judgment, prioritization, program management, issue management, and stakeholder influence skills.
Preferred Qualifications
  • Experience with ServiceNow GRC/IRM, Archer, OneTrust, ProcessUnity, Coupa, Ariba, Prevalent, BitSight, SecurityScorecard, UpGuard, or similar third-party risk platforms.
  • Knowledge of NIST CSF 2.0, NIST SP 800-161, ISO 27001, SOC 2 Trust Services Criteria, PCI DSS, SOX, GDPR/CCPA, and SEC cybersecurity disclosure expectations.
  • Professional certification such as CISSP, CISM, CRISC, CISA, CCSP, CCSK, CDPSE, ISO 27001 Lead Auditor/Implementer, or third-party risk management certification.
  • Experience with critical suppliers, cloud service providers, managed service providers, offshore support models, payment processors, data processors, and operationally critical vendors.
  • Experience supporting board, audit committee, enterprise risk committee, or executive-level cybersecurity reporting.
  • Experience transforming or scaling a third-party cyber risk program across a complex supplier ecosystem.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age national origin, religion, sexual orientation, gender identity, status as a veteran and basis of disability or any other federal, state or local protected class. We comply with all applicable federal, state, and local laws.

California Residents click below for Privacy Notice:

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Sr. Manager of Cybersecurity, Third Party Risk in Raleigh, NC vacancy
  • $90.78k

     ...The Sr. Analyst - Supply Chain Risk Management (SCRM) Analyst supports enterprise and program stakeholders in...  ...ensuring Maximus, Maximus Federal, and third-party relationships meet U.S. federal...  ...(e.g., performance, financial, cybersecurity, and geopolitical indicators),... 
    Senior
    Risk
    Contract work
    For subcontractor
    Work at office

    MAXIMUS

    Raleigh, NC
    6 days ago
  •  ...following job description: Truist Senior Audit Manager is responsible for providing a...  ...of value-added independent and objective risk-based internal audit assurance and advisory...  ...principles and practices of technology, cybersecurity, IT infrastructure, IT service... 
    Senior
    Risk
    Full time
    Part time
    Work at office
    Relocation
    Shift work
    Day shift

    Habitat For Humanity Of Durham

    Raleigh, NC
    2 days ago
  • $35.87 - $51.57 per hour

     ...communities we serve. Summary The HCS Compliance Analyst III will be assigned to support the Compliance and Privacy Operations - Third Party Risk Management Department in the Compliance Program and will report directly to the manager of that team. Relevant work assignments may... 
    Risk
    Hourly pay
    Full time

    Direct Jobs

    Morrisville, NC
    3 days ago
  •  ...FUJIFILM Biotechnologies #35288-Sr. IT Engineer 1, CSV - Holly...  ...supports regulatory agency, and third-party inspections, as needed....  ...lifecycle documentation (e.g., risk and impact assessments, user requirement...  ...Systems Assists with managing the allocation of contract CSV... 
    Senior
    Risk
    Full time
    Contract work
    Local area

    FUJIFILM Biotechnologies

    Raleigh, NC
    4 days ago
  • Itlearn360 is seeking a Sr Consultant for Global 3rd Party Management to oversee third party risk management activities in Cary, NC. This hybrid role requires strong leadership and operational skills and aims to enhance the user experience in TPRM processes. The ideal candidate... 
    Senior
    Risk

    Itlearn360

    Cary, NC
    4 days ago
  • Sr Consultant - Global 3rd Party MGMT - TPRM at MetLife. Cary, NC. Must live within a commutable distance of the Cary, NC, office. Hybrid...  ...responsible for providing daily operational oversight of the third party risk management (TPRM) activities. The role will become the key... 
    Senior
    Risk
    Work at office
    3 days per week

    Itlearn360

    Cary, NC
    4 days ago
  •  ...Director, you will assist senior management in the development and...  ...the project among interested parties including investors, market research...  ...knowledge, taking calculated risks aligned with our convictions...  .... No calls or emails from third parties at this time please.... 
    Senior
    Risk
    Work experience placement
    Work at office
    Local area

    Hines

    Raleigh, NC
    11 hours ago
  •  ...Job Title: Senior Manager, Product Management - Data Integrations (Platform) Location...  ...Platform) is the single-threaded owner for third-party data integrations that power advanced...  ...internal alignment, and executive-ready status/risk communication. Nice to Have:... 
    Senior
    Risk
    Work experience placement
    Remote work

    comScore

    Raleigh, NC
    5 days ago
  • $145k - $180k

     ...Senior Clinical Project Manager About Pharming Pharming...  ...Senior Clinical Project Manager (Sr. CPM) is responsible to plan,...  ...selects, guides, and supervises third party vendors and defines budgets,...  ...progress to proactively identify risks to study timelines and budget,... 
    Senior
    Risk
    Temporary work
    Work experience placement
    Local area
    Remote work
    Flexible hours

    Pharming Healthcare

    Raleigh, NC
    6 days ago
  • $145k - $165k

     ...requirements. This role works closely with project managers, superintendents, owners, and...  ...plan project activities, identify schedule risks, and implement mitigation strategies....  ...and our subsidiaries do not work with any third-party recruiters or agencies without a valid... 
    Senior
    Risk
    Daily paid
    Full time
    Contract work
    Temporary work
    Work experience placement
    For subcontractor
    Work at office
    Local area
    Flexible hours
    Shift work

    MasTec Industrial

    Raleigh, NC
    2 days ago
  •  ...main contentThis site uses cookies from Hitachi and third parties for our own business purposes and to personalize...  ...and maintain high satisfaction.* Support project managers with technical input for proposals and risk assessments.* Drive continuous improvement and share... 
    Senior
    Risk
    Full time
    Remote work

    Hitachi Automotive Systems Americas, Inc.

    Raleigh, NC
    3 days ago
  •  ...Sr. Cybersecurity Lead New York, New York, United States ATLAS SP...  ...comprehensive service across the asset management landscape. ATLAS...  ...potential security risks, help develop, implement and...  ...Experience managing and influencing third-party security vendors. • Manage... 
    Risk
    Local area

    ATLAS SP Partners

    Raleigh, NC
    2 days ago
  •  ...Description Role Summary The Cybersecurity Compliance Manager is responsible for designing,...  ...including: PCI DSS attestations HIPAA risk and compliance reviews Privacy...  ...(CDE). Familiarity with third-party risk and vendor compliance monitoring... 
    Senior
    Risk
    Local area

    Advance Auto Parts

    Raleigh, NC
    11 hours ago
  •  ...Summary The Sr. Intelligence Risk Analyst will lead enterprise-wide efforts in data-informed threat...  ..., open-source intelligence, and third-party feeds). Develop predictive and geospatial...  ...Develop and deliver training for management and frontline teams on data driven... 
    Senior
    Risk
    Shift work

    Jewelers Mutual Group

    Raleigh, NC
    11 hours ago
  • $117k - $159k

     ...The Sr. Project Management role works to plan, execute, and oversee projects to completed on time...  ...The role monitors progress, manages risks and change, resolves challenges, and...  ...Manage external resources : Including third parties/vendors to deliver successfully on their... 
    Senior
    Risk
    Contract work
    Temporary work

    Brown and Caldwell

    Raleigh, NC
    2 days ago
  •  ...institution, AI introduces risk across model performance, customer...  ...legal obligations, privacy, cybersecurity, third‑party dependency, operational...  ...governance, and reputation. Managing those risks well is exactly...  ...regulatory expectations (including SR 11‑7 / SR 26‑2, OCC guidance... 
    Risk

    First Citizens Bank

    Raleigh, NC
    4 days ago
  • $31.35 - $63.65 per hour

     ...Description Oracle Health is seeking a Product Manager to lead the onboarding, implementation, and support of third-party data source integrations. This role will...  ...implementation activities. Track project status, risks, dependencies, and delivery timelines while... 
    Risk
    Hourly pay
    Temporary work
    Work experience placement
    Flexible hours

    Oracle

    Raleigh, NC
    1 day ago
  • $102.5k - $187.9k

     ...Banking and Capital Markets, Wealth and Asset Management, Insurance, and Real Estate, Hospitality...  ...remediation and mitigation of process risk. You will assist engagement teams...  ...with client technology professionals or third-party strategic alliances to provide implementation... 
    Senior
    Risk
    Work experience placement
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Raleigh, NC
    4 days ago
  • $120k - $150k

    Description Sr IT Project Manager Salary Range: $120,000.00 to $150,000.00 depending on experience...  ..., engineering teams, QA, and third-party vendors to ensure solutions are delivered...  ...expectations. Proactively identify delivery risks, issues, and dependencies, and drive... 
    Senior
    Risk
    Remote work

    Toshiba America Business Solutions

    Raleigh, NC
    2 days ago
  •  ...projects? Gilbane is seeking a Sr. Scheduler to be a Business...  ...most reputable construction management firms in the country, Gilbane...  ...members * Trains others in risk identification and mitigation...  ...Gilbane will not pay fees to any third party agency or firm and will not... 
    Senior
    Risk
    For contractors

    Gilbane Building Company

    Raleigh, NC
    3 days ago
  • $112k - $154.9k

     ...NYSE:PD) is a leader in Digital Operations Management. In an always-on world, organizations of...  ...time operations. Proactively identify risks to the customer achieving their stated...  ...Forbes AI 50, as well as approximately two-thirds of the Fortune 100, PagerDuty is essential... 
    Senior
    Risk
    Local area
    Flexible hours

    PagerDuty

    Raleigh, NC
    3 days ago
  • $128.1k - $239.6k

     ...Information Security we blend risk strategy, digital identity,...  ...on these pillars: Risk Management and Reduction: Assisting with...  ...infrastructure, applications, and third-party dependencies. Improve...  ...managing a team. A degree in Cybersecurity, Information Security, Computer... 
    Risk
    Work experience placement
    Summer holiday
    Local area
    Flexible hours

    Ernst & Young Oman

    Raleigh, NC
    2 days ago
  • Company Overview Asset Living is a third‑party management firm and a proven partner in fostering thriving communities nationwide. Founded in 19...  ...personnel, leasing, maintenance, financial, administration & risk management. As an on‑site leader, you will supervise all... 
    Risk
    Permanent employment
    Full time
    For contractors
    Work at office
    Night shift
    Weekend work

    Asset Living

    Raleigh, NC
    2 days ago
  •  ...including incident response and incident management, threat intelligence, threat hunting...  ...updates focused on business impact and risk. Provide operational oversight for U....  ...regional service providers and support third party incident response engagements when activated... 
    Risk
    Full time
    Local area
    Shift work

    Ralliant

    Raleigh, NC
    3 days ago
  • $69.7k - $75.23k

     ...The Continuity Manager leads the development, implementation, and...  ...impact analyses and risk assessments to identify priority...  ...closely with IT operations, cybersecurity, service and process owners,...  ..., hybrid architectures, and third-party providers to incorporate continuity... 
    Risk
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Raleigh, NC
    4 days ago
  • $135.6k - $203.4k

    Position Overview To plan and manage highly complex engineering projects for PLXS-ENG customers...  ..., including scope, schedule, budget, risks, deliverables, and any changes to the...  ...with manufacturing, supply chain, and third‑party suppliers to ensure Plexus’ designs are... 
    Senior
    Risk

    Plexus Corp.

    Raleigh, NC
    11 hours ago
  • $77k - $214k

     ...Industry/Sector Asset and Wealth Management Specialism Industry Tax Practice Management...  ...of goods and services between related parties, as well as providing advice on tax...  ...requirements, management of operational tax risks, and tax implications of investing in... 
    Senior
    Risk
    H1b
    Local area
    Overseas

    PwC

    Raleigh, NC
    5 days ago
  •  ...and skilled Techno-Functional HCM Senior Manager to join our HRIS team. This role will...  ...team member growth. Ensure that issues and risks are documented and discussed with...  ...Excellent understanding of interfaces with third‑party platforms/vendors. Experience understanding... 
    Senior
    Risk
    Work at office
    Flexible hours

    IRB USA Inspire Resources

    Raleigh, NC
    2 days ago
  • $124k - $335k

     ...Industry/Sector Asset and Wealth Management Specialism Industry Tax Practice Management...  ...of goods and services between related parties, as well as providing advice on tax...  ...requirements, management of operational tax risks, and tax implications of investing in... 
    Senior
    Risk
    H1b
    Local area
    Overseas

    PwC

    Raleigh, NC
    5 days ago
  •  ...presents a wide range of risks to the solutions...  ...Lenovo developed and 3rd party, using industry-standard...  ..., developers, project managers, and testers -...  ...security of Lenovo- and third party-developed software...  ...related field; or relevant cybersecurity experience of 5+ years... 
    Senior
    Risk
    Local area
    Home office

    Lenovo

    Raleigh, NC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Manager of Cybersecurity, Third Party Risk. Be the first to apply!