A highly respected professional services organization is seeking a Client & Vendor Risk Manager to lead information security due diligence, third-party risk assessments, and client-facing security reviews.
This individual will serve as a key liaison between Information Security, Legal, Procurement, Risk Management, business stakeholders, clients, and external vendors while helping strengthen and mature enterprise risk management processes.
Lead client security due diligence and security questionnaire responses.
- Manage third-party vendor risk assessments and ongoing monitoring activities.
- Evaluate vendor security controls, certifications, and risk posture.
- Review SOC 2 reports, ISO 27001 certifications, penetration test results, privacy controls, and cloud security practices.
- Develop and improve vendor risk methodologies, onboarding processes, and monitoring programs.
- Support client audits, assessments, and regulatory reviews.
- Partner with Legal, Information Security, Procurement, and business teams to evaluate contracts and security requirements.
- Participate in client-facing discussions involving information security and risk management.
- Monitor cybersecurity, privacy, and regulatory developments.
- Develop reporting and provide risk-related recommendations to leadership.
- Mentor junior team members and contribute to overall risk maturity initiatives.
6+ years of experience in Information Security, Third-Party Risk Management, Vendor Risk Management, Compliance, Governance, Risk & Compliance (GRC), or related disciplines.
- Experience conducting vendor risk assessments for enterprise technology providers.
- Strong understanding of security frameworks and standards including:
- SOC 2
- ISO 27001
- NIST
- HIPAA
- Privacy and regulatory frameworks
- Experience reviewing security controls, risk reports, and compliance documentation.
- Ability to communicate effectively with technical and non-technical stakeholders.
- Experience presenting findings, recommendations, and risk assessments to leadership.
- Ability to work independently and lead cross-functional initiatives.
Preferred
- CISSP
- CISM
- CRISC
- CISA
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- CTPRA
Ideal Backgrounds
- Vendor Risk Manager
- Third-Party Risk Manager
- Information Security Risk Manager
- Cybersecurity Governance Manager
- GRC Manager
- Security Compliance Manager
- Information Security Analyst (Senior)
- Security Risk & Compliance Lead
- IT Risk Manager
Technology Doesn't Change the World, People Do. ®
Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more.
All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.
© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use and Privacy Notice .