Job opening
Information Technology Security Manager
Filed under Pharmaceutical Manufacturing
Full job description
IT Security Manager – Third Party Cyber Risk Management (Contract)
I'm partnering with a leading biotechnology company seeking an experienced IT Security Manager to support enterprise-wide Third-Party Cyber Risk Management (TPCRM), vendor security governance, cybersecurity audits, and regulatory compliance initiatives.
Requirements
• Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field
• 5+ years of experience in information security, third-party cyber risk management (TPCRM), or IT risk management
• Experience within Pharma, Biotech, Healthcare, or other highly regulated environments
• Strong knowledge of security and compliance frameworks including NIST, ISO 27001, GDPR, SOX, HIPAA, FISMA, and GxP
• Experience conducting vendor security assessments, supplier risk reviews, and third-party security evaluations
• Experience reviewing SOC 1/SOC 2 reports, audit findings, and security assurance documentation
• Experience using GRC platforms such as ServiceNow, Archer, MetricStream, Galvanize, Vanta, or similar tools
• Professional certifications such as CISSP, CISM, CRISC, or CISA preferred
• Experience working within global organizations and cross-functional teams
Responsibilities
• Support and enhance the organization's Third-Party Cyber Risk Management (TPCRM) program
• Develop, maintain, and improve vendor security standards, processes, and documentation
• Conduct security risk assessments and manage supplier remediation activities
• Evaluate vendor security controls, compliance evidence, and assurance reports
• Develop and maintain TPCRM metrics, KPIs, KRIs, and executive reporting
• Monitor and communicate third-party security risks across the business
• Partner with Procurement, Legal, Compliance, Privacy, Quality, and IT stakeholders to align security requirements
• Drive initiatives supporting compliance with evolving cybersecurity regulations, including NIS2
• Develop and execute cybersecurity audit programs and risk-based audit plans
• Track audit findings, remediation efforts, and continuous improvement initiatives
• Support implementation of security controls, risk management processes, and governance frameworks
• Guide business teams on security requirements, risk mitigation, and best practices
Preferred
• Experience building or improving enterprise TPCRM programs
• Strong understanding of vendor assurance frameworks and audit methodologies
• Experience establishing cybersecurity governance and audit functions
• Knowledge of emerging cybersecurity threats, regulations, and industry best practices
• Strong communication, stakeholder management, and presentation skills
• Excellent analytical, organizational, and problem-solving abilities
Location: Remote/Hybrid
Duration: 6-Month Contract
Interviews are starting soon, so if you're interested and would like to be considered, give me a call at (919) 892-9841 as soon as you're available.