Overview
CTG is seeking an experienced Vendor Security Manager to lead and enhance our client's third-party risk management program. This role is responsible for evaluating vendor cybersecurity risks, overseeing security assessments, ensuring compliance with industry standards, and partnering with internal stakeholders to strengthen the organization's overall security posture.
The ideal candidate brings expertise in cybersecurity, vendor risk management, compliance frameworks, and IT controls, along with strong leadership and communication skills.
Location: Washington, DC
Duration: 4 months
Primary Responsibilities
- Lead the organization's third-party risk management and vendor security program.
- Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory requirements.
- Guide and mentor team members responsible for vendor risk assessments and related security activities.
- Collaborate with business units, vendors, and security stakeholders to remediate identified control gaps and mitigate risk.
- Evaluate third-party security risks and provide recommendations for risk acceptance, mitigation, or remediation.
- Maintain security documentation, including risk assessments, policies, standards, metrics, and compliance records.
- Interpret cybersecurity data to identify potential security, compliance, and operational risks.
- Develop executive-level dashboards and actionable metrics to communicate vendor risk posture.
- Maintain internal procedures, documentation, and program governance materials.
- Respond promptly to vendor security inquiries, compliance requests, and audit activities.
- Support team development through coaching, training, and performance management.
Required Skills
- Strong knowledge of third-party risk management and vendor security best practices.
- Solid understanding of cybersecurity concepts, security architecture, networks, and IT infrastructure.
- Experience evaluating IT controls and conducting security risk assessments.
- Familiarity with industry security frameworks including:
- ISO 27001
- NIST Cybersecurity Framework (CSF)
- NIST 800-171
- Knowledge of vulnerability management, enterprise risk management, AI-related security considerations, and governance practices.
- Excellent analytical, organizational, and documentation skills.
- Strong verbal and written communication skills with the ability to communicate effectively across technical teams, business leaders, and executive management.
- Exceptional attention to detail and ability to manage multiple priorities simultaneously.
Required Experience
- 5–7 years of experience in cybersecurity, information security, information risk management, third-party risk management, or IT internal controls.
- Experience leading or supporting vendor security assessment programs.
- Demonstrated success evaluating security controls and recommending effective risk mitigation strategies.
- Experience producing compliance documentation, metrics, executive reporting, and audit support materials.
- Prior leadership or team management experience is preferred.
Education
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Business, or a related discipline preferred.
- Industry certifications such as CISSP, CISM, CRISC, CISA, or Security+ are highly desirable.
Excellent verbal and written English communication skills and the ability to interact professionally with a diverse group are required.
CTG does not accept unsolicited resumes from headhunters, recruitment agencies, or fee based recruitment services for this role.
To Apply:
To be considered, please apply directly to this requisition using the link provided. Kindly forward this to any other interested parties. Thank you!
The expected base salary for this position ranges from $58.00 to $72.00/hour. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, market factors, and where applicable, licensure or certifications obtained. In addition to salary, a competitive benefit package is also offered.