- Company Name
- McCain Foods
- Job Title
- Manager, Cyber Risk Management
- Job Description
-
Job title: Manager, Cyber Risk Management
Role Summary:
Lead the design, implementation, and ongoing operation of the organization’s cyber risk and Third‑Party Risk Management (TPRM) functions. Work closely with senior leadership and cross‑functional teams to embed risk awareness, define key metrics, and ensure continuous monitoring and remediation of cyber and vendor‑related risks.
Expectations:
* Report directly to the CISO and influence enterprise‑wide risk strategy.
* Drive a culture of compliance and accountability across IT, business, legal, and procurement.
* Deliver measurable risk metrics to executive leadership and risk committees.
Key Responsibilities:
- Conduct risk assessments for technology platforms, including cloud, AI, and SaaS solutions.
- Maintain and evolve the organization’s cyber risk framework (IT, AI, NIST, SWIFT).
- Govern the cyber risk register, define KRIs/KPIs, and report insights to executives.
- Empower technology teams to own risk mitigation plans.
- Lead annual maturity and audit assessments (SWIFT, NIST).
- Manage and enhance the global TPRM program, including risk assessments, control questionnaires, and vendor monitoring.
- Collaborate with procurement, governance, legal, and risk stakeholders on vendor risk integration.
- Serve as liaison with external and internal auditors for vendor security compliance.
- Establish KRI/KPI dashboards for vendor security posture and risk appetite management.
- Advise leadership on TPRM effectiveness and recommend improvements.
- Ensure contractual security language and controls are incorporated into third‑party agreements.
- Maintain continuous monitoring of third‑party cyber incidents and incidents impact on operations.
Required Skills:
- 7+ years managing Information Security risk and TPRM in medium to large organizations.
- Deep knowledge of AI risk frameworks and Gen AI assessment techniques.
- Proven ability to influence without authority, negotiate, and resolve conflicts.
- Strong communication, coaching, and stakeholder‑management skills.
- Experience with vendor risk management processes and tools.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field.
- Preferred certifications: CISSP, CISM, CRISC, CGEIT, or equivalent.
- Additional certifications in AI risk or third‑party risk management are advantageous.