- Company Name
- International Air Transport Association (IATA)
- Job Title
- Information Security Supply Chain, Governance and Compliance Manager
- Job Description
-
**Job title:** Information Security Supply Chain, Governance and Compliance Manager
**Role Summary:**
Lead the design, implementation, and oversight of IATA’s supply chain security program. Ensure all third‑party vendors meet the organization’s information security standards and regulatory requirements. Coordinate risk assessments, audits, and remedial actions across global suppliers, and provide executive reporting on supply chain security posture.
**Expectations:**
- Minimum 7 years in cybersecurity or information security, with at least 3 years focused on third‑party risk, supply chain security, or security governance.
- Proven experience managing global vendor assessments, audits, and corrective action plans.
- Comprehensive knowledge of ISO 27001, NIST 800‑161, NIST CSF, SOC 2, GDPR, and related cybersecurity frameworks.
- Strong communication, stakeholder management, and negotiation skills.
- English proficiency required; additional languages an advantage.
- Professional certifications (CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CISA, or equivalent) are preferred.
- Ability to travel up to 10 % of the time.
**Key Responsibilities:**
- Establish and maintain the organization’s supply chain security program aligned with risk posture and business objectives.
- Develop and enforce internal processes, policies, and supplier security requirements in collaboration with Legal, Procurement, Engineering, and Technology.
- Conduct comprehensive security assessments for RFPs, RFQs, RFIs, and software procurement.
- Maintain a register of critical suppliers, perform periodic reviews, audits, and manage risk scoring.
- Manage vendor risk platform: configure, analyze data, and produce dashboards and executive summaries.
- Support due diligence, contractual security clauses, incident response plans, and investigations of third‑party incidents.
- Drive continuous process improvement and automation for supplier risk management.
- Stay abreast of emerging threats, technologies, and regulatory changes affecting supply chain cybersecurity.
- Document minutes, procedures, enhancement requests, and standard operating procedures.
**Required Skills:**
- Vendor risk assessment and due diligence expertise.
- Knowledge of security assurance practices, audit methodologies, and corrective action management.
- Familiarity with ISO 27001, NIST 800‑161, NIST CSF, SOC 2, GDPR, and related frameworks.
- Strong presentation, communication, and stakeholder management skills.
- Ability to analyse complex security data and translate findings for non‑technical audiences.
**Required Education & Certifications:**
- Bachelor’s degree in Information Security, Computer Science, Business Administration, or related field.
- Professional certifications: CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CISA, or equivalent preferred.