drjobs Senior Manager Third Party Risk Cybersecurity

Senior Manager Third Party Risk Cybersecurity

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

USA

Monthly Salary drjobs

$ 120000 - 222600

Vacancy

1 Vacancy

Job Description

Application Deadline:

06/26/2025

Address:

VIRTUAL43 HomeRes TX

Job Family Group:

Technology

As a Senior Manager of ThirdParty Risk Assessment at BMO you wont just manage assessments youll shape how we secure hundreds of critical thirdparty relationships that power one of North Americas leading financial institutions. This is more than a people management role its a chance to build coach and elevate a team of experts while leading frontline efforts in cyber defense.

What Makes This Role Stand Out:

  • 100 Remote Flexibility: Work remotely while leading a leading team of experienced Third Party Cyber Assessors most of whom are tenured and highly skilled in Third Party Risk Assessments
  • Strong Peer Collaboration: Youll partner closely with another senior manager and report directly to a Director who leads a dynamic 20person assessment team. Youll never lead in isolation youll be part of a collaborative leadership structure.
  • High Impact & Visibility: Lead quality assurance across hundreds of assessments annually coach Third Party Risk Assessors engage with executive stakeholders and help drive resolution of complex risk findings. Youll be seen as a goto expert and decisionmaker.
  • MissionDriven Culture: Our team thrives in a fastmoving highstakes environment where we balance business agility with security regulatory expectations and internal audit. This is cyber with realworld impact where negotiation leadership and strategy matter just as much as technical acumen.
  • Growth & Thought Leadership: Youll be expected to challenge the status quo bring fresh ideas to evolve our assessment model and stay ahead of emerging threats while mentoring others to do the same.

What You Bring to the Table:

  • 510 years of Cyber ThirdParty Risk assessment experience
  • 5 years in peopleleadership (Managerial) role(s)
  • CISSP certified
  • Deep knowledge of NIST ISO or CIS frameworks
  • Handson experience with major Cloud platforms such as AWS Azure or Google Cloud with a strong understanding of cloud security principles architectures and best practices.
  • Expertlevel capability in interviewing auditing documentation and risk reporting
  • Strong coaching instincts and the ability to raise the bar on technical quality
  • A calm assertive presence with proven skills in conflict resolution negotiation and influence
  • Bonus points for ethical hacking certifications (OSCP GPEN CEPT)

Youll Excel Here If You

  • Love being the calm in the chaos stepping into crisis calls leading tough conversations and helping teams find clarity
  • Get energy from teaching others and raising the standard of the whole team
  • Arent afraid to push back when needed while still keeping people on your side
  • Are a fast learner with the curiosity and technical aptitude to pick up new concepts quickly

Key Responsibilities:

  • You are a Quality Assurance Czar. You will be responsible for ensuring all assessments have consistent strong quality and meet the expectations of our stakeholders.
  • Train and coach: Work closely with your team of Assessors and provide them feedback on their assessments this can include both technical and soft skills like negotiation and communication. Being comfortable challenging others and critiquing the work of others is a musthave.
  • Enjoy sharing knowledge. This could include coaching people outside of your team e.g. explaining to the business a technical security control so that they can better understand the risk.
  • Findings management. Review evidence and negotiate the closure of findings with internal teams and third parties.
  • Be a thought leader. Bring new ideas to the team and challenge the status quo. The security landscape is always changing we need to ensure that our assessments are aligned with the latest threats.

Join us if youre ready to lead with purpose grow a bestinclass cyber risk team and help secure the future of banking

Additional Information:

Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision objectives and KPIs. Leads the development of information security strategy by understanding business processes policies information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need are approved by all relevant stakeholders and meets essential information security standards. Provides thought leadership promotes new processes and methodologies and emerging technologies with the flexibility to align to the unique requirements of the business/group and deliverables.

  • Fosters a culture aligned to BMO purpose values and strategy and role models BMO values and behaviours in all that they do.
  • Ensures alignment between values and behaviour that fosters diversity and inclusion.
  • Regularly connects work to BMOs purpose sets inspirational goals defines clear expected outcomes and ensures clear accountability for follow through.
  • Builds interdependent teams that collaborate across functional and operating groups to create the highest value for all stakeholders.
  • Attracts retains and enables the career development of top talent.
  • Improves team performance recognizes and rewards performance coaches employees supports their development and manages poor performance.
  • Provides strategic input into business decisions as a trusted advisor.
  • Understands and can explain to others the core processes risks and mitigation techniques for designated areas.
  • Acts as a subject matter expert on relevant regulations and policies.
  • Identifies and recommends opportunities to create/contribute to the tactical and strategic vision of the organization.
  • Supports the of strategic initiatives in collaboration with internal and external stakeholders.
  • Acts as the prime subject matter expert for internal/external stakeholders.
  • Breaks down strategic problems and analyses data and information to provide insights and recommendations.
  • Presents data and information to all levels within IT and to business units.
  • Leads/oversees the management of vendor relationships and provides guidelines for ; ensures that all agreements are met as per requirements.
  • Stays abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
  • Analyzes trends and stays current with industry events to proactively prevent information security issues.
  • Understands the strategy plans activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
  • Provides advice counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles frameworks programs approaches trends legislation and regulatory requirements including interpretation of policy and identification and management of risk.
  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
  • Tracks metrics and milestones providing recommendations for resolution and escalating as appropriate when issues arise.
  • Facilitates discussions and follows a disciplined approach to plan elicit analyse document communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe challenge and understand associated risks.
  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
  • Creates professional presentations and deliver them in a meaningful concise way.
  • Assesses information security impact to a projects benefits and risks when scope changes.
  • Develops and champions information security best practices including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
  • Gathers examines and interprets data and information to extract meaningful insights answer business questions and provide actionable recommendations.
  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.
  • Ensures consistent high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
  • Operates at a group/enterprisewide level and serves as a specialist resource to senior leaders and stakeholders.
  • Applies expertise and thinks creatively to address unique or ambiguous situations and to find solutions to problems that can be complex and nonroutine.
  • Implements changes in response to shifting trends.
  • Broader work or accountabilities may be assigned as needed.

    Qualifications:

  • Typically 7 years of relevant experience and a postsecondary degree in Information Security Computer Science Engineering and/or Information Systems or a related field of study or an equivalent combination of education and experience.
  • Multiple information security certifications from a wellrecognized institution (e.g. (ISC)2 ISACA SANS).Possesses an expert level of knowledge of information security processes procedures and controls.
  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF) ISO 27001 and 27002 Indepth/Expert.
  • Knowledge of business analysis project delivery practices and standards across the project lifecycle Indepth/Expert.
  • Demonstrates in depth knowledge of information security concepts methodology processes procedures and controls.
  • Understanding and problem solving ability of information security issues across the bank Indepth/Expert.
  • Understanding of information security risk and regulatory requirements Indepth/Expert.
  • Knowledge of the technical/business environment and the corporate processes and procedures Indepth/Expert.
  • Seasoned professional with a combination of education experience and industry knowledge.
  • Verbal & written communication skills Indepth / Expert.
  • Analytical and problem solving skills Indepth / Expert.
  • Influence skills Indepth / Expert.
  • Collaboration & team skills; with a focus on crossgroup collaboration Indepth / Expert.
  • Able to manage ambiguity.
  • Data driven decision making Indepth / Expert.

Salary:

$120000.00 $222600.00

Pay Type:

Salaried

The above represents BMO Financial Groups pay range and type.

Salaries will vary based on factors such as location skills experience education and qualifications for the role and may include a commission structure. Salaries for parttime roles will be prorated based on number of hours regularly worked. For commission roles the salary listed above represents BMO Financial Groups expected target for the first year in this position.

BMO Financial Groups total compensation package will vary based on the pay type of the position and may include performancebased incentives discretionary bonuses as well as other perks and rewards. BMO also offers health insurance tuition reimbursement accident and life insurance and retirement savings plans. To view more details of our benefits please visit: Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting positive change for our customers our communities and our people. By working together innovating and pushing boundaries we transform lives and businesses and power economic growth around the world.

As a member of the BMO team you are valued respected and heard and you have more ways to grow and make an impact. We strive to help you make an impact from day one for yourself and our customers. Well support you with the tools and resources you need to reach new milestones as you help our customers reach theirs. From indepth training and coaching to manager support and networkbuilding opportunities well help you gain valuable experience and broaden your skillset.

To find out more visit us at is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race religion color national origin sex (including pregnancy childbirth or related medical conditions) sexual orientation gender identity gender expression transgender status sexual stereotypes age status as a protected veteran status as an individual with a disability or any other legally protected characteristics. We also consider applicants with criminal histories consistent with applicable federal state and local law.

BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process please send an email to and let us know the nature of your request and your contact information.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO directly or indirectly will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid written and fully executed agency agreement contract for service to submit resumes.


Required Experience:

Senior Manager

Employment Type

Remote

Company Industry

Key Skills

  • Arm
  • Risk Management
  • Financial Services
  • Cybersecurity
  • COSO
  • PCI
  • Root cause Analysis
  • COBIT
  • NIST Standards
  • SOX
  • Information Security
  • RMF

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.