
Vendor Risk Consultant
- New York City, NY
- $120,000-150,000 per year
- Permanent
- Full-time
- Advise Stakeholders: Serve as a trusted advisor to both customers and their vendors, translating technical risk findings into clear business impacts and risk management actions.
- Apply Threat Intelligence: Leverage SecurityScorecard's proprietary findings and all-source threat intelligence to assess emerging risks, advise vendors on impacts, and guide remediation.
- Build and Maintain Relationships: Foster trust with both customers and vendors as you help each understand risks, ensure ongoing compliance with requirements, and prevent incidents.
- Enhance Customer Risk Programs: Evaluate the maturity of vendor risk management programs and recommend improvements to strengthen governance and operational processes.
- Monitor & Elevate Vendor Security: Track and report on vendor risk profiles, proactively identifying trends, emerging threats, and opportunities for program improvement.
- Manage Multiple Engagements: Orchestrate concurrent client programs, ensuring consistent delivery excellence, measurable results, and alignment with regulatory and industry standards.
- Communications Skills: Outstanding ability to explain complex cybersecurity and vendor risk concepts to a range of technical and non-technical audiences, in both written and verbal form.
- Cybersecurity Expertise: Strong comprehension and ability to apply cybersecurity concepts, frameworks, technologies, controls, threat knowledge, and best practices to vendor risk.
- Analytical Skills: Proficiency in common scripting languages (Python preferred) and/or Microsoft Excel (or equivalent) to analyze complex data, build trends, and spot patterns.
- Client & Program Management: Demonstrated success managing multiple external clients and projects simultaneously, prioritizing competing demands, and meeting deadlines.
- Solo and Team Excellence: Ability to thrive in fast-paced independent and collaborative settings.
- Desired Certifications (One or More Completed): CRISC, CISSP, CISM, CISA, GSTRT, GCCC, GSLC, or GSNA. CRVPM, CTPRP, ISO 27001 Lead Auditor or technical certs are also a plus.
- Languages: English (fluent). Other regional languages are a plus.
- Other Desired Experience: Experience conducting cybersecurity audits, vendor risk assessments or broader vendor risk management.