CybersecurityJobs.io
← Back to all jobs

Job Description

In this role, you will assess supplier cybersecurity posture and cloud-hosted environments to support supplier risk decisions within Supplier Assurance Services.

Responsibilities

  • Perform cybersecurity and technology control assessments for third-party supplier environments, including cloud-hosted services
  • Review supplier security architectures, controls, processes, and supporting evidence
  • Partner with internal and external stakeholders to evaluate control effectiveness and identify risk exposures
  • Assess supplier alignment to cybersecurity industry standards and best practices
  • Document assessment findings, including risk impacts and remediation recommendations
  • Convert technical observations into clear business risk outcomes and recommendations
  • Monitor emerging cyber threats and industry developments to improve assessment quality
  • Drive continuous improvement across assessment methodologies, standards, and reporting
  • Use approved AI-enabled tools to strengthen assessment preparation, documentation, and analysis, with appropriate oversight
  • Support governance, escalation, and reporting activities related to supplier cybersecurity risks

Requirements

  • Minimum 7 years of experience in cybersecurity, technology risk, technology controls, technology audit, cloud security, supplier risk management, or related disciplines in a large enterprise environment
  • Strong expertise in one or more cybersecurity domains, such as:
    • Cloud security
    • Application security
    • Infrastructure security
    • Identity and access management
    • Cyber resiliency
    • Incident management
    • Data protection
  • Strong understanding of security frameworks including ISO 27001, ISO 27002, NIST Cybersecurity Framework, or equivalent
  • Ability to evaluate technical controls and the evidence needed for risk-based conclusions
  • Experience challenging assumptions, influencing stakeholders, and driving risk-based decisions
  • Excellent written and verbal communication skills, including presenting technical topics to senior stakeholders
  • Strong analytical and problem-solving skills with sound judgment and attention to detail
  • Ability to manage multiple priorities in a fast-paced, highly regulated environment
  • Experience using approved AI-enabled productivity tools while maintaining accountability for accuracy, validation, and risk outcomes
  • Relevant certification: CISSP, CISA, CISM, CCSP, or CRISC

Preferred Qualifications

  • Experience assessing public cloud environments including AWS, Microsoft Azure, or Google Cloud Platform
  • Cloud security or cloud architecture certifications
  • Experience working in financial services or another highly regulated industry

Technology & Standards

  • ISO 27001, ISO 27002
  • NIST Cybersecurity Framework
  • AWS, Microsoft Azure, Google Cloud Platform

Team Overview

  • Corporate Functions professionals cover areas from finance and risk to human resources and marketing
  • Corporate teams help set up businesses, clients, customers, and employees for success
  • Global Supplier Services (GSS) manages the source-to-pay cycle, including supplier engagement, contract negotiation, risk assessments, and customer experience evaluation
  • Global teams support sourcing, third-party oversight, procurement and payment operations, supplier relationship management, and customer experience

Location: Columbus, OH (onsite)

Similar Jobs