J
Supplier Cybersecurity Assessor - Vice President
Job Description
In this role, you will assess supplier cybersecurity posture and cloud-hosted environments to support supplier risk decisions within Supplier Assurance Services.
Responsibilities
- Perform cybersecurity and technology control assessments for third-party supplier environments, including cloud-hosted services
- Review supplier security architectures, controls, processes, and supporting evidence
- Partner with internal and external stakeholders to evaluate control effectiveness and identify risk exposures
- Assess supplier alignment to cybersecurity industry standards and best practices
- Document assessment findings, including risk impacts and remediation recommendations
- Convert technical observations into clear business risk outcomes and recommendations
- Monitor emerging cyber threats and industry developments to improve assessment quality
- Drive continuous improvement across assessment methodologies, standards, and reporting
- Use approved AI-enabled tools to strengthen assessment preparation, documentation, and analysis, with appropriate oversight
- Support governance, escalation, and reporting activities related to supplier cybersecurity risks
Requirements
- Minimum 7 years of experience in cybersecurity, technology risk, technology controls, technology audit, cloud security, supplier risk management, or related disciplines in a large enterprise environment
- Strong expertise in one or more cybersecurity domains, such as:
- Cloud security
- Application security
- Infrastructure security
- Identity and access management
- Cyber resiliency
- Incident management
- Data protection
- Strong understanding of security frameworks including ISO 27001, ISO 27002, NIST Cybersecurity Framework, or equivalent
- Ability to evaluate technical controls and the evidence needed for risk-based conclusions
- Experience challenging assumptions, influencing stakeholders, and driving risk-based decisions
- Excellent written and verbal communication skills, including presenting technical topics to senior stakeholders
- Strong analytical and problem-solving skills with sound judgment and attention to detail
- Ability to manage multiple priorities in a fast-paced, highly regulated environment
- Experience using approved AI-enabled productivity tools while maintaining accountability for accuracy, validation, and risk outcomes
- Relevant certification: CISSP, CISA, CISM, CCSP, or CRISC
Preferred Qualifications
- Experience assessing public cloud environments including AWS, Microsoft Azure, or Google Cloud Platform
- Cloud security or cloud architecture certifications
- Experience working in financial services or another highly regulated industry
Technology & Standards
- ISO 27001, ISO 27002
- NIST Cybersecurity Framework
- AWS, Microsoft Azure, Google Cloud Platform
Team Overview
- Corporate Functions professionals cover areas from finance and risk to human resources and marketing
- Corporate teams help set up businesses, clients, customers, and employees for success
- Global Supplier Services (GSS) manages the source-to-pay cycle, including supplier engagement, contract negotiation, risk assessments, and customer experience evaluation
- Global teams support sourcing, third-party oversight, procurement and payment operations, supplier relationship management, and customer experience
Location: Columbus, OH (onsite)