Dforeferrals

Vendor Risk Manager

Westport, CT

Sponsorship not specified$53k-$800kDetected 19 days ago
OAuthLLMsCybersecurityPenetration TestingComplianceStakeholder ManagementCommunication

About the role

  • The core of the DFO's culture is built around meaningful work and meaningful relationships and the family's commitment to giving back.
  • The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi.
  • You will synthesize risk across cybersecurity, AI, privacy, financial, and AML/CFT/sanctions domains into clear, actionable risk positions, performing structured threat modeling for high-exposure vendors. ​

Responsibilities

  • Own the VRM program end-to-end: strategy, policy, procedure, workflow, tooling, metrics, and executive reporting for CISO/CRO/board visibility.
  • Partner with Legal to translate identified risks into enforceable contractual requirements.
  • Advise IT, Engineering and business teams on vendor integration architecture (SSO/SCIM, OAuth, conditional access, DLP, segmentation, BYOK, VPC peering) and maintain approved reference patterns.
  • ​ Drive automation and tooling maturity to handle high vendor volume without proportional headcount growth; produce program dashboards tracking throughput, cycle time, recertification compliance, and remediation aging.

Requirements

  • Bachelor's degree in Information Security, Risk Management, Computer Science, Cybersecurity, or a related discipline.
  • At least 7 years of progressive experience across vendor risk management, cybersecurity architecture, security engineering, GRC, audit, or related fields.
  • 10% travel as required based on business needs.
  • Experience managing the full third-party/vendor risk lifecycle, including vendor onboarding, due diligence, risk assessments, continuous monitoring, recertification, remediation tracking, and vendor exit planning, with at least 2 years owning an end-to-end TPRM program.
  • Strong technical knowledge of cybersecurity frameworks, standards, and methodologies including NIST, ISO 27001/27002, OWASP, MITRE ATT&CK, Shared Assessments, threat modeling approaches (STRIDE/PASTA), and risk management practices.
  • Hands-on experience evaluating enterprise security controls, cloud and integration architectures, SOC 2 Type II reports, ISO certifications, penetration testing results, data protection requirements, and third-party security risks across complex technology environments.
  • Ability to communicate complex technical and risk concepts to executive stakeholders, collaborate effectively across business functions

Skills

  • ​ ​ The ideal candidate will possess the following knowledge, skills, attributes, and values:
  • Strong risk assessment and analytical skills
  • Excellent communication and stakeholder management skills

Compensation

  • <span data-ccp- ="normaltextrun" data-ccp- -defn="{"ObjectId":"ac0262f4-8a9e-5820-b908-2d943c5f7113|1","ClassId":1073872969," ":[201342446,"1",201342447,"5",201342448,"1",201342449,"1",469777841,"Calibri",46977

Benefits

  • 100% company paid medical premiums
  • Generous PTO offering
  • Gym reimbursement, back up childcare services, insurance, financial, and legal services, and much more!

Company info

  • 17 company paid holidays

This listing is sourced directly from Dforeferrals's careers page and normalized into a canonical job model.