Dforeferrals
Vendor Risk Manager
Westport, CT
Sponsorship not specified$53k-$800kDetected 19 days ago
OAuthLLMsCybersecurityPenetration TestingComplianceStakeholder ManagementCommunication
About the role
- The core of the DFO's culture is built around meaningful work and meaningful relationships and the family's commitment to giving back.
- The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi.
- You will synthesize risk across cybersecurity, AI, privacy, financial, and AML/CFT/sanctions domains into clear, actionable risk positions, performing structured threat modeling for high-exposure vendors.
Responsibilities
- Own the VRM program end-to-end: strategy, policy, procedure, workflow, tooling, metrics, and executive reporting for CISO/CRO/board visibility.
- Partner with Legal to translate identified risks into enforceable contractual requirements.
- Advise IT, Engineering and business teams on vendor integration architecture (SSO/SCIM, OAuth, conditional access, DLP, segmentation, BYOK, VPC peering) and maintain approved reference patterns.
- Drive automation and tooling maturity to handle high vendor volume without proportional headcount growth; produce program dashboards tracking throughput, cycle time, recertification compliance, and remediation aging.
Requirements
- Bachelor's degree in Information Security, Risk Management, Computer Science, Cybersecurity, or a related discipline.
- At least 7 years of progressive experience across vendor risk management, cybersecurity architecture, security engineering, GRC, audit, or related fields.
- 10% travel as required based on business needs.
- Experience managing the full third-party/vendor risk lifecycle, including vendor onboarding, due diligence, risk assessments, continuous monitoring, recertification, remediation tracking, and vendor exit planning, with at least 2 years owning an end-to-end TPRM program.
- Strong technical knowledge of cybersecurity frameworks, standards, and methodologies including NIST, ISO 27001/27002, OWASP, MITRE ATT&CK, Shared Assessments, threat modeling approaches (STRIDE/PASTA), and risk management practices.
- Hands-on experience evaluating enterprise security controls, cloud and integration architectures, SOC 2 Type II reports, ISO certifications, penetration testing results, data protection requirements, and third-party security risks across complex technology environments.
- Ability to communicate complex technical and risk concepts to executive stakeholders, collaborate effectively across business functions
Skills
- The ideal candidate will possess the following knowledge, skills, attributes, and values:
- Strong risk assessment and analytical skills
- Excellent communication and stakeholder management skills
Compensation
- <span data-ccp- ="normaltextrun" data-ccp- -defn="{"ObjectId":"ac0262f4-8a9e-5820-b908-2d943c5f7113|1","ClassId":1073872969," ":[201342446,"1",201342447,"5",201342448,"1",201342449,"1",469777841,"Calibri",46977
Benefits
- 100% company paid medical premiums
- Generous PTO offering
- Gym reimbursement, back up childcare services, insurance, financial, and legal services, and much more!
Company info
- 17 company paid holidays
Apply directly at Dforeferrals →Create a free account for alerts like thisView Dforeferrals immigration profile
This listing is sourced directly from Dforeferrals's careers page and normalized into a canonical job model.