As a relationship-based organization, we welcome and value a diverse workforce. We provide equal employment opportunity to all qualified persons without regard to race, creed, color, sex, including sexual orientation, gender identity and transgender status, religion, national origin, age, disability, military service, veteran status, pregnancy, AIDS/HIV or genetic information, or any other basis prohibited by law.
IT - Third Party Risk Manager I
Location
United States
Posted
16 days ago
Salary
0
Seniority
Lead
Job Description
IT - Third Party Risk Manager I
Cincinnati Financial
Role Description Our Vendor Management Office department is currently seeking a Third Party Risk Manager. Be ready to: - Conduct information security risk assessments of vendors and vendor software, based on company standards and risk appetite, leveraging demonstrated working knowledge of industry security practices. - Make information security risk recommendations on behalf of the company, within limits approved by management. - Review project documentation, system design documents, vendor security policies and other vendor security references (i.e. SOC II type 2, SIG, AUP, PCI ROC, TPRM monitoring reports, etc.) to determine the extent, type, and scope of risks of the vendor relationship. - Provide security-related recommendations and communicate the need for the changes to business, IT and other stakeholders. - Coordinate with IT architects, project teams and vendors to bring system designs into alignment with company security standards. - Follow procedures to establish company records for the risk management process. - Modify vendor risk procedures and other tools to support continuous improvement of the vendor risk management program. - Support IT management relative to vendor product ownership responsibility, product license needs, license and support renewal process. - Follow vendor governance policies and procedures that drive the behaviors of those individuals/organizations. - Inform IT and business unit stakeholders on vendor management practices. - Work with business partners and other IT service areas in the requirement gathering process. - Manage vendor relationships including negotiation, license/cost analysis, audit support and coordination, product renewals, and performance monitoring. Qualifications - Demonstrate an understanding of fundamental aspects of information security (i.e. data classification, inventories, technical/ procedural/ physical control categories). - Demonstrate an understanding of information security standards and regulations (e.g., ISO 27001/27002, NIST, FFIEC, etc.), and commonly used concepts, practices and procedures within the information security and privacy fields. - Demonstrate an understanding of the fundamentals of vendor relationship management (i.e. stakeholder management, communication, problem solving and organizational skills, relationship building). Requirements - A bachelor’s degree or technical institute training or any combination of education and experience that would provide an equivalent background. Benefits Your commitment to providing strong service, sharing best practices and creating solutions that impact lives is appreciated. To increase the well-being and satisfaction of our associates, we offer a variety of benefits and amenities. Learn more about our benefits and amenities packages. Many departments at our Headquarters in Fairfield, Ohio, offer hybrid work options, empowering associates to work from home several days a week. Depending on your role and responsibilities, hybrid options may be available. Company Description As a relationship-based organization, we welcome and value a diverse workforce. We grant equal employment opportunity to all qualified persons without regard to race; creed; color; sex, including sexual orientation; religion; national origin; age; disability; or any other basis prohibited by law.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Demand Generation Manager – Cybersecurity, AI
Rosie's PeopleYour one-stop partner for all your Leadership, HR & Business Operations challenges.
• Designing and executing a demand generation roadmap across priority sectors (e.g. financial services, fintech, regulated industries) • Planning and running multi-channel campaigns (LinkedIn, email, webinars, reports, communities) • Building and managing lead-nurture journeys for complex buying committees (CISO, risk, compliance, IT, innovation) • Collaborating with leadership to define ICPs, personas, and core messaging • Creating and repurposing cornerstone content into campaign-ready assets that support the sales cycle • Setting up lightweight marketing operations, including tracking, basic lead scoring, and funnel reporting • Experimenting with targeted, account-based motions for high-value prospects and partner ecosystems • Testing, iterating, and sharing insights across marketing, sales, and product teams to refine GTM approach
SOC Incident Response Specialist
SupportYourAppSupport-as-a-Service that helps companies scale faster by taking care of their customers’ needs.
Role Description Our team is continuously growing alongside our expanding client base, so we are looking for a SOC Incident Response Specialist who is eager to apply their technical expertise, develop in the field of security, and work with real incidents and modern tools. What you will do: - Manage security and operational incidents end-to-end, including investigation, coordination, and response; - Communicate directly with Clients and stakeholders during Data Breach incidents; - Conduct Root Cause Analysis, develop preventive measures, and prepare management reports; - Analyze Clients’ workflows and incident trends to identify risks and improve security processes; - Assess the security of software, platforms, and third-party vendors; - Review new hiring locations for compliance with data protection and security standards; - Develop incident response procedures and maintain internal security documentation and knowledge base. Qualifications - Proven experience in investigating and handling information security incidents (from 1 year); - Analytical mindset and the ability to make fast decisions to mitigate incident impact; - Strong self-organization skills and the ability to prioritize work independently; - Understanding of data privacy principles and breach notification requirements; - English proficiency at level B2 or higher. Requirements - Proficiency in OSINT methodologies for investigations; - Experience in the BPO or Customer Support industry; - Basic knowledge of security tools logic (SIEM, EDR, DLP, NGFW, VPN, VDI). Benefits - Providing services during business hours; - Opportunity to cooperate fully remotely; - Inclusive international environment; - Compensation in USD; - Rewards for referring friends; - Balance between project workload and personal time, but also – internal health policy; - Responsive leadership interested in your growth and long-lasting cooperation; - Greenhouse conditions for self-development; - A culture built on trust, with no time-tracking requirements. *The items listed in this section may vary depending on the terms of your engagement. Certain benefits and conditions typically apply to employees; independent contractors may not be eligible for all of these. The specific terms, including compensation, benefits, and work conditions, will be clearly defined in your agreement if selected.
Corporate Security Engineer
BranchWe provide cross-platform linking and attribution solutions to the world's leading digital brands.
• Own the day-to-day administration of CrowdStrike Falcon — prevention policies, detection tuning, custom IOAs, USB device control, and Real Time Response runbooks across the entire Branch endpoint fleet. • Operate and mature ThreatLocker — build and maintain application allowlisting, ringfencing, storage control, and elevation policies; reduce learning-mode exceptions over time and drive measurable hardening progress. • Administer Island Enterprise Browser — define and enforce browser-level policies for SaaS access, copy/paste, downloads, screenshot, and extension governance; align browser controls with insider risk and DLP objectives. • Drive endpoint hardening and configuration baselines for macOS and Windows. MDM (Jamf / Intune), patch SLAs, FileVault/BitLocker, and CIS-aligned benchmarks. • Maintain a defensible inventory of endpoints, agents, and coverage gaps, and drive remediation when devices fall out of compliance. • Own corporate-side incident response for endpoint, identity, email, and insider events — from initial triage through containment, eradication, recovery, and post-incident review. • Build and run Branch’s insider risk program — from defining risk indicators (data exfiltration, anomalous access, departing employee behavior) to building detections and response playbooks across endpoint, browser, and SaaS telemetry. • Operate Data Loss Prevention controls across Google Workspace (Drive, Gmail), Island Browser, and endpoint channels; investigate DLP events end-to-end, balancing user friction against data-protection outcomes. • Lead onboarding, offboarding, transitions security workflows in partnership with People Operations — enforce least-privilege access, data return at offboarding, and time-bounded monitoring of high-risk departures, ultimately skilling up our IAM team. • Triage and investigate insider risk cases with discretion, partnering with Legal, HR, and GRC on documentation, evidence handling, and outcomes; preserve chain-of-custody on every case. • Develop user-facing guidance and training that reduces accidental risk — phishing reporting, secure handling of customer data, and acceptable use of AI and SaaS tools. • Harden Google Workspace — admin role hygiene, context-aware access, OAuth third-party app governance, advanced phishing/malware protection, and audit logging into the SIEM. • Automate repetitive corporate security work using Python or Bash and orchestration platforms (e.g., Tines, Torq, XSOAR) — alert enrichment, user notifications, evidence collection, and offboarding checks. • Contribute to the corporate vulnerability management program for endpoints and SaaS — prioritization, SLA tracking, and cross-functional remediation. • Serve as a security consultant and escalation point for the broader business on secure configurations, patching, exception requests, and acceptable-use questions.
Role Description This role is for our partner. [the company]'s AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and business processes. Customers trust [the company] to safeguard their digital assets, drive operational efficiency, and reduce compliance costs. Built for the AI age, [the company] is today helping organizations safely accelerate their deployment and usage of AI. [the company] is recognized as the leader in identity security, with solutions that protect and empower the world's leading brands, Fortune 500 companies, and government institutions. [the company] is currently seeking a Sales Development Representative (SDR) to initiate sales cycles for our Enterprise Sales team. SDRs do this by: - Identifying and engaging the appropriate prospect personas across Federal Agencies - Inquiring into their IGA business and infrastructure challenges - Aligning [the company]'s value propositions to those challenges - Gaining the prospects' commitment to take a meeting with a Director of Sales to learn more Qualifications - 1+ year prospecting Enterprise SaaS - Federal agency software-procurement understanding - IGA knowledge - Phone-prospecting confidence - Salesforce required - Degree or equivalent Company Description



