Senior Manager Third-Party Cybersecurity Risk
Senior Manager Third-Party Cybersecurity Risk

Senior Manager Third-Party Cybersecurity Risk

Full-Time 100000 - 120000 ÂŁ / year (est.) No home office possible
Go Premium
CFA Institute

At a Glance

  • Tasks: Lead a top-notch cybersecurity risk program and protect our organisation from vendor risks.
  • Company: Join CFA Institute, a global leader in investment excellence and ethics.
  • Benefits: Enjoy competitive salary, generous leave, flexible work options, and comprehensive health coverage.
  • Why this job: Make a real impact by shaping strategies that enhance supplier security.
  • Qualifications: 5-8 years in cybersecurity or risk management with strong stakeholder communication skills.
  • Other info: Be part of a culture that values authenticity, courage, and growth.

The predicted salary is between 100000 - 120000 ÂŁ per year.

Overview

Help us safeguard CFA Institute by building and leading a best-in-class third-party cybersecurity risk program. In this senior role, you’ll identify, assess, and reduce risks across our vendor ecosystem—partnering closely with procurement, legal, security, and business teams to embed strong controls into how we select, onboard, and manage suppliers. If you thrive at the intersection of risk, security, and stakeholder influence, we’d love to hear from you.

Please note: CFA Institute does not provide work authorization or visa sponsorship for this position (including student or temporary worker visas).

What You’ll Do

  • Design, implement, and continuously mature the third-party cybersecurity risk management (TPRM) program across the full vendor lifecycle.
  • Lead due diligence and risk assessments; establish risk ratings, KRIs, and clear escalation protocols.
  • Integrate security requirements into sourcing, contracting, and onboarding in partnership with procurement and legal.
  • Recommend, track, and close remediation actions; stand up continuous monitoring for critical suppliers.
  • Build and maintain dashboards/metrics to communicate exposure and drive decision-making with leadership.
  • Align the program with relevant regulations and frameworks (e.g., GDPR, CCPA) and certifications/standards (e.g., NIST CSF, ISO 27001, SOC 2); support internal and external audits.
  • Serve as the primary point of contact for third-party cyber risk; educate stakeholders and champion best practices across the enterprise.

What You’ll Bring

Minimum Qualifications

  • Bachelor’s degree in cybersecurity, information systems, risk management, or a related field—or equivalent experience.
  • 5–8 years of cybersecurity or risk management experience with direct ownership of third-party/vendor risk.
  • Strong working knowledge of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and risk assessment methodologies.
  • Familiarity with compliance and audit requirements (e.g., SOC 2, HIPAA, PCI DSS).
  • Proven ability to analyze complex vendor ecosystems and clearly communicate risk in business terms.
  • Excellent stakeholder management, influence, and communication skills.
  • Analytical, detail-oriented, and adept at balancing risk with business objectives in a dynamic environment.

Preferred Qualifications

  • Professional certifications such as CISM, CRISC, CTPRP (or equivalent).
  • Experience establishing KRIs, dashboards, and continuous monitoring for supplier risk.
  • Demonstrated success partnering with procurement, legal, and security to embed controls in enterprise processes.
  • Audit support experience for vendor risk programs and an ongoing commitment to professional development.

Why Join Us

  • Lead a high-impact program that protects our mission and members worldwide.
  • Collaborate with experienced security, technology, and business leaders.
  • Work in a culture that values authenticity, courage, accountability, and a growth mindset.
  • Opportunity to shape strategies and practices that elevate supplier security across the organization.

At CFA Institute, we are committed to transparency and equity in our hiring process. In compliance with wage transparency laws in many of the jurisdictions in which we recruit, we provide the following information regarding compensation for this position:

Expected salary range: $135,000 – $155,000

Other benefits include eligibility for annual incentives, 12% retirement employer contribution, and competitive medical benefits.

All salary ranges are subject to adjustment based on experience, education, and other factors relevant to the position. CFA Institute is an equal opportunity employer and encourages applications from all qualified individuals.

#LI-ML1

About CFA Institute

CFA Institute are the global leader in investment excellence and ethics. With nearly 200,000 charterholders across 160 markets, we drive professional growth, ethical behavior, and better markets. We care about our employees’ well-being, offering industry-leading benefits like:

  • Comprehensive health coverage for you and your family
  • Generous leave and time off
  • Competitive retirement plans
  • Flexible work options
  • Wellness, education, and support programs

If you feel this opportunity could be the next step in your career, we encourage you to click “Apply” and complete our three-minute application.

Be part of a team committed to putting investors first and growing economies. Follow us @CFAInstitute on LinkedIn and X.

Important Message: Your application must clearly demonstrate how you meet the requirements as CFA Institute cannot make assumptions about your education, experience, or location. We thank all those who apply. Only those selected for further consideration will be contacted.

We are an Equal Opportunity Employer. CFA Institute prohibits both discrimination and harassment with regard to all identifying characteristics: any individual employee, group of employees, or prospective employee on the basis of race, color, national origin, citizenship or immigration status, religion, creed or belief, age, marital or partnership status, marital or family status, care giver status, pregnancy and maternity, sexual and other reproductive health decisions, physical abilities/qualities, disability, sexual orientation, gender, gender identity or expression, predisposing genetic characteristic, military or veteran status, status as a victim or witness of domestic violence or sex offense or stalking, unemployment status, infectious disease carrier status, migrant worker status, educational background, socio-economic status, geographic location and culture or any other basis protected by applicable law. This policy impacts all aspects of employment, including but not limited to, recruitment, hiring, compensation, training, development, promotion, demotion, layoff, recall, furlough, transfer, leave of absence, and dismissal. This is a global policy that applies to all CFA Institute employees, regardless of location.

If, due to a disability or current medical condition, you need an accommodation or assistance to complete a job application, you can request one at any stage of the recruitment process. Please send an email to humanresources@cfainstitute.org noting the accommodations or assistance you are requesting. Please do not include any medical or health information in this email. We will review your request and contact you to discuss the possible options and arrangements. We will try our best to provide you with an accommodation or assistance that meets your needs and respects your preferences.

Our application is not compatible with Internet Explorer (IE). We recommend using Chrome.

#J-18808-Ljbffr

Senior Manager Third-Party Cybersecurity Risk employer: CFA Institute

CFA Institute is an exceptional employer that prioritises the well-being and professional growth of its employees. With a strong commitment to transparency, equity, and a culture that values authenticity and accountability, you will have the opportunity to lead impactful cybersecurity initiatives while collaborating with experienced professionals. Enjoy industry-leading benefits, flexible work options, and a supportive environment that fosters continuous learning and development.
CFA Institute

Contact Detail:

CFA Institute Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Manager Third-Party Cybersecurity Risk

✨Tip Number 1

Network like a pro! Reach out to your connections in the cybersecurity field and let them know you're on the hunt for a Senior Manager role. You never know who might have the inside scoop on openings or can put in a good word for you.

✨Tip Number 2

Prepare for those interviews by brushing up on your knowledge of cybersecurity frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've successfully managed third-party risks in the past—real-life examples will make you stand out!

✨Tip Number 3

Show off your analytical skills! Create a portfolio that highlights your experience with risk assessments, dashboards, and continuous monitoring. This will not only impress interviewers but also demonstrate your proactive approach to managing vendor risks.

✨Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining CFA Institute and contributing to our mission.

We think you need these skills to ace Senior Manager Third-Party Cybersecurity Risk

Cybersecurity Risk Management
Vendor Risk Assessment
Stakeholder Management
Communication Skills
Analytical Skills
Knowledge of Cybersecurity Frameworks (e.g., NIST CSF, ISO 27001)
Compliance and Audit Requirements (e.g., SOC 2, HIPAA, PCI DSS)
Dashboard Creation and Metrics Tracking
Risk Rating Establishment
Continuous Monitoring for Supplier Risk
Collaboration with Procurement and Legal
Problem-Solving Skills
Professional Certifications (e.g., CISM, CRISC, CTPRP)
Adaptability in Dynamic Environments

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Senior Manager Third-Party Cybersecurity Risk role. Highlight your relevant experience in cybersecurity and risk management, and show how your skills align with what we’re looking for.

Showcase Your Achievements: Don’t just list your responsibilities; share specific achievements that demonstrate your impact in previous roles. Use metrics where possible to quantify your success in managing third-party risks and improving security protocols.

Be Clear and Concise: Keep your application clear and to the point. We appreciate well-structured documents that are easy to read. Avoid jargon unless it’s relevant to the role, and make sure your key points stand out.

Apply Through Our Website: We encourage you to apply directly through our website. This ensures your application is received properly and allows us to process it efficiently. Plus, it’s a great way to show your enthusiasm for joining our team!

How to prepare for a job interview at CFA Institute

✨Know Your Cybersecurity Frameworks

Make sure you brush up on your knowledge of cybersecurity frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've applied these in past roles, especially in relation to third-party risk management.

✨Showcase Your Stakeholder Management Skills

Prepare examples that highlight your ability to influence and manage stakeholders. Think about times when you successfully collaborated with procurement, legal, or security teams to embed controls in processes.

✨Be Ready for Risk Assessment Scenarios

Expect to be asked about your experience with risk assessments and due diligence. Have specific examples ready that demonstrate how you've established risk ratings and managed remediation actions in previous roles.

✨Communicate Clearly and Confidently

Practice articulating complex cybersecurity concepts in business terms. The interviewers will want to see that you can communicate risks effectively to non-technical stakeholders, so clarity is key!

Senior Manager Third-Party Cybersecurity Risk
CFA Institute
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>