Director, IT Security Risk
Job in
Joliet, Will County, Illinois, 60432, USA
Listed on 2026-09-25
Listing for:
R1-Rc
Full Time
position Listed on 2026-09-25
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Reporting to the Deputy CISO, you will lead a US- and India-based team and own key programs spanning third-party cyber risk, customer cybersecurity inquiries and assessments, risk exceptions, and the cyber risk register.
This is a hands-on leadership opportunity to mature and automate critical cyber risk processes in a dynamic, global healthcare organization. You will partner with customers, business leaders, Procurement, Compliance, IT, Product Development, and Security teams to address risk, support business needs, and strengthen the organization’s overall security posture.
Responsibilities:
· Develop and execute the strategy and operating program for assessing, monitoring, and mitigating cybersecurity risk from third parties and suppliers.
· Lead, mentor, and develop a US- and India-based team, including approximately two to three direct reports and a broader team of approximately five employees.
· Oversee responses to customer cybersecurity questionnaires, customer cyber risk assessments, risk-exception processing, and maintenance of the cyber risk register.
· Build and mature scalable governance and third-party risk capabilities, including clear procedures, documentation, controls, reporting, and stakeholder accountability.
· Continuously review and optimize processes for efficiency and effectiveness in a changing threat environment, leveraging automation wherever appropriate.
· Partner with customers and internal relationship leaders to respond to cybersecurity inquiries and support time-sensitive business needs.
· Collaborate with IT, Product Development, Procurement, Compliance, business leaders, and other Security teams to reduce risk and address customer, contractual, regulatory, and operational requirements.
· Ensure alignment with applicable regulatory requirements, industry standards, company policies, and cybersecurity best practices.
· Develop and maintain program procedures, standards, and supporting documentation.
· Define and communicate program performance, risk trends, priorities, and recommendations to senior management and other stakeholders.
· Stay current on industry trends, emerging threats, and evolving cybersecurity governance and third-party risk practices.
· Foster a culture of security awareness, accountability, collaboration, and continuous improvement.
· Manage relationships with external partners, including security vendors and consultants.
Required Skills:
· Bachelor’s degree or an equivalent combination of education and relevant experience.
· 10+ years of cybersecurity, technology risk, governance, risk and compliance, or related experience, including at least five years in a people-management role.
· Demonstrated experience leading cybersecurity governance, risk, and compliance programs, with significant responsibility for third-party cyber risk management.
· Experience building a new cyber GRC or third-party risk capability from the ground up, or materially rebuilding and maturing an existing program.
· Experience managing customer cybersecurity questionnaires, risk assessments, exceptions, and risk-register processes.
· Experience leading and developing teams across geographies, ideally including US- and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×