×
Register Here to Apply for Jobs or Post Jobs. X

Third-Party Security Manager

Job in New York, New York County, New York, 10261, USA
Listing for: Guild Mortgage
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 94882 - 136097 USD Yearly USD 94882.00 136097.00 YEAR
Job Description & How to Apply Below
Location: New York

Guild Mortgage Company
, closing loans and opening doors since 1960. As a mortgage banking firm we are dedicated to serving the home owner/buyer. Our goal is to provide affordable home financing for our customers, utilizing the best terms available while providing a level of professionalism and service unsurpassed in the lending industry.

Position Summary

The Third-Party Security Manager is responsible for leading and maturing the organization's Third-Party Risk Management (TPRM) program. This role oversees the identification, assessment, monitoring, and mitigation of risks associated with vendors, suppliers, service providers, business partners, and other third parties. The position works closely with Information Security, Legal, Compliance, Procurement, Privacy, Enterprise Risk Management, and business stakeholders to ensure third-party relationships align with organizational risk tolerance, regulatory requirements, and security standards.

The Third-Party Security Manager possesses strong cybersecurity, risk management, and vendor governance experience with the ability to communicate risk effectively to both technical and executive audiences.

Compensation

This role is an exempt position with a Targeted Salary Range of $94,882 to $136,097 annually.

Compensation at Guild is influenced by a wide array of factors including but not limited to local and federal minimum wage requirements, education, level of experience, and applicant's geographical location.

Essential Functions
  • Develop, maintain, and continuously improve the Third-Party Risk Management (TPRM) framework, policies, standards, and procedures.
  • Establish risk-based processes for onboarding, reviewing, monitoring, and offboarding third parties.
  • Define vendor risk assessment methodologies and risk scoring criteria.
  • Ensure alignment with regulatory requirements and industry frameworks including NIST, SOC 2, ISO 27001, FFIEC, GLBA, PCI-DSS, and applicable privacy regulations.
  • Conduct security, privacy, operational, compliance, and business continuity risk assessments for new and existing vendors.
  • Review vendor security documentation including: SOC 1 and SOC 2 reports, ISO certifications, Penetration test reports, Vulnerability management reports, Security questionnaires, Business continuity and disaster recovery plans,
  • Identify control gaps and work with vendors and stakeholders on remediation plans.
  • Evaluate fourth-party dependencies and concentration risks.
  • Maintain an inventory of third-party relationships and associated risk ratings.
  • Develop continuous monitoring processes for critical and high-risk vendors.
  • Monitor external security ratings, threat intelligence, breach activity, financial condition, and compliance status of vendors.
  • Track remediation activities and ensure timely closure of identified risks.
  • Facilitate periodic vendor reviews and risk re-assessments.
  • Partner with Procurement, Legal, Privacy, Compliance, Business Owners, and Information Security teams during vendor selection and contract negotiations.
  • Provide risk guidance to business leaders regarding vendor onboarding and ongoing risk management decisions.
  • Present vendor risk findings and recommendations to leadership committees, risk committees, and executive management.
  • Support internal and external audits related to vendor management controls.
  • Collaborate with Legal and Procurement to establish and maintain security and privacy contractual requirements.
  • Review and recommend contract language related to:
    Information security controls, Data protection requirements, Breach notification obligations, Audit rights, Business continuity requirements, Regulatory compliance obligations.
  • Ensure vendor agreements include appropriate security, privacy, and reporting requirements.
  • Develop and maintain TPRM dashboards, KPIs, and executive reporting.
  • Track vendor assessment volumes, remediation status, risk trends, and program maturity metrics.
  • Provide regular reporting to Information Security leadership, Enterprise Risk Management, and audit committees.
  • Support risk quantification and business impact analysis efforts.
Qualifications
  • Bachelors Degree directly related to the position or equivalent, preferred.
  • Minimum five years' experience.
  • Minimum three years supervisory or leadership experience
  • Excellent verbal and written communication skills required.
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment required.
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary