Service Manager – Supplier Security Due Diligence & Monitoring Service
Listed on 2026-07-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job DescriptionThe Supplier Security Due Diligence & Monitoring Service operates at the intersection of Cybersecurity, Legal, Procurement, Supplier Management, and Enterprise Risk Management. The team is responsible for helping the enterprise navigate information security requirements within supplier contracts by providing first‑line support during contract negotiations and redline reviews. The Service Manager leads the specialized service responsible for translating supplier risk assessments into practical contractual security positions.
The team advises stakeholders on acceptable contractual outcomes, applies approved fallback language, documents security control exceptions, and ensures non‑standard contractual positions are reviewed through appropriate governance channels. This service plays a critical role in balancing supplier risk management with business enablement while maintaining alignment with enterprise risk expectations.
- Strong risk leader with the ability to distinguish between acceptable contractual deviations, temporary accommodations, material control weaknesses, and risks requiring formal escalation or acceptance.
- Proven operational leader capable of building structure, driving consistency, and managing a high‑demands service with multiple stakeholders and competing priorities.
- Brings strong understanding of how information security requirements translate into contractual obligations and can evaluate legal language through a practical risk lens.
- Highly disciplined in governance, documentation, exception management, and maintaining defensible audit trails for risk decisions.
- Demonstrated ability to influence legal, procurement, business, security, and supplier stakeholders without direct authority.
- Pragmatic and commercially aware, balancing risk management objectives with business outcomes and supplier realities.
- Service‑oriented leader committed to responsiveness, consistency, stakeholder experience, and operational excellence.
- Consistent application of enterprise risk tolerances and contractual security standards.
- Achievement of service‑level commitments and stakeholder satisfaction objectives.
- Effective documentation, governance, and escalation of security control exceptions and contractual deviations.
- Reduction in unmanaged contractual security risk across supplier agreements.
- Operational maturity demonstrated through scalable processes, metrics, reporting, and continuous improvement.
- Development of a high‑performing team capable of delivering consistent, risk‑informed contracting outcomes.
- Lead the Supplier Security Due Diligence & Monitoring Service and oversee day‑to‑day service delivery.
- Manage and develop a team responsible for supplier security contracting support and risk‑based decision making.
- Review and interpret supplier security assessment outcomes and monitoring results to guide contractual negotiations.
- Provide guidance on acceptable contractual security positions, fallback language, compensating controls, and alternative risk mitigation approaches.
- Ensure consistent application of enterprise security requirements across supplier agreements.
- Oversee documentation and tracking of contractual exceptions, deviations, and risk accommodations.
- Escalate contractual positions that exceed established risk tolerances through appropriate governance and risk acceptance processes.
- Partner closely with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier issues.
- Establish and maintain operational metrics, service‑level objectives, reporting, and quality management practices.
- Lead continuous improvement efforts designed to improve scalability, consistency,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).