Director, IT Risk Management
We are seeking a motivated and collaborative leader to develop and implement our Global Cyber & IT Risk Management strategies. This role will lead the Global 3rd Party Risk Management Team, supporting vendor risk assessments and working closely with teams to identify, assess, and address risks to critical services, information, and systems. This is a hybrid role (3 days a week in office, 2 days a week remote).
We will count on you to :
- Develop and support global cyber and IT risk management strategies aligned with business goals.
- Lead the Global 3rd Party Risk Management Team in conducting vendor risk assessments and facilitating remediation efforts.
- Collaborate to develop risk models that assess and quantify risks to critical services, information, and systems.
- Maintain current and comprehensive vendor inventories and assessments.
- Prepare reports, presentations, and dashboards for executive leadership to communicate risk posture and emerging threats.
- Continuously enhance Vendor Risk Assessment methodologies to align with evolving industry standards and best practices.
- Foster a skilled team environment to effectively perform risk assessments and maintain strong client communication.
- Partner with vendors to establish cybersecurity and resilience standards within contracts.
- Coordinate global internal audits, client assessments, and security reviews related to third-party risk.
- Participate in incident response activities involving third parties, collaborating across teams to reduce exposure.
- Engage with operational leaders to identify emerging risks and co-develop risk-reducing solutions.
- Adapt and scale risk management processes to address new and evolving threats, including those related to AI and advanced technologies.
What you need to have :
Experience in cyber and IT risk management, preferably in a global or cross-functional environment.Strong interpersonal and leadership skills with experience supporting diverse, collaborative teams.Knowledge of vendor risk assessment and third-party risk management practices.Effective communication skills, able to engage with internal and external stakeholders at all levels.Familiarity with current cybersecurity frameworks, standards, and best practices.Ability to develop and apply risk models and metrics-based reporting.Experience partnering in contract negotiations related to cybersecurity and resilience.Understanding of incident response processes and cross-functional collaboration.Demonstrated ability to innovate and adapt processes to meet evolving threats, including AI-related risks.What makes you stand out :
Proven track record of leading global teams in cyber and IT risk management.Experience driving continuous improvement in vendor risk assessment methodologies.Strong ability to build partnerships with vendors and internal stakeholders to enhance cybersecurity resilience.Expertise in emerging technologies and their associated risks, including AI.Ability to communicate complex risk concepts clearly to executive leadership and diverse audiences.Why join our team :
We help you be your best through professional development opportunities, interesting work and supportive leaders.We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.