Third Party Vendor Risk Manager
• Conducted thorough risk assessments on third-party systems identifying vulnerabilities and implementing targeted mitigation strategies to minimize risks.• Collaborated with procurement teams to develop selection criteria and assist in vendor selection processes.• Managed simulated phishing campaigns (KnowBe4, PhishMe) focused on third-party users to evaluate and strengthen defenses against social engineering threats.• Led compliance initiatives to ensure third-party vendors… Show more • Conducted thorough risk assessments on third-party systems identifying vulnerabilities and implementing targeted mitigation strategies to minimize risks.• Collaborated with procurement teams to develop selection criteria and assist in vendor selection processes.• Managed simulated phishing campaigns (KnowBe4, PhishMe) focused on third-party users to evaluate and strengthen defenses against social engineering threats.• Led compliance initiatives to ensure third-party vendors aligned with Zippycom’s security standards, integrating ISO 27001, SOC 2, PCI-DSS, and HITRUST Cybersecurity Framework requirements, meeting industry benchmarks.• Actively monitored third-party threat intelligence sources (ThreatConnect, Recorded Future), anticipating emerging threats and preemptively addressing potential vulnerabilities.• Implemented a vendor risk management program that involved assessing third-party cybersecurity practices, conducting regular security questionnaires, and onsite audits to evaluate adherence to security policies.• Worked closely with legal and procurement teams to establish security clauses in vendor contracts, ensuring third-party obligations for data protection, breach notification, and compliance standards.• Developed and enforced a vendor access management policy, ensuring proper access controls for third-party users, including least privilege access, periodic access reviews, and multi-factor authentication (MFA).• Utilized a Third-Party Risk Management (TPRM) tool to automate vendor risk assessments, track risk remediation progress, and maintain an up-to-date inventory of vendor relationships.• Provided training and awareness programs for third-party partners, educating them on cybersecurity best practices, data protection requirements, and incident response protocols. Show less