A biotech organization in Plainsboro, NJ is seeking an IT Security Manager to lead third-party cyber risk management and audit activities within a hybrid environment. This role will focus on security risk assessment, control development, stakeholder collaboration, and ongoing compliance reporting across a global organization.
About the Opportunity:
- Schedule: Monday to Friday
- Hours: Standard business
- Setting: Hybrid (2 days onsite)
Responsibilities:
- Develop and maintain third-party cyber risk management security standards, documentation, and related requirements.
- Assess third-party and vendor security risks and support ongoing risk management throughout supplier relationships.
- Plan, coordinate, and execute security audits, assurance reviews, and remediation tracking.
- Define security metrics, key risk indicators, and reporting dashboards to monitor risk posture and progress.
- Partner with cross-functional teams to align security practices with policies, regulations, and business needs.
Qualifications:
- Bachelor’s degree in Computer Science, MIS, or a related field, or an equivalent combination of relevant work experience and training
- At least 5 years of experience in third-party Cyber Risk Management, Information Security, and Risk Management
- Experience working with security and risk management frameworks and regulations such as ISO, NIST, GDPR, SOX, HIPAA, or similar standards
- Experience with GRC tools such as ServiceNow, Galvanize, Vanta, MetricStream, Archer, or WolfPAC
- Experience defining and implementing security management processes and controls
- Experience in multinational organizations and global virtual teams
- Excellent written, verbal, communication, presentation, analytical, organizational, and interpersonal skills
Desired Skills:
- Experience in pharma, biotech, or healthcare environments
- Professional certification such as CISA, CRISC, CISM, or CISSP
- Knowledge of current and emerging cybersecurity and privacy regulations
- Experience with vendor management and assurance frameworks, including SOC 1 and SOC 2 audits and reports
- Background in developing security improvement roadmaps and driving remediation actions



