Client & Vendor Risk Manager

Baker Botts LLP

Dallas, Northern (TX, KY)

Hybrid

USD 140,000 - 200,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Baker Botts LLP in the United States is seeking an Information Security Client & Vendor Risk Manager to oversee the firm’s client due diligence and third-party risk vetting. You will be SME on information-security controls, coordinate with IT Security, Procurement, and OGC, and prepare for audits and regulatory reviews while mentoring junior analysts.

The role is fully remote with periodic on-site meetings and travel as needed, interfacing with senior clients and partners in a high-regulation

Qualifications

  • Deep understanding of security frameworks and standards (SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, state privacy laws).
  • Experience conducting or leading vendor-risk assessments for enterprise providers.
  • Strong communication skills to brief partners and translate technical concepts.

Responsibilities

  • Own and mature the firm‑wide client and vendor due‑diligence program.
  • Serve as the firm’s SME on information‑security controls and risk posture.
  • Lead complex vendor‑risk assessments for high‑impact providers.
  • Develop and maintain the vendor‑risk management framework and onboarding workflows.
  • Partner with Procurement, IT, and OGC to evaluate vendor contracts and risk mitigation.
  • Prepare the firm for client audits and regulatory reviews and coordinate evidence collection.
  • Represent the firm in client‑facing security discussions with counsel and client teams.
  • Monitor regulatory developments relevant to the legal industry.

Skills

Security frameworks
Communication
Cross-functional leadership

Education

Certifications such as CTPRA / ISO 27001 Lead Implementer or Lead Auditor / CISSP, CISM, CRISC, CISA

Tools

DMS
e‑discovery platforms
cloud‑based practice‑management tools

Job description

Job Category: Office of General Counsel - Info Governance

The Information Security Client & Vendor Risk Manager leads the firm’s client due diligence program and oversees all information security vetting for third party vendors across the firm. This role requires deep expertise in security frameworks, strong risk‑assessment judgment, and the ability to influence senior stakeholders, including internal stakeholders, and client security teams. The Manager acts as a key liaison between the firm’s clients, internal leadership, IT Security, Procurement, and Risk Management, ensuring the firm meets the heightened expectations of our clients.

WHAT YOU'LL DO

Primary Responsibilities

  • Own and mature the firm‑wide client and vendor due‑diligence program, ensuring consistency, accuracy, and alignment with the firm’s security posture and regulatory obligations.
  • Serve as the firm’s subject‑matter expert on information‑security controls, certifications, and risk posture during client audits, RFPs, and reviews or client engagement terms.
  • Lead complex vendor‑risk assessments for high‑impact technology and service providers, including review of SOC 2 reports, ISO 27001 certifications, penetration‑test results, cloud‑security controls, data‑protection, privacy, and retention practices.
  • Develop and maintain the firm’s vendor‑risk management framework, including risk‑scoring methodologies, onboarding workflows, and continuous‑monitoring processes.
  • Partner with Procurement, IT, and Office of General Counsel to evaluate vendor contracts, negotiate security requirements, and recommend risk‑mitigation strategies.
  • Prepare the firm for client audits and regulatory reviews, coordinating evidence collection, documentation, and SME participation across multiple departments.
  • Represent the firm in client‑facing security discussions, including responding to escalated inquiries from corporate counsel, privacy officers, and client security teams.
  • Monitor emerging risks and regulatory developments relevant to the legal industry (e.g., SEC cybersecurity rules, state privacy laws, international data‑transfer requirements).
  • Mentor junior analysts and contribute to the professional development of the broader Risk and Compliance team.
  • Drive continuous improvement, identifying opportunities to streamline due‑diligence workflows, enhance tracking and remediation of client‑identified risks, and strengthen the firm’s security posture.

Additional Responsibilities

  • Provide management with periodic reports & briefings on evolving topics within their area of responsibility.
  • Other related projects and duties as assigned by the Director of Information Security.

WHAT YOU'LL BRING

Required

  • 6+ years of experience in information security, vendor risk management, compliance, or legal‑industry operations, ideally within an Am Law 200 firm or similarly regulated environment.
  • Deep understanding of security frameworks and standards (SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, state privacy laws).
  • Experience conducting or leading vendor‑risk assessments for enterprise‑level technology providers.
  • Strong communication skills, including the ability to brief partners, respond to client security teams, and translate technical concepts for non‑technical audiences.
  • Demonstrated ability to work independently, manage sensitive information, and lead cross‑functional initiatives in a high‑pressure environment.
  • Professional certifications such as CTPRA, ISO 27001 Lead Implementer or Lead Auditor and CISSP, CISM, CRISC, or CISA required.
  • Experience with legal‑industry technologies (DMS, e‑discovery platforms, cloud‑based practice‑management tools) is a plus.

HOW YOU'LL WORK

Extent of Contact

This position requires contact with individuals within the firms as follows:

  • Daily contact with staff from the Firm’s Information Technology, Client Development and Office of the General Counsel teams.
  • Moderate contact with Firm’s attorneys and client representatives.
  • Occasional contact with Firm Management.

This position requires contact with individuals outside the firm as follows:

  • Moderate contact with Firm vendors or potential vendors.
  • Moderate contact with Firm clients

Physical Requirements

  • Must be able to routinely lift and carry event materials and other items up to 10 pounds.
  • Must be able to work at a computer for extensive periods of time.
  • Must be able to lift, squat, kneel and bend.
  • Position requires the ability to visit face‑to‑face and on the phone with firm lawyers.

Working Conditions and Environment

  • Position is full‑time and requires a five‑day work week and standard hours as outlined in the Firm policy manual. Additional hours, including weekend and evening hours may be required to perform the essential functions of the job.
  • Must be able to perform essential duties of the position with time constraints and frequent interruptions.
  • Ability to work well in high pressure environments.
  • 24x7 communication access is required.
  • This position is fully remote. You will be required to come to the office periodically for team meetings or when there is a business or client need.
  • There is potential for travel when needed for team meetings, onsite assessments etc. when there is a business or client need.
  • When working remotely, you must have secure and reliable internet service and a safe, private workspace from which to work.

Baker Botts L.L.P. is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, gender, sex, age, religion, creed, national origin, citizenship, marital status, sexual orientation, disability, medical condition, military and veteran status, gender identity or expression, genetic information, or any other basis protected by federal, state, or local law.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vendor Security Analyst
Vendor Security Analyst

Hogan Lovells • Louisville (KY)

On-site
USD 121,000 - 146,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
Vendor Security Analyst
Vendor Security Analyst

Hogan Lovells • Washington, Northern (KY)

Hybrid
USD 121,000 - 146,000
Medical, dental, and vision insurance
401(k) retirement plan
Paid time off
IT Enterprise Risk Analyst
IT Enterprise Risk Analyst

Holland & Knight • Tampa (FL)

On-site
USD 85,000 - 110,000
Medical, dental and vision plans
401(k) and profit-sharing
Paid holidays and leave for new parents
Legal - Contracts Manager - Junior
Legal - Contracts Manager - Junior

Mindlance • Town of Texas (WI)

On-site
USD 120,000 - 150,000
Vendor Risk Management Analyst
Vendor Risk Management Analyst

Careers • Los Angeles (CA)

Hybrid
USD 80,000 - 110,000
Healthcare insurance
401k plan
Paid holidays & PTO
+4
Vendor Risk Management Analyst
Vendor Risk Management Analyst

Latham & Watkins LLP • Lancaster (CA)

Hybrid
USD 80,000 - 110,000
Healthcare, life and disability
401k plan
11 paid holidays + PTO 23 days first y
+4
Client Development Senior Coordinator, Intellectual Property
Client Development Senior Coordinator, Intellectual Property

Baker Botts LLP • Dallas (TX), Northern (KY)

Hybrid
USD 96,000 - 115,000
Information Governance Specialist
Information Governance Specialist

AIIM • Houston (TX)

On-site
USD 65,000 - 75,000
Governance, Risk, and Compliance Engineer
Governance, Risk, and Compliance Engineer

Baker Botts LLP • Austin (TX), Northern (KY)

Hybrid
USD 128,000 - 140,000
Comprehensive benefits program
Remote work flexibility
Professional development opportunities
Lead Engineer: Information Security
Lead Engineer: Information Security

Mayer Brown • Los Angeles (CA)

On-site
USD 135,000 - 180,000
Medical/dental/vision insurance
401(k) plan
Paid time off