Cybersecurity Lead Associate — Third-Party Risk Management

Beacon Roofing Supply, Inc

Charlotte (NC)

On-site

USD 101,000 - 172,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Annual bonus
401(k) with employer match
Medical, dental, and vision insurance
PTO and holidays
Paid time off during first year

Job summary

QXO is seeking a Cybersecurity Lead Associate — Third-Party Risk Management to own and mature the TPRM program, including day-to-day administration of our security platform. The role focuses on assessing cyber risk from suppliers, vendors, and acquired entities during growth and acquisitions.

You will lead risk assessments, embed cybersecurity in vendor contracts, and report metrics to Cybersecurity leadership, while supporting due diligence for M&A activities.

Qualifications

  • 10+ years of experience in cybersecurity or risk management.
  • Experience owning an enterprise-level program with multiple stakeholders.
  • Familiarity with NIST CSF 2.0 and third-party risk frameworks.
  • Experience conducting or reviewing security risk assessments.
  • Strong written communication and executive summaries.

Responsibilities

  • Own the TPRM program and continuous monitoring.
  • Lead SecurityScorecard administration and vendor outreach.
  • Conduct security risk assessments for suppliers.
  • Embed cybersecurity in contracts and onboarding.
  • Track risk posture and metrics for leadership.
  • Support due diligence for M&A activity.
  • Administer Optro TPRM module and manage data integrity.
  • Serve as primary point of contact for module support.

Skills

Cybersecurity
IT risk management
Vendor risk management
NIST CSF 2.0
Risk assessments
Written communication
Enterprise platforms

Job description

As a(n) Cybersecurity Lead Associate — Third-Party Risk Management at QXO, you’ll own and mature the Third-Party Risk Management (TPRM) program, including build out and day-to-day administration of our continuous vendor monitoring platform (SecurityScorecard). This role is central to QXO's ability to assess and manage cyber risk introduced through suppliers, technology vendors, and acquired entities as the company continues its acquisition-driven growth strategy.

QXO is a leading distributor and installer of building products serving an $800 billion market. The company’s mission is to modernize the building products industry through advanced technology and a best-in-class customer experience. QXO is North America’s largest distributor and installer of insulation, the second-largest distributor of roofing products, the second-largest publicly traded distributor of lumber and building materials, and the largest distributor of waterproofing products. The company is targeting $50 billion in annual revenue within the decade through accretive acquisitions and organic growth. For more information, visit QXO.com.

What you'll do:
  • Independently own the cybersecurity TPRM program: continuous security posture monitoring, supplier due diligence assessments, contract negotiations and redlining, administration of multiple supplier risk management platforms
  • Lead the administration and optimize QXO's SecurityScorecard implementation, including score monitoring, alerting workflows, and vendor outreach for identified issues
  • Conduct security risk assessments of new and existing suppliers, with limited oversight and particular attention to vendors accessing Confidential or Highly Confidential QXO data
  • Serve as the subject matter expert and technical partner with Procurement, Legal, and Business Owners to ensure cybersecurity requirements are embedded in contracts and vendor onboarding
  • Track and report on third-party risk posture, remediation status, and program metrics to Cybersecurity leadership
  • Support due diligence for M&A activity, evaluating the cyber risk profile of acquisition targets and integration plans
  • Administer and maintain the Optro Third-Party Risk Management (TPRM) module, including workflow configuration, user access, and data integrity across compliance and vendor risk assessments.
  • Serve as the primary point of contact for Optro TPRM module support, troubleshooting issues, coordinating platform updates/enhancements, and training end users
What you'll bring:
  • 10+ years of experience in cybersecurity, IT risk management, and/or vendor risk management
  • Hands‑on experience owning an Enterprise level program of significant complexity with multiple stakeholder groups
  • Working knowledge of NIST CSF 2.0 and third‑party risk frameworks
  • Experience conducting or reviewing security risk assessments
  • Strong written communication skills — this role regularly produces risk assessments and executive‑facing summaries
  • Experience administering Enterprise level platforms used by diverse stakeholders
What you'll earn
  • Base pay range: $101,300 - $172,000
  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • PTO, company holidays, and parental leave
  • Paid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.
  • Paid training and certifications
  • Legal assistance and identity protection
  • Pet insurance
  • Employee assistance program (EAP)

To comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.

QXO is an Equal Opportunity Employer. We value diversity and do not discriminate on the basis of race, color, religion, gender or sexual orientation, national origin, age, disability, or any other protected status.

Salary Range:

USD $101,300.00 - USD $172,000.00 /Yr.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Application Security Engineer, Code to Cloud
Lead Application Security Engineer, Code to Cloud

QXO • Vancouver (WA)

On-site
USD 101,000 - 172,000
Medical, dental, and vision insurance
PTO and holidays
401(k) with employer match
Manager, Indirect Procurement
Manager, Indirect Procurement

Beacon Roofing Supply, Inc • Herndon (VA)

Hybrid
USD 150,000 - 200,000
Lead Application Security Engineer, Code to Cloud
Lead Application Security Engineer, Code to Cloud

Beacon Roofing Supply, Inc • Vancouver (WA)

On-site
USD 101,000 - 172,000
Manager, Indirect Procurement
Manager, Indirect Procurement

QXO • Herndon (VA)

On-site
USD 120,000 - 150,000
401(k) with employer match
Medical, dental, and vision insurance
PTO, company holidays, and parental-le
+4
Senior Software Engineer, Mobile
Senior Software Engineer, Mobile

QXO • Seattle (WA)

On-site
USD 158,000 - 214,000
Annual bonus
Stock options
401(k) with employer match
+5
Senior Software Engineer, Mobile
Senior Software Engineer, Mobile

Beacon Roofing Supply, Inc • Seattle (WA)

On-site
USD 138,000 - 235,000
Bonus (Annual performance)
Equity / Long term incentive
401(k) with employer match
+7
Senior Manager, Indirect Procurement
Senior Manager, Indirect Procurement

QXO • Tucker (GA)

On-site
USD 140,000 - 210,000
401(k) with employer match
Medical, dental, and vision insurance
+1
Principal Product Manager, Technical
Principal Product Manager, Technical

Beacon Roofing Supply, Inc • Seattle (WA)

On-site
USD 175,000 - 400,000
Annual performance bonus
Long term incentive (equity/stock)
401(k) with employer match
+1
Senior Software Engineer
Senior Software Engineer

QXO • Seattle (WA)

On-site
USD 170,000 - 235,000
Medical, dental, and vision insurance
401(k) with employer match
PTO and holidays
+1
Project Manager, Pricing
Project Manager, Pricing

QXO • Greenwich (CT)

On-site
USD 100,000 - 150,000
401(k) match
Medical, dental, and vision insurance
PTO, holidays, parental leave
+3