Cybersecurity Lead Associate — Third-Party Risk Management

QXO

United States

On-site

USD 101,000 - 172,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

401(k) with employer match
Medical, dental, and vision insurance
PTO and holidays
Parental leave
Paid time off for sick leave
Training and certifications
Legal assistance
EAP

Job summary

QXO, a leading building products distributor, seeks a Cybersecurity Lead Associate for Third-Party Risk Management in the United States.

You will own the TPRM program, monitor security posture, perform due diligence on suppliers, and drive risk-based improvements across contracts and onboarding.

Qualifications

  • 10+ years of experience in cybersecurity, IT risk management, and/or vendor risk management.
  • Hands-on experience owning an enterprise-level program of significant complexity with multiple stakeholder groups.
  • Working knowledge of NIST CSF 2.0 and third-party risk frameworks.

Responsibilities

  • Independently own the cybersecurity TPRM program: continuous security posture monitoring, supplier due diligence assessments, contract negotiations and redlining, administration of multiple supplier risk management platforms
  • Lead the administration and optimize QXO's SecurityScorecard implementation, including score monitoring, alerting workflows, and vendor outreach for identified issues
  • Conduct security risk assessments of new and existing suppliers, with limited oversight and particular attention to vendors accessing Confidential or Highly Confidential QXO data
  • Serve as the subject matter expert and technical partner with Procurement, Legal, and Business Owners to ensure cybersecurity requirements are embedded in contracts and vendor onboarding
  • Track and report on third‑party risk posture, remediation status, and program metrics to Cybersecurity leadership
  • Support due diligence for M&A activity, evaluating the cyber risk profile of acquisition targets and integration plans
  • Administer and maintain the Optro Third-Party Risk Management (TPRM) module, including workflow configuration, user access, and data integrity across compliance and vendor risk assessments.
  • Serve as the primary point of contact for Optro TPRM module support, troubleshooting issues, coordinating platform updates/enhancements, and training end users

Skills

Cybersecurity
IT risk management
Vendor risk management
NIST CSF 2.0
Security risk assessments
Executive communication
Enterprise platforms administration

Tools

SecurityScorecard
Optro TPRM module

Job description

As a(n) Cybersecurity Lead Associate — Third-Party Risk Management at QXO, you’ll own and mature the Third-Party Risk Management (TPRM) program, including build out and day-to-day administration of our continuous vendor monitoring platform (SecurityScorecard). This role is central to QXO's ability to assess and manage cyber risk introduced through suppliers, technology vendors, and acquired entities as the company continues its acquisition-driven growth strategy.

QXO is a leading distributor and installer of building products serving an $800 billion market. The company’s mission is to modernize the building products industry through advanced technology and a best-in‑class customer experience. QXO is North America’s largest distributor and installer of insulation, the second‑largest distributor of roofing products, the second‑largest publicly traded distributor of lumber and building materials, and the largest distributor of waterproofing products. The company is targeting $50 billion in annual revenue within the decade through accretive acquisitions and organic growth. For more information, visit QXO.com.

What You'll Do
  • Independently own the cybersecurity TPRM program: continuous security posture monitoring, supplier due diligence assessments, contract negotiations and redlining, administration of multiple supplier risk management platforms
  • Lead the administration and optimize QXO's SecurityScorecard implementation, including score monitoring, alerting workflows, and vendor outreach for identified issues
  • Conduct security risk assessments of new and existing suppliers, with limited oversight and particular attention to vendors accessing Confidential or Highly Confidential QXO data
  • Serve as the subject matter expert and technical partner with Procurement, Legal, and Business Owners to ensure cybersecurity requirements are embedded in contracts and vendor onboarding
  • Track and report on third‑party risk posture, remediation status, and program metrics to Cybersecurity leadership
  • Support due diligence for M&A activity, evaluating the cyber risk profile of acquisition targets and integration plans
  • Administer and maintain the Optro Third-Party Risk Management (TPRM) module, including workflow configuration, user access, and data integrity across compliance and vendor risk assessments.
  • Serve as the primary point of contact for Optro TPRM module support, troubleshooting issues, coordinating platform updates/enhancements, and training end users
What You'll Bring
  • 10+ years of experience in cybersecurity, IT risk management, and/or vendor risk management
  • Hands‑on experience owning an Enterprise level program of significant complexity with multiple stakeholder groups
  • Working knowledge of NIST CSF 2.0 and third‑party risk frameworks
  • Experience conducting or reviewing security risk assessments
  • Strong written communication skills — this role regularly produces risk assessments and executive‑facing summaries
  • Experience administering Enterprise level platforms used by diverse stakeholders
What you’ll earn
  • Base pay range: $101,300 - $172,000
  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • PTO, company holidays, and parental leave
  • Paid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.
  • Paid training and certifications
  • Legal assistance and identity protection
  • Employee assistance program (EAP)

To comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.

QXO is an Equal Opportunity Employer. We value diversity and do not discriminate on the basis of race, color, religion, gender or sexual orientation, national origin, age, disability, or any other protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Lead Associate — Third-Party Risk Management
Cybersecurity Lead Associate — Third-Party Risk Management

Beacon Roofing Supply, Inc • Charlotte (NC)

On-site
USD 101,000 - 172,000
Annual bonus
401(k) with employer match
Medical, dental, and vision insurance
+2
Manager, Indirect Procurement
Manager, Indirect Procurement

QXO • Herndon (VA)

On-site
USD 120,000 - 150,000
401(k) with employer match
Medical, dental, and vision insurance
PTO, company holidays, and parental-le
+4
Lead Application Security Engineer, Code to Cloud
Lead Application Security Engineer, Code to Cloud

QXO • Vancouver (WA)

On-site
USD 101,000 - 172,000
Medical, dental, and vision insurance
PTO and holidays
401(k) with employer match
Lead Application Security Engineer, Code to Cloud
Lead Application Security Engineer, Code to Cloud

Beacon Roofing Supply, Inc • Vancouver (WA)

On-site
USD 101,000 - 172,000
Manager, Indirect Procurement
Manager, Indirect Procurement

Beacon Roofing Supply, Inc • Herndon (VA)

On-site
USD 150,000 - 200,000
Staff Software Engineer, Backend
Staff Software Engineer, Backend

QXO • Seattle (WA)

On-site
USD 150,000 - 275,000
401(k) match
Medical insurance
Dental insurance
+5
Senior Manager, Software Engineering - Transactions
Senior Manager, Software Engineering - Transactions

Beacon Roofing Supply, Inc • Seattle (WA)

Hybrid
USD 200,000 - 275,000
Base salary range
Annual bonus
Equity/stock
+4
Project Manager, Pricing
Project Manager, Pricing

QXO • Greenwich (CT)

On-site
USD 100,000 - 150,000
401(k) match
Medical, dental, and vision insurance
PTO, holidays, parental leave
+3
Senior Software Engineer, Mobile
Senior Software Engineer, Mobile

QXO • Seattle (WA)

On-site
USD 158,000 - 214,000
Annual bonus
Stock options
401(k) with employer match
+5
Senior Software Engineer
Senior Software Engineer

QXO • Seattle (WA)

On-site
USD 170,000 - 235,000
Medical, dental, and vision insurance
401(k) with employer match
PTO and holidays
+1