Information Security Client and Vendor Risk Manager

KamisPro

Dallas (TX)

Hybrid

USD 120,000 - 180,000

Full time

48 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KamisPro seeks an Information Security Client & Vendor Risk Manager to lead the client due diligence program and oversee third-party assessments. This role requires expertise in security frameworks, risk, compliance, and stakeholder management, with a preference for law-firm experience.

The position is hybrid: primarily remote with in-person meetings in Dallas, usually 2 per month and up to 6 every 4–6 months, supporting a broad Risk & Compliance function.

Qualifications

  • 6+ years of experience in information security, vendor risk management, cybersecurity compliance, or governance, risk, and compliance (GRC) within a Law Firm.
  • Strong knowledge of security frameworks and standards, including SOC 2, ISO 27001, NIST Cybersecurity Framework (CSF), HIPAA, GLBA, and applicable privacy regulations.
  • Experience leading enterprise vendor risk assessments and evaluating third-party security controls.
  • Excellent written and verbal communication skills with the ability to present technical information to executive leadership and non-technical audiences.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, CTPRA, or ISO 27001 Lead Implementer/Auditor.

Responsibilities

  • Lead and continuously improve the enterprise-wide client and vendor due diligence program.
  • Serve as the subject matter expert for information security controls, certifications, and risk posture during client security reviews, audits, RFPs, and contract negotiations.
  • Conduct complex vendor security assessments, including reviews of SOC 2 reports, ISO 27001 certifications, penetration testing results, cloud security controls, privacy practices, and data protection measures.
  • Develop and maintain vendor risk management processes, including risk scoring methodologies, onboarding workflows, and continuous monitoring.
  • Partner with Procurement, Legal, IT, and business stakeholders to evaluate vendor contracts, negotiate security requirements, and recommend risk mitigation strategies.
  • Coordinate responses for client audits and regulatory reviews, including evidence collection and cross-functional collaboration.
  • Represent the organization in client-facing security discussions and respond to security questionnaires and escalated inquiries.
  • Monitor emerging cybersecurity threats, privacy regulations, and industry compliance requirements.
  • Mentor junior team members and contribute to the growth of the broader Risk and Compliance function.
  • Drive process improvements that enhance efficiency, strengthen security posture, and improve the client and vendor due diligence experience.
  • Prepare periodic risk reports and executive briefings for leadership.
  • Support additional information security and risk management initiatives as assigned.

Skills

Vendor risk management
Information security
Executive communication
Independent working

Job description

The Information Security Client & Vendor Risk Manager leads the organization's client due diligence program and oversees information security assessments for third-party vendors. Highly prefer law firm experience. This role requires expertise in security frameworks, risk assessment, regulatory compliance, and stakeholder management. You will serve as the primary liaison between clients, internal leadership, Information Security, Procurement, Legal, and Risk Management to ensure the organization meets evolving security and compliance expectations.

Hybrid: The role is primarily remote. There will be some days of in-person meetings in Dallas, usually 2 per month, but sometimes extended up to 6 every 4-6 months.

Key Responsibilities
  • Lead and continuously improve the enterprise-wide client and vendor due diligence program.
  • Serve as the subject matter expert for information security controls, certifications, and risk posture during client security reviews, audits, RFPs, and contract negotiations.
  • Conduct complex vendor security assessments, including reviews of SOC 2 reports, ISO 27001 certifications, penetration testing results, cloud security controls, privacy practices, and data protection measures.
  • Develop and maintain vendor risk management processes, including risk scoring methodologies, onboarding workflows, and continuous monitoring.
  • Partner with Procurement, Legal, IT, and business stakeholders to evaluate vendor contracts, negotiate security requirements, and recommend risk mitigation strategies.
  • Coordinate responses for client audits and regulatory reviews, including evidence collection and cross-functional collaboration.
  • Represent the organization in client-facing security discussions and respond to security questionnaires and escalated inquiries.
  • Monitor emerging cybersecurity threats, privacy regulations, and industry compliance requirements.
  • Mentor junior team members and contribute to the growth of the broader Risk and Compliance function.
  • Drive process improvements that enhance efficiency, strengthen security posture, and improve the client and vendor due diligence experience.
  • Prepare periodic risk reports and executive briefings for leadership.
  • Support additional information security and risk management initiatives as assigned.
Qualifications
Required
  • 6+ years of experience in information security, vendor risk management, cybersecurity compliance, or governance, risk, and compliance (GRC), within a Law Firm.
  • Strong knowledge of security frameworks and standards, including SOC 2, ISO 27001, NIST Cybersecurity Framework (CSF), HIPAA, GLBA, and applicable privacy regulations.
  • Experience leading enterprise vendor risk assessments and evaluating third-party security controls.
  • Excellent written and verbal communication skills with the ability to present technical information to executive leadership and non-technical audiences.
  • Proven ability to manage sensitive information, lead cross-functional initiatives, and work independently in fast-paced environments.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, CTPRA, or ISO 27001 Lead Implementer/Auditor.
Preferred
  • Familiarity with document management systems, eDiscovery platforms, SaaS environments, and cloud-based enterprise technologies.
  • Full-time, mostly remote position with occasional travel for team meetings, client engagements, or onsite assessments.
  • Periodic availability outside standard business hours may be required to support business needs.
  • Requires a secure home office, reliable internet connection, and the ability to collaborate across distributed teams.
  • Ability to manage multiple priorities and perform effectively in a fast-paced environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Client & Vendor Security Risk Manager
Remote Client & Vendor Security Risk Manager

KamisPro • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Director, Security Risk Management
Director, Security Risk Management

CardWorks Servicing LLC • United States

Hybrid
USD 151,000 - 168,000
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
Paid vacation and sick days
Vendor Risk Management
Vendor Risk Management

Synergis • Atlanta (GA)

Hybrid
Vendor Infrastructure IT Risk Manager - Chief Risk Office
Vendor Infrastructure IT Risk Manager - Chief Risk Office

Selby Jennings • New York (NY)

On-site
Interim Cybersecurity and IT Risk Lead Consultant
Interim Cybersecurity and IT Risk Lead Consultant

Ports North • Dallas (TX)

Hybrid
USD 140,000 - 200,000
Vendor Cybersecurity Auditor #2945
Vendor Cybersecurity Auditor #2945

Genius Road, LLC • Austin (TX)

On-site
USD 85,000 - 115,000
Opportunities for professional growth
Collaborative work environment
High visibility within the team
Cyber Security Specialist
Cyber Security Specialist

Jim Adler & Associates • Houston (TX)

On-site
USD 90,000 - 125,000
Supply Chain Analyst (Vendor & Supply Chain Risk)
Supply Chain Analyst (Vendor & Supply Chain Risk)

Crux Security • Austin (TX)

Hybrid
USD 90,000 - 130,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Supervisor, IT Security Vendor Risk Management
Supervisor, IT Security Vendor Risk Management

Raymond James • Saint Petersburg (FL)

Hybrid
USD 120,000 - 190,000
Benefits package
Hybrid work model