InfoSec - Client & Vendor Risk Manager

KamisPro

Dallas (TX)

Hybrid

USD 120,000 - 180,000

Full time

35 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

KamisPro is seeking an experienced Information Security Client & Vendor Risk Manager to lead the client due diligence program and oversee third-party security assessments. This role requires expertise in security frameworks, risk assessment, regulatory compliance, and stakeholder management.

Hybrid: The role is primarily remote. There will be some days of in-person meetings in Dallas, usually 2 per month, but sometimes extended up to 6 every 4-6 months.

Qualifications

  • 6+ years in information security, vendor risk or GRC, ideally in a law firm.
  • Strong knowledge of SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA and privacy regs.
  • Proven vendor risk assessments and third-party security controls experience.
  • Excellent written and verbal communication for executives and non-technical audiences.
  • Ability to manage sensitive information and lead cross-functional initiatives.

Responsibilities

  • Lead and continuously improve the enterprise-wide client and vendor due diligence program.
  • Serve as SME for information security controls during client security reviews and audits.
  • Conduct complex vendor security assessments, including SOC 2, ISO 27001 and cloud controls.
  • Develop vendor risk processes, risk scoring, onboarding workflows, and monitoring.
  • Partner with Procurement, Legal, IT and stakeholders to evaluate contracts and mitigate risk.
  • Coordinate responses for client audits and regulatory reviews with cross-functional teams.
  • Represent the organization in client security discussions and respond to security questionnaires.
  • Monitor emerging cybersecurity threats and evolving privacy regulations.
  • Mentor junior team members and contribute to Risk & Compliance growth.
  • Drive process improvements to strengthen security posture and client/vendor diligence.

Skills

Information security
Vendor risk management
Regulatory compliance
Stakeholder management
Security frameworks
Executive communication

Job description

The Information Security Client & Vendor Risk Manager leads the organization's client due diligence program and oversees information security assessments for third-party vendors. This role requires expertise in security frameworks, risk assessment, regulatory compliance, and stakeholder management. You will serve as the primary liaison between clients, internal leadership, Information Security, Procurement, Legal, and Risk Management to ensure the organization meets evolving security and compliance expectations.

Hybrid: The role is primarily remote. There will be some days of in-person meetings in Dallas, usually 2 per month, but sometimes extended up to 6 every 4-6 months.

Key Responsibilities
  • Lead and continuously improve the enterprise-wide client and vendor due diligence program.
  • Serve as the subject matter expert for information security controls, certifications, and risk posture during client security reviews, audits, RFPs, and contract negotiations.
  • Conduct complex vendor security assessments, including reviews of SOC 2 reports, ISO 27001 certifications, penetration testing results, cloud security controls, privacy practices, and data protection measures.
  • Develop and maintain vendor risk management processes, including risk scoring methodologies, onboarding workflows, and continuous monitoring.
  • Partner with Procurement, Legal, IT, and business stakeholders to evaluate vendor contracts, negotiate security requirements, and recommend risk mitigation strategies.
  • Coordinate responses for client audits and regulatory reviews, including evidence collection and cross-functional collaboration.
  • Represent the organization in client-facing security discussions and respond to security questionnaires and escalated inquiries.
  • Monitor emerging cybersecurity threats, privacy regulations, and industry compliance requirements.
  • Mentor junior team members and contribute to the growth of the broader Risk and Compliance function.
  • Drive process improvements that enhance efficiency, strengthen security posture, and improve the client and vendor due diligence experience.
  • Prepare periodic risk reports and executive briefings for leadership.
  • Support additional information security and risk management initiatives as assigned.
Qualifications
Required
  • 6+ years of experience in information security, vendor risk management, cybersecurity compliance, or governance, risk, and compliance (GRC), within a Law Firm.
  • Strong knowledge of security frameworks and standards, including SOC 2, ISO 27001, NIST Cybersecurity Framework (CSF), HIPAA, GLBA, and applicable privacy regulations.
  • Experience leading enterprise vendor risk assessments and evaluating third-party security controls.
  • Excellent written and verbal communication skills with the ability to present technical information to executive leadership and non-technical audiences.
  • Proven ability to manage sensitive information, lead cross-functional initiatives, and work independently in fast-paced environments.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, CTPRA, or ISO 27001 Lead Implementer/Auditor.
Preferred
  • Familiarity with document management systems, eDiscovery platforms, SaaS environments, and cloud-based enterprise technologies.
  • Full-time, mostly remote position with occasional travel for team meetings, client engagements, or onsite assessments.
  • Periodic availability outside standard business hours may be required to support business needs.
  • Requires a secure home office, reliable internet connection, and the ability to collaborate across distributed teams.
  • Ability to manage multiple priorities and perform effectively in a fast-paced environment.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Client & Vendor Risk Leader | InfoSec & Compliance (Hybrid)
Client & Vendor Risk Leader | InfoSec & Compliance (Hybrid)

KamisPro • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Vendor Risk Management
Vendor Risk Management

Synergis • Atlanta (GA)

Hybrid
Interim Cybersecurity and IT Risk Lead Consultant
Interim Cybersecurity and IT Risk Lead Consultant

Ports North • Dallas (TX)

Hybrid
USD 140,000 - 200,000
Vendor Cybersecurity Auditor #2945
Vendor Cybersecurity Auditor #2945

Genius Road, LLC • Austin (TX)

On-site
USD 85,000 - 115,000
Opportunities for professional growth
Collaborative work environment
High visibility within the team
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Interim Cybersecurity & IT Risk Lead Consultant
Interim Cybersecurity & IT Risk Lead Consultant

Fermi LLC • Town of Texas (WI)

Hybrid
USD 180,000 - 230,000
Fractional Supply Chain Analyst
Fractional Supply Chain Analyst

Gofractional • Austin (TX)

Hybrid
USD 90,000 - 130,000
Risk & Compliance Engineer
Risk & Compliance Engineer

WebMD • Newark (NJ)

On-site
USD 82,000 - 97,000
Health Insurance (medical, dental, and
401(k) Retirement Plan with employer
Paid Time Off
+3
Senior Vendor Risk Analyst
Senior Vendor Risk Analyst

Direct Staffing Inc • San Francisco (CA)

On-site
USD 90,000 - 130,000
Risk & Compliance Engineer
Risk & Compliance Engineer

WebMD LLC • Newark (NJ)

On-site
USD 82,000 - 97,000
Health Insurance
Paid Time Off
401(k) Retirement Plan
+3