Remote Client & Vendor Security Risk Manager

KamisPro

Dallas (TX)

Hybrid

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KamisPro seeks an Information Security Client & Vendor Risk Manager to lead the client due diligence program and oversee third-party assessments. This role requires expertise in security frameworks, risk, compliance, and stakeholder management, with a preference for law-firm experience.

The position is hybrid: primarily remote with in-person meetings in Dallas, usually 2 per month and up to 6 every 4–6 months, supporting a broad Risk & Compliance function.

Qualifications

  • 6+ years of experience in information security, vendor risk management, cybersecurity compliance, or governance, risk, and compliance (GRC) within a Law Firm.
  • Strong knowledge of security frameworks and standards, including SOC 2, ISO 27001, NIST Cybersecurity Framework (CSF), HIPAA, GLBA, and applicable privacy regulations.
  • Experience leading enterprise vendor risk assessments and evaluating third-party security controls.
  • Excellent written and verbal communication skills with the ability to present technical information to executive leadership and non-technical audiences.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, CTPRA, or ISO 27001 Lead Implementer/Auditor.

Responsibilities

  • Lead and continuously improve the enterprise-wide client and vendor due diligence program.
  • Serve as the subject matter expert for information security controls, certifications, and risk posture during client security reviews, audits, RFPs, and contract negotiations.
  • Conduct complex vendor security assessments, including reviews of SOC 2 reports, ISO 27001 certifications, penetration testing results, cloud security controls, privacy practices, and data protection measures.
  • Develop and maintain vendor risk management processes, including risk scoring methodologies, onboarding workflows, and continuous monitoring.
  • Partner with Procurement, Legal, IT, and business stakeholders to evaluate vendor contracts, negotiate security requirements, and recommend risk mitigation strategies.
  • Coordinate responses for client audits and regulatory reviews, including evidence collection and cross-functional collaboration.
  • Represent the organization in client-facing security discussions and respond to security questionnaires and escalated inquiries.
  • Monitor emerging cybersecurity threats, privacy regulations, and industry compliance requirements.
  • Mentor junior team members and contribute to the growth of the broader Risk and Compliance function.
  • Drive process improvements that enhance efficiency, strengthen security posture, and improve the client and vendor due diligence experience.
  • Prepare periodic risk reports and executive briefings for leadership.
  • Support additional information security and risk management initiatives as assigned.

Skills

Vendor risk management
Information security
Executive communication
Independent working

Job description

KamisPro seeks an Information Security Client & Vendor Risk Manager to lead the client due diligence program and oversee third-party assessments. This role requires expertise in security frameworks, risk, compliance, and stakeholder management, with a preference for law-firm experience.

The position is hybrid: primarily remote with in-person meetings in Dallas, usually 2 per month and up to 6 every 4–6 months, supporting a broad Risk & Compliance function.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Client and Vendor Risk Manager
Information Security Client and Vendor Risk Manager

KamisPro • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Vendor Risk & Security Specialist (Remote Fridays)
Vendor Risk & Security Specialist (Remote Fridays)

Icapitalnetwork • Salt Lake City (UT)

Hybrid
USD 70,000 - 90,000
Comprehensive benefits package
Employer-matched retirement plan
Unlimited paid time off
Director, Cyber Risk & Vendor Security (Hybrid/Remote)
Director, Cyber Risk & Vendor Security (Hybrid/Remote)

CardWorks Servicing LLC • United States

Hybrid
USD 151,000 - 168,000
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
Paid vacation and sick days
Remote Cyber Security Analyst — Risk, Compliance & Assurance
Remote Cyber Security Analyst — Risk, Compliance & Assurance

RXinsider LTD. • Mission (KS)

On-site
USD 85,000 - 120,000
Health insurance
401(k) plan with company match
Paid time off
Senior Vendor Risk Analyst - Cybersecurity & TPRM (Hybrid)
Senior Vendor Risk Analyst - Cybersecurity & TPRM (Hybrid)

Synergis • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Vendor Risk Manager
Vendor Risk Manager

Aquent • Westlake (TX)

On-site
USD 120,000 - 180,000
Health insurance
Vision insurance
Dental insurance
+2
Remote Senior Cybersecurity Risk Analyst – TPRM & AI Risk
Remote Senior Cybersecurity Risk Analyst – TPRM & AI Risk

Danaher • United States

Remote
USD 130,000 - 160,000
Bonus eligibility
Benefits package
IT Security Vendor Risk Management Lead
IT Security Vendor Risk Management Lead

Raymond James • Saint Petersburg (FL)

Hybrid
USD 120,000 - 190,000
Benefits package
Hybrid work model
Remote Cyber Security Analyst - Compliance & Risk Expert
Remote Cyber Security Analyst - Compliance & Risk Expert

ScriptPro LLC • Mission (KS)

On-site
USD 80,000 - 105,000
Health benefits
PTO
Nine holidays
+1
Remote Information Security Auditor & Vendor Risk Lead
Remote Information Security Auditor & Vendor Risk Lead

securitypal • San Francisco (CA)

Hybrid
USD 166,000 - 170,000