Remote InfoSec Client & Vendor Risk Lead

Baker Botts

Dallas (TX)

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Baker Botts L.L.P. is seeking an Information Security Client & Vendor Risk Manager to lead the client and vendor due-diligence program and oversee security vetting for third-party providers.

The role demands expertise in security frameworks, risk judgment, and the ability to influence senior stakeholders and client security teams. The successful candidate will collaborate with IT, Procurement, and Legal teams, manage audits, and stay ahead of regulatory developments affecting the legal industry.

Qualifications

  • 6+ years in information security, vendor risk management, compliance, or legal-industry operations.
  • Deep understanding of SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, and state privacy laws.
  • Experience conducting or leading vendor-risk assessments for enterprise-level technology providers.
  • Strong communication skills, including briefing partners, responding to client security teams, and translating technical concepts for non-technical audiences.
  • Demonstrated ability to work independently, manage sensitive information, and lead cross-functional initiatives.
  • Certifications such as CTPRA, ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CRISC, or CISA are required.
  • Experience with legal-industry technologies (DMS, e-discovery platforms, cloud-based tools) is a plus.

Responsibilities

  • Own and mature the firm-wide client and vendor due-diligence program.
  • Serve as the firm’s subject-matter expert on information-security controls, certifications, and risk posture during audits, RFPs, and reviews.
  • Lead vendor-risk assessments for high-impact technology providers, including review of SOC 2, ISO 27001, pen-test results, and data protection practices.
  • Develop and maintain the firm's vendor-risk management framework, including risk scoring and onboarding workflows.
  • Partner with Procurement, IT, and Office of General Counsel to evaluate vendor contracts and risk mitigation strategies.
  • Prepare the firm for client audits and regulatory reviews, coordinating evidence collection across departments.
  • Represent the firm in client-facing security discussions with stakeholders.
  • Monitor emerging risks and regulatory developments relevant to the legal industry.
  • Mentor junior analysts and contribute to the Risk and Compliance team.
  • Drive continuous improvement of due-diligence workflows and remediation processes.

Skills

Vendor risk management
Information security
Compliance
Communication skills
Independent work
Cross-functional leadership
Regulatory awareness

Education

CISSP, CISM, CRISC, or CISA
CTPRA
ISO 27001 Lead Implementer / Lead Auditor

Tools

DMS
e-discovery platforms
Cloud-based practice-management tools

Job description

Baker Botts L.L.P. is seeking an Information Security Client & Vendor Risk Manager to lead the client and vendor due-diligence program and oversee security vetting for third-party providers.

The role demands expertise in security frameworks, risk judgment, and the ability to influence senior stakeholders and client security teams. The successful candidate will collaborate with IT, Procurement, and Legal teams, manage audits, and stay ahead of regulatory developments affecting the legal industry.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Client & Vendor Risk Manager, InfoSec & Compliance
Remote Client & Vendor Risk Manager, InfoSec & Compliance

Baker Botts LLP • Dallas (TX), Northern (KY)

Hybrid
USD 140,000 - 200,000
Client & Vendor Risk Manager
Client & Vendor Risk Manager

Baker Botts LLP • Dallas (TX), Northern (KY)

Hybrid
USD 140,000 - 200,000
Remote Client & Vendor Security Risk Manager
Remote Client & Vendor Security Risk Manager

KamisPro • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Information Security Client and Vendor Risk Manager
Information Security Client and Vendor Risk Manager

KamisPro • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Senior IT Risk & Cybersecurity Leader (Hybrid)
Senior IT Risk & Cybersecurity Leader (Hybrid)

Baker Tilly International • Tewksbury (MA)

On-site
USD 160,000 - 299,000
IT Risk & Cybersecurity Senior Consultant
IT Risk & Cybersecurity Senior Consultant

Baker Tilly Advisory Group, LP • Atlanta (GA)

Hybrid
USD 86,000 - 163,000
Senior IT Risk & Cybersecurity Consultant (Hybrid)
Senior IT Risk & Cybersecurity Consultant (Hybrid)

Baker Tilly Advisory Group, LP • Frisco (TX)

Hybrid
USD 86,000 - 163,000
Senior IT Audit & Cybersecurity Risk Consultant
Senior IT Audit & Cybersecurity Risk Consultant

Baker Tilly US • New York (NY)

On-site
USD 85,000 - 163,000
Senior IT Audit & Cybersecurity Risk Consultant
Senior IT Audit & Cybersecurity Risk Consultant

Baker Tilly Advisory Group, LP • Tewksbury (MA)

Hybrid
USD 86,000 - 163,000
IT Audit, Cybersecurity & Risk Director — Flexible
IT Audit, Cybersecurity & Risk Director — Flexible

Baker Tilly US • Tewksbury (MA)

On-site
USD 212,000 - 359,000