Lead Service Consultant – Supplier Security Due Diligence & Monitoring Service
About the role
The Supplier Security Due Diligence & Monitoring Service operates at the intersection of Cybersecurity, Legal, Procurement, Supplier Management, and Enterprise Risk Management. The team is responsible for helping the enterprise navigate information security requirements within supplier contracts by providing first-line support during contract negotiations and redline reviews.
What's exciting about this role?
Be a key influencer within a highly visible enterprise service that directly impacts supplier risk outcomes across the organization. This role operates at the center of cybersecurity, legal, procurement, and business strategy, providing the opportunity to shape supplier contracting decisions, influence enterprise risk management practices, and drive operational excellence in security governance. As a senior individual contributor, you will have the opportunity to advise stakeholders on complex contractual security matters, help establish scalable practices and standards, and support the evolution of a service that enables the business to move quickly while ensuring critical security requirements remain protected in an increasingly complex supplier ecosystem.
Responsibilities
- Provide subject matter expertise and consultation on information security requirements within supplier contracts during contract negotiations and redline reviews.
- Translate supplier risk assessment outcomes into practical contractual security positions and recommend risk-aligned solutions for business stakeholders.
- Review supplier-proposed contractual language and determine alignment with established security requirements, standards, and enterprise risk expectations.
- Apply approved fallback language and assist stakeholders in navigating contractual negotiations involving security controls and requirements.
- Document security control exceptions, risk acceptance decisions, contractual deviations, and non-standard positions in accordance with established governance processes.
- Facilitate escalation and governance review of contractual positions that fall outside approved standards or risk tolerances.
- Partner closely with Cybersecurity, Legal, Procurement, Supplier Management, Enterprise Risk Management, and business stakeholders to support timely and informed contracting decisions.
- Serve as a senior resource for complex supplier security due diligence engagements and contractual risk discussions.
- Support development and maintenance of service procedures, operating guidelines, knowledge articles, templates, and training materials.
- Identify trends, recurring issues, and opportunities for process optimization to improve service effectiveness and stakeholder experience.
- Contribute to service metrics, reporting, quality assurance activities, and continuous improvement initiatives.
Preferred Experience
- Experience supporting third-party risk management, supplier security assessments, cybersecurity governance, technology risk management, procurement, legal operations, or contract management activities.
- Demonstrated ability to interpret complex security requirements and translate technical risk concepts into practical business and contractual guidance.
- Experience working with cross-functional stakeholders including Legal, Procurement, Enterprise Risk Management, and Cybersecurity teams.
- Strong analytical, communication, negotiation, and stakeholder management skills.
- Experience supporting governance processes, exception management, policy interpretation, and control assessment activities.
- Ability to influence decisions, build consensus, and navigate ambiguity in a complex enterprise environment.
Success in this role
Success in this position is demonstrated through the delivery of consistent, risk-aligned contractual security guidance; effective support of supplier negotiations; timely resolution of stakeholder inquiries; thorough documentation of contractual exceptions and decisions; and meaningful contributions to the ongoing maturity, scalability, and effectiveness of the Supplier Security Due Diligence & Monitoring Service. The role helps ensure the enterprise can confidently engage suppliers while maintaining alignment with information security requirements and enterprise risk expectations.
Skills
- Analytical Thinking
- Contract Negotiations
- Cybersecurity Risk Management
- Executive Communications
- Information Security
- Information Technology (IT) Risk Management
- Process Governance
- Reporting
- Risk Mitigation Strategies
- Risk Reporting
- Supplier Governance
- Supplier Management
- Technical Risk Assessment
- Third Party Risk Management
- Threat and Vulnerability Management
Pay
Compensation offered for this role is 90,700.00 - 153,925.00 annually and is based on experience and qualifications.