FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in third-party risk management, security operations, and vulnerability management, with a strong focus on developing and implementing security policies, risk assessments, and automation solutions. Proficient in leveraging AI and emerging technologies to enhance operational efficiency and decision-making within enterprise security frameworks.
Highest-signal resume keywords
Third-Party Risk ManagementSecurity OperationsVulnerability ManagementAI and Automation ToolsInformation Security Policies
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk AssessmentSecurity Architecture EvaluationDisaster Recovery PlanningEDiscoveryData Retention ManagementSecurity Awareness TrainingProcess ImprovementMetrics DevelopmentControl Gap MitigationNetwork and Systems Architecture
Soft Skills
Exceptional Communication SkillsStakeholder CollaborationTraining Delivery
Tools & Technologies
Third-Party Risk Management PlatformsEnterprise Threat Intelligence ToolsMulti-Cloud Environments
Certifications & Qualifications
CISSPCISMCRISCSecurity+CISA
Industry Keywords
SOC-2ISO-27001NIST SP 800Data Privacy LawsCCPA/CPRAGDPRBroadcast/Media Entertainment
Tech Stack
Tools & technologiesCloud
About the role
Key responsibilities & impact- Conduct third-party, vendor, service provider, and software risk assessments while meeting SLAs and communicating with stakeholders
- Contribute to the creation and maturation of information security policies and processes
- Identify opportunities to automate manual processes and engineer process improvements
- Develop and deliver Disaster Recovery and Continuity of Operations risk assessments and establish resiliency plans
- Assist with governance of the enterprise Policy Exception process and provide reports visible to senior leaders
- Create, adapt, and enhance weekly metrics to measure program effectiveness
- Evaluate security architectures, identify risks and compensating controls, and develop mitigation plans
- Develop and deliver security awareness and phishing campaigns
- Perform and maintain litigation and data retention holds using eDiscovery and support Legal requests
- Collaborate with stakeholders, business partners, third parties, Legal, Privacy, and IT
- Deliver live training sessions to diverse audiences
- Evaluate and recommend products, maintain knowledge of emerging technologies, and maximize existing tool value
- Respond to information security tickets and requests according to team SLA
- Collaborate with third parties to remediate risks and minimize attack surface
- Design, document, and implement procedures for analyzing and evaluating risk
- Research emerging technologies and provide options to leadership
- Identify security team improvements and optimize processes and techniques
- Support an enterprise security program through security engineering, investigations, vulnerability remediation, policy enforcement, and AI or automation engineering
Requirements
What you’ll need- Bachelor’s degree in Information Security, Information Technology, or related discipline
- 7 years of relevant work experience or a combined background in third-party risk management, security operations, security engineering, risk management, and vulnerability management
- Experience with enterprise threat intelligence and third-party risk management platforms
- Experience leveraging artificial intelligence (AI) and automation tools to streamline workflows, improve operational efficiency, and enhance decision-making
- Understanding of SOC-2, ISO-27001, and NIST SP 800 series frameworks, with ability to identify and mitigate control gaps
- Exceptional verbal and written communication skills, with ability to present complex information to audiences of varying subject knowledge
- Solid technical background and ability to understand network and systems architectures
- Prior experience working in commercial multi-cloud provider environments
- Industry certification required in one of the following areas: CISSP, CISM, CRISC, Security+, CISA, or equivalent
- Basic knowledge of current data privacy laws, including CCPA/CPRA and GDPR
- Commercial enterprise experience required
- Prior experience in broadcast/media entertainment industries preferred
- Experience conducting litigation holds, retention requests, and eDiscovery is a plus
- Not eligible for visa sponsorship, including H-1B sponsorship and OPT-STEM employment
Benefits
Comp & perks- Retirement plan
- Life and disability insurance
- Health insurance
- Dental insurance
- Vision plans
- Flexible spending accounts
- Sick leave
- Vacation time
- Personal time
- Parental leave
- Employee stock purchase plan
- Great benefits
- Open-door policy
- Upward mobility
