We use essential cookies

Please Accept our Privacy Policy

Cybersecurity & Third-Party Risk Manager

AtWork Personnel Services

Sacramento, CA • $114,400 to $124,800 / yr • 9/10/2026

Job Description

Job Description

We are seeking an experienced Cybersecurity & Third-Party Risk Manager to support the day-to-day operation of enterprise IT risk management and third-party risk management programs.

This role will conduct cybersecurity and supplier risk assessments, manage the enterprise security risk register, oversee the vendor risk lifecycle, support third-party access governance, and assess risks associated with artificial intelligence vendors and use cases. The position works closely with Information Security, Compliance, Legal, Procurement, IT, Engineering, and other business stakeholders.

The organization maintains a SOC 2 Type 2 attestation and aligns its control environment with NIST SP 800-53 Revision 5, Moderate baseline. This position is primarily responsible for executing and maintaining established risk-management programs rather than building them from the ground up.

Responsibilities

  • Conduct third-party and supplier risk assessments throughout the vendor lifecycle, including onboarding, periodic reassessment, monitoring, and offboarding.
  • Evaluate vendor security posture using SOC 2 reports, ISO 27001 certifications, security questionnaires, and other supporting documentation.
  • Maintain and manage the enterprise cybersecurity risk register, including risk identification, scoring, treatment, ownership, exceptions, and remediation tracking.
  • Manage risk acceptance, security exceptions, and Plan of Action and Milestones (POA&M) activities.
  • Monitor vendor and supply-chain risks, including security incidents, fourth-party dependencies, concentration risk, attestation expirations, ownership changes, and other emerging risks.
  • Partner with Legal and Procurement to review cybersecurity requirements, contractual security provisions, data-processing terms, and vendor obligations.
  • Assess artificial intelligence vendors, model providers, and internal AI use cases for cybersecurity, privacy, data-use, data-retention, reliability, and governance risks.
  • Maintain an inventory of AI use cases and support alignment with frameworks such as NIST AI RMF and ISO/IEC 42001.
  • Support governance of third-party and non-employee access, including access reviews, recertification campaigns, provisioning, modification, and termination controls.
  • Support SOC 2 examinations and other audit activities by providing risk-management documentation and supporting evidence.
  • Develop risk metrics, key risk indicators, management reporting, and recommendations regarding security posture and risk priorities.
  • Collaborate with cross-functional stakeholders to integrate risk and vendor-review requirements into operational processes.

Qualifications

  • Bachelor’s degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related field
  • 5+ years of progressively responsible experience in IT risk, cybersecurity, third-party risk management, supply-chain risk or information security governance
  • Direct experience working with GRC platforms and managing risk registers, assessment workflows, remediation, and reporting.
  • Experience with access governance and user-access review or recertification programs, particularly for vendors, contractors, or other non-employees.
  • Experience with Identity Governance and Administration (IGA) platforms.
  • Experience evaluating AI vendors, model providers, or internal AI use cases.
  • Familiarity with frameworks and standards such as SOC 2, NIST SP 800-53 Rev. 5, NIST SP 800-161r1, NIST CSF 2.0, ISO 27001/27002, ISO 27036, NIST AI RMF, and ISO/IEC 42001.
  • Experience reviewing or negotiating cybersecurity provisions, data-processing agreements, AI data-use terms, and breach-notification requirements.
  • Experience working in a regulated environment with formal third-party oversight requirements.
  • Ability to communicate complex technical and risk issues clearly to business stakeholders and executive management.
  • Strong organizational skills with the ability to independently manage multiple concurrent assessments, vendor reviews, and risk-management activities.
  • One or more of the following certifications is preferred: CRISC, CISA, CISM, CISSP, CTPRP, CTPRA, AIGP, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer.
\nCompany Description

For over 30 years, clients and candidates have entrusted AtWork to provide workforce solutions nationwide. With over 80 offices nationwide, AtWork specialize in executive, professional, commercial, and government verticals. AtWork utilizes a collaborative approach where we deliver quick, high-quality results. Our customizable service portfolio focuses on direct-hire and flexible workforce solutions. Since 1986, AtWork has continued to be an award-recognized leader in the staffing industry by clients, candidates, and industry professionals.

Company Description

For over 30 years, clients and candidates have entrusted AtWork to provide workforce solutions nationwide. With over 80 offices nationwide, AtWork specialize in executive, professional, commercial, and government verticals. AtWork utilizes a collaborative approach where we deliver quick, high-quality results. Our customizable service portfolio focuses on direct-hire and flexible workforce solutions. Since 1986, AtWork has continued to be an award-recognized leader in the staffing industry by clients, candidates, and industry professionals.