Analysis Skills, Artificial Intelligence (AI), Best Practices, Business Solutions, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Coaching, Communication Skills, CompTIA Security+, Compensation and Benefits, Computer Science, Computer Security, Detail Oriented, Documentation, English Language, Federal Laws and Regulations, ISO (International Organization for Standardization), Industry Standards, Information Technology & Information Systems, Information/Data Security (InfoSec), Internet Security, Leadership, Legal, Maintain Compliance, Material Audit, Mentoring, Metrics, Multitasking, Network Architecture/Engineering, Organizational Skills, Performance Management, Presentation/Verbal Skills, Recruiting/Staffing Agency, Regulatory Requirements, Reporting Dashboards, Risk, Risk Analysis, Risk Management, Risk Management Framework (RMF), Security Analysis, Security Architecture, Security Monitoring, State Laws and Regulations, Team Building, Team Lead/Manager, U.S. National Institute of Standards and Technology (NIST), Vendor/Supplier Evaluation, Vendor/Supplier Management, Writing Skills
Description:
CTG is seeking an experienced Vendor Security Manager to lead and enhance our client's third-party risk management program. This role is responsible for evaluating vendor cybersecurity risks, overseeing security assessments, ensuring compliance with industry standards, and partnering with internal stakeholders to strengthen the organization's overall security posture.
The ideal candidate brings expertise in cybersecurity, vendor risk management, compliance frameworks, and IT controls, along with strong leadership and communication skills.
Location: Washington, DC
Duration: Ongoing Contract
Primary Responsibilities
- Lead the organization's third-party risk management and vendor security program.
- Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory requirements.
- Guide and mentor team members responsible for vendor risk assessments and related security activities.
- Collaborate with business units, vendors, and security stakeholders to remediate identified control gaps and mitigate risk.
- Evaluate third-party security risks and provide recommendations for risk acceptance, mitigation, or remediation.
- Maintain security documentation, including risk assessments, policies, standards, metrics, and compliance records.
- Interpret cybersecurity data to identify potential security, compliance, and operational risks.
- Develop executive-level dashboards and actionable metrics to communicate vendor risk posture.
- Maintain internal procedures, documentation, and program governance materials.
- Respond promptly to vendor security inquiries, compliance requests, and audit activities.
- Support team development through coaching, training, and performance management.
Required Skills
- Strong knowledge of third-party risk management and vendor security best practices.
- Solid understanding of cybersecurity concepts, security architecture, networks, and IT infrastructure.
- Experience evaluating IT controls and conducting security risk assessments.
- Familiarity with industry security frameworks including:
- ISO 27001
- NIST Cybersecurity Framework (CSF)
- NIST 800-171
- Knowledge of vulnerability management, enterprise risk management, AI-related security considerations, and governance practices.
- Excellent analytical, organizational, and documentation skills.
- Strong verbal and written communication skills with the ability to communicate effectively across technical teams, business leaders, and executive management.
- Exceptional attention to detail and ability to manage multiple priorities simultaneously.
Required Experience
- 5–7 years of experience in cybersecurity, information security, information risk management, third-party risk management, or IT internal controls.
- Experience leading or supporting vendor security assessment programs.
- Demonstrated success evaluating security controls and recommending effective risk mitigation strategies.
- Experience producing compliance documentation, metrics, executive reporting, and audit support materials.
- Prior leadership or team management experience is preferred.
Education
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Business, or a related discipline preferred.
- Industry certifications such as CISSP, CISM, CRISC, CISA, or Security+ are highly desirable.
Excellent verbal and written English communication skills and the ability to interact professionally with a diverse group are required.
CTG does not accept unsolicited resumes from headhunters, recruitment agencies, or fee based recruitment services for this role.
To Apply:
To be considered, please apply directly to this requisition using the link provided. Kindly forward this to any other interested parties. Thank you!
The expected base salary for this position ranges from $58.00 to $72.00/hour. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, market factors, and where applicable, licensure or certifications obtained. In addition to salary, a competitive benefit package is also offered.
About Us:
CTG, a Cegeka company, delivers IT and business solutions that enhance clients’ digital agility, empowering them to seize new opportunities and overcome any challenge. Backed by more than 60 years’ experience and a commitment to being a reliable, results-driven partner, we work shoulder to shoulder with clients to shape digital together. Our vision is to be an indispensable partner to our clients and the preferred career destination for digital and technology experts. With more than 9,000 team members in over 15 countries, we combine global expertise with local insight to deliver innovative solutions. We operate across the Americas, Europe, and India, working with over 3,000 clients in many of today's highest-growth industries.
Together, we shape what’s next—working shoulder to shoulder to deliver impactful solutions for our clients and society. Our culture is built by the people who work at CTG, the values we hold, and the actions we take. It's a living, breathing thing that is renewed every day through the ways we engage with each other, our clients, and our communities. At CTG, you’ll find a workplace where you are encouraged to grow, supported in your ambitions, and empowered to shape your own career journey. For more information, visit www.ctg.com.
CTG will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of all applicable local, state, and federal laws.
CTG is an Equal Opportunity Employer. CTG will assure equal opportunity and consideration to all applicants and employees in recruitment, selection, placement, training, benefits, compensation, promotion, transfer, and release of individuals without regard to race, creed, religion, color, national origin, sex, sexual orientation, gender identity and gender expression, age, disability, marital or veteran status, citizenship status, or any other discriminatory factors as required by law. CTG is fully committed to promoting employment opportunities for members of protected classes.
C
Computer Task Group, Inc
CTG (NASDAQ: CTG) provides industry-specific IT services and solutions that address the business needs and challenges of clients in high-growth industries in North America and Western Europe. CTG also provides strategic staffing services for major technology companies and large corporations. Backed by more than 50 years of experience and proprietary methodologies, CTG has a proven track record of reliably delivering high-value, industry-specific staffing services and solutions to its clients. CTG has operations in North America, Western Europe, and India.
CTG's greatest asset is its people, and as such, we are committed to providing employees programs and processes to support their performance, hone their skills, and advance in their careers. This commitment is reflected by CTG being named a Best Places to Work in Healthcare company by Modern Healthcare (2013-2016) in North America, and a Best Workplace in the United Kingdom (2013), Belgium (since 2007), and Luxembourg (since 2011).
CTG will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of all applicable local, state, and federal laws.
CTG is an Equal Opportunity/Affirmative Action Employer and strong advocate of workforce diversity. Minority/Female/Sexual Orientation/Gender Identity/Disability/Veteran.