Strong understanding of information security risk management methodologies, cybersecurity principles, and recognized frameworks such as ISO 27001, NIST, COBIT, and industry best practices, including security considerations for cloud environments, networks, services, products, and operations. Conduct comprehensive cybersecurity assessments of new and existing third-party suppliers, evaluating security controls, policies, processes, and overall risk posture; analyze findings to identify vulnerabilities, control gaps, and potential business risks.