Manager, Security & Governance The Manager of Security & Governance will lead our security and governance program, owning cybersecurity operations, risk management, compliance, business continuity/disaster recovery (BCDR), third-party risk management (TPRM) and AI governance.
This role consolidates security accountability across cyber operations, audit readiness, security policy, incident response, and vendor risk governance, including AI/third party risk analysis, contractual data governance, and vendor risk analytics.
The Manager, Security & Governance will will work against NIST CSF 2.0 and drive The Institutes MDR partnership and security tool roadmap, embed risk-tiered gates into our SDLC 2.0 process, and own AI governance, setting guardrails for agentic development and our citizen development program.
What You'll Do:- Own the enterprise security program aligned to the most current NIST CSF, including maturity assessment, remediation of unimplemented controls, and continuous improvement of the Recover function.
- Oversee daily cybersecurity operations, including the MDR/agentic SOC relationship, alert triage and escalation, threat intelligence, and vulnerability management with tracked remediation.
- Manage the investigation of security breaches and incidents end to end, ensuring complete incident response documentation, after-action reviews, and improvement actions.
- Own the Third-Party Risk Management (TPRM) program end to end with full, non-delegable accountability: maintain vendor tier classifications and risk profiles; review and distribute security questionnaires; collect and analyze SOC reports, cyber insurance documentation, and compliance artifacts; track vendor remediation items to closure; and proactively research vendor markets to surface emerging risks, trends, and current events.
- Own AI and third-party risk analysis: conduct AI-focused vendor risk assessments covering model usage, training data sources, and data retention practices; maintain the AI risk scoring methodology; assess model risk exposure (bias, explainability, regulatory considerations); detect and mitigate Shadow AI usage across the organization; track vendor data exposure and data-sharing pathways; and operate TPRM/AI governance platform workflows (e.g., OneTrust).
- Own contractual data governance risk review: evaluate AI/data-related clauses in vendor contracts - data ownership, data residency, model training rights, sub-processor disclosures, and AI indemnification and liability language - in partnership with General Counsel; strengthen AI and data protection contractual standards; and provide risk review during vendor onboarding and renewals coordinated by the Director, Portfolio.
- Provide vendor risk analytics and executive reporting: risk dashboards, AI vendor exposure, data risk trends, model risk concentration, and systemic risk patterns across vendor categories; assess overlapping AI tool capabilities and risk duplication in partnership with the Director, Portfolio, who owns cost and commercial rationalization.
- Own the security tool portfolio strategy and consolidation roadmap (endpoint, DSPM, data protection, backup/recovery, SIEM, MDR, and Microsoft security stack), including lifecycle-forcing decisions such as on-premises end-of-life transitions.
- Own BCDR: maintain, test, and continuously improve business continuity and disaster recovery plans, including backup managed-service oversight and recovery validation.
- Manage audits, reviews, and assessments of information systems on the schedule defined in the Information Security Policy; manage cross-functional teams through external audits and maintain compliance documentation and evidence; manage assessor independence, ensuring assessment and remediation vendors are appropriately separated.
- Develop, implement, and maintain security policies, procedures, and guidelines according to NIST best practices, including the AI notetaker policy and applicable consent statutes.
- Own AI governance operations: MCP allowlists, coding-standard security requirements, citizen developer guardrails, app admin-consent review, and the risk register for AI-enabled tools.
- Develop and grow the Risk Steward capability within SDLC 2.0, staffing risk review at risk-tiered delivery gates in partnership with the engineering Directors.
- Implement security awareness and training programs to educate employees about information security best practices.
- Oversee the technical risk management process and prepare cybersecurity and third-party risk reporting for the Executive Committee and Board.
- Perform employee evaluations and reviews for direct reports, documenting as necessary.
What We're Looking For:- Bachelor's degree in computer science, information security, or equivalent experience.
- Minimum 8 years of information security experience, including security operations and incident response.
- Minimum 3 years leading a security or governance function or team.
- Working knowledge of NIST CSF, audit and compliance management, BCDR, and cloud security (AWS and Microsoft stack).
- Demonstrated experience with third-party risk management, including vendor risk assessment, security questionnaire processes, SOC report analysis, and contract risk review; familiarity with TPRM/governance platforms (e.g., OneTrust) preferred.
- Effective hands-on use of LLM-based tools to manage the research and analysis demands of the role.
- Experience governing AI/ML or agentic technologies preferred; relevant certifications (e.g., CISSP, CISM, CRISC) preferred.
Key Competencies: - Risk Management and Governance
- Third-Party and AI Risk Analysis
- Decision Making
- Leadership
- Communication
- Analytical Thinking
- Relationship Building
- Supplier and Partner Management
- Enterprise Perspective
- Technical Knowledge (Security Architecture and Operations)
- Executive-Ready Reporting
- Employee Development
- Strive to reflect our five cultural values in all efforts: Put the Customer First, Do What You Say, Work Together, Be Innovative and Do the Right Thing.
The Best Part? The Benefits! To enforce the importance of work-life balance, employees enjoy excellent benefits, including:
- 401(k) plan with company contribution up to 16%
- Generous time off package that includes paid vacation, personal, sick, and holidays
- Paid maternity and parental leave
- Tuition reimbursement
- Medical, dental, vision, and prescription coverage
- On our Malvern campus: Free lunch every day when working on campus, onsite fitness center, and a beautiful 1.25-mile walking path!