Manager - IT Risk Management
StericycleAbout the role
About Us:
At Stericycle, we deliver solutions and drive innovations that protect the environment, people, and public health. This includes working to create a more sustainable, shared future. Our innovative solutions make a difference in people's lives, communities, and our planet by protecting their health and well-being. Change your career. Change your world. Join Stericycle and help protect health and well-being in a safe, responsible, and sustainable way. We protect what matters.
Position Purpose:
The Manager - IT Risk Management leads the team responsible for identifying, measuring, reporting, and treating IT and cybersecurity risks both internally within Stericycle and externally with partners, vendors, and customers. This position will work across a diverse landscape of Stericycle, its customers, and 3rd parties to mature and operationalize global IT risk management capabilities. The qualified individual will act as an “IT Risk Ambassador” across the company, consult to business stakeholders, and advise on IT and Cyber risks matters broadly. This role will report to the Director – Governance, Risk, & Compliance and will actively collaborate with Legal, IT, HR, Commercial, and Operations functions around the world.
Key Job Activities:
- Recruit, manage, retain, and mentor a high performing team of IT risk professionals.
- Build relationships, advocate, and consult to different Stericycle functional and business stakeholder groups on areas of cybersecurity risk.
- Lead development of IT and cyber risk management strategies, roadmaps, and project portfolio plans.
- Lead development and maintenance of Stericycle IT security policies, procedures, and standards.
- Lead global cybersecurity awareness and training programs.
- Lead global Cybersecurity Risk Management Steering Committee function.
- Lead security assessment program and perform internal and external security assessments.
- Define, manage, and lead risk intake, risk register, risk treatment, and risk reporting process.
- Mature global cyber risk management processes and capabilities.
- Lead response activities for customer cyber due diligence / questionnaire requests.
- Develop and lead vender cyber risk management capability.
- Partner with legal and commercial teams in support of customer and vendor contract reviews.
- Develop and mature security metric reporting and dashboarding capabilities.
- Lead implementation and operationalization of ServiceNow Risk Management platform.
- Provide project management leadership and discipline supporting security related transformation initiatives to successfully deliver on time and within budget.
- Assist with incident response or event management as needed. This may include occasional involvement outside of regular work hours, and responsiveness is expected.
- Perform other duties and responsibilities, as assigned.
Education:
Experience (North America):
- 8+ years’ experience in cybersecurity, including governance, assessments, 3rd party risk, compliance, governance, and IT/cyber risk management.
- Knowledge and demonstrable experience utilizing / assessing against common security and controls frameworks: NIST CSF, NIST 800-53, NIST 800-37, ISO27001 (or equivalent).
- Knowledge and demonstrable experience utilizing common risk management tools: Archer, ServiceNow IRM, MetricStream, or similar.
- Experience leading risk management processes including risk register, treatment, and reporting.
- Experience (5+ years) performing cyber risk assessments, risk quantification, and risk prioritization.
- Demonstrable experience in establishing and operationalizing security metric and risk reporting programs.
- Experience (3+ years) performing security contract reviews (redlining) or other similar function.
- Great communicator that can articulate complex risk concepts to both technical and non-technical audiences.
- Great listener that can capture and understand stakeholder requirements to translate into security controls.
- Experience and understanding (3+ years) of audit or compliance.
- Experience in a risk lead capacity, providing guidance and direction to team members on risk and security issues.
- Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively.
- Bachelors or equivalent.
- 10+ Years of Experience in Information Technology preferably in Cybersecurity
Certifications and/or Licenses:
Benefits:
Stericycle currently offers its employees the option to participate in a full range of benefits, including a health care program which includes medical, dental, vision and prescription coverage, healthcare a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s