Jobs and Careers
ID

Senior Manager, Third Party Risk

ID.me
United Statesfull_timeVerifiedPosted 13 Mar 2024
💰 $196,924/yr($158,926/yr$196,924/yr)

About the role

Company Overview

ID.me is a high-growth enterprise software company that simplifies how people prove and share their identity online.  The company empowers people to control their data through a portable and trusted login, which means they don’t need to create a new password when visiting sites that have the ID.me button.  ID.me’s digital identity network has over 117 million registered members, and is used by fourteen federal agencies, agencies in 30 states and over 600 corporations for secure identity proofing and verification.

ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. In addition to helping people control their credentials and data, the company’s “No Identity Left Behind” initiative strives to expand digital access and inclusion for all people. The company offers multiple pathways to identity verification – online self-serve, live video chat agents, and in person.  ID.me is passionate about building a robust identity network that does not compromise access for traditionally underserved groups.

ID.me has received numerous awards including Deloitte’s 2023 Technology Fast 500, Washington Business Journal’s Fastest Growing Companies, Entrepreneur Magazine’s 100 Brilliant Companies and Wall Street Journal’s Startup of the Year finalist.  In recent quarters, ID.me announced it raised $132 million in Series D funding, led by Viking Global Investors with participation from CapitalG, Morgan Stanley Counterpoint, FTV Capital, PSP Growth, Auctus Investment Group, Moonshots Capital, and Scout Ventures. ID.me’s most recent round brings the total investment in ID.me to over $275 million since its founding in 2010.

Role Overview

The ID.me security team is looking for a proven Senior Manager of Third Party Risk. As an individual contributor, the Senior Manager will help drive and implement the risk management practices to maintain rigor over supply chain security operations. Activities include roadmap design, control design, assessment operations, and key metrics. This role will collaborate with teams across the company to assess and manage risks when using third and fourth parties. This position will perform critical operations as part of procurement and customer assurance. 

This is a multifaceted role that combines project management, delivery management, and systems analysis responsibilities. The role embodies strategic thinking with tactical execution to enhance the customer experience, business resiliency, and promote a rationalized technology footprint. 

Responsibilities

  • Work cross functionally with Security, IT, Engineering, Product, and Finance to evaluate vendors and assess supply chain risks. 
  • Keep detailed assessment records and ERM control mappings to vendor operations in a high volume environment
  • Own responding to customer assurance requests such as security questionnaires, security reviews and similar engagements.
  • Performing control based assessments of vendor documentation (SOC 2) or industry standard customer questionnaire (CAIQ, SIG CORE or SIG LITE)
  • Understanding of MITRE System of Trust (SoT) Framework
  • Direct enablement of Sales opportunities by participating in  RFP, RFI, contracts and other sales opportunity deliverables
  • Run engagements with customer auditors educate and demonstrate compliance
  • Communicate effectively and proactively with management ideas and recommendations for optimizing business operations, resources and capacity to meet internal and external compliance goals
  • Develop and propose key program performance and risk metrics
  • Create and mature  procedural documentation, including training materials or process documentation 

Qualifications

  • BA or BS in a technical field or equivalent experience
  • 5+ years of program management experience 
  • 3+ years of experience for end-to-end management of third party risk programs 
  • 3+ years of experience with major compliance audits (FedRAMP, SOC 2, HIPAA, etc.)
  • Owner and builder of risk management processes. Ability to own finding and fixing issues with no supervision.
  • Familiar with SaaS product design and cloud architecture.
  • Deep understanding of common business processes and functions in enterprise environments
  • Prior experience automating audit evidence collection 
  • Excellent verbal, written and interpersonal communication skills with both technical and non-technical audiences
  • CCSP, CISSP, CISA, and similar certifications are a plus 

#LI-JS1

The annual base salary listed below for this role is based on experience, skills, education, relevant training

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ID.me

View company profile →