About this role
Make a meaningful impact by strengthening supplier risk outcomes through high-quality issue management and evidence validation. Join a team that values collaboration, continuous learning, and practical problem solving. Partner with stakeholders across the organization to help raise security and control standards for third-party relationships.
Job summary
As an Issue Management - Information Security Associate in Supplier Issue Management, you support robust supplier oversight by reviewing assessment findings and validating remediation evidence. You will work closely with internal stakeholders and suppliers to drive timely action plans, risk decisions, and quality outcomes. Your work helps reduce exposure from third-party relationships and promotes consistent risk management practices.
Job responsibilities
- Review supplier assessment findings for accuracy, completeness, and alignment to organizational guidance
- Validate closure evidence submitted by suppliers, including policies, procedures, and supporting documentation
- Respond to issue management questions and provide clear guidance to internal stakeholders
- Advise business partners on remediation approaches, including action plans and risk acceptance considerations
- Engage with critical and high-risk suppliers to accelerate remediation and monitor progress
- Coordinate with business partners to drive timely completion of remediation activities and risk acceptances
- Manage the issue lifecycle, including creation, updates, extensions, and closure validation
- Identify process improvement opportunities to strengthen issue quality, consistency, and turnaround times
- Share best practices and lessons learned to support internal education and continuous improvement
- Maintain working knowledge of supplier assessment workflows, controls expectations, and documentation standards
- Communicate status, themes, and material risks clearly to senior stakeholders across business groups
Required qualifications, capabilities and skills
- Experience in information security, risk management, supplier management, information technology, or cybersecurity (years of experience: TBD if required)
- Knowledge of supplier information technology and operational risk concepts, including control expectations and governance practices
- Demonstrated ability to review documentation and evidence with strong attention to detail
- Demonstrated ability to communicate clearly in writing and verbally with senior stakeholders
- Ability to collaborate effectively across multiple business groups and stakeholder teams
- Ability to manage multiple tasks and priorities in a time-sensitive environment
- Ability to evaluate issue remediation artifacts for sufficiency against defined requirements
- Demonstrated problem-solving skills, including identifying root causes and practical remediation paths
- Experience identifying and implementing process improvements to increase quality and efficiency
- Ability to work effectively in a team-oriented, collaborative environment
Preferred qualifications, capabilities and skills
- Certification in Information Systems Audit or Risk and Information Systems Control (or equivalent)
- Experience supporting internal education and best-practice sharing initiatives
- Familiarity with supplier risk assessment and issue management processes
- Experience validating closure evidence for compliance to defined standards and requirements
- Experience engaging with a wide range of stakeholders across functions and seniority levels
- Knowledge of global supplier management or third-party risk management standards
- Demonstrated commitment to continuous learning and professional development