- Company Name
- Chan Zuckerberg Initiative
- Job Title
- Program Manager, Third Party Security
- Job Description
-
**Job title**
Program Manager, Third Party Security
**Role Summary**
Oversee and advance the Third Party Security program, ensuring vendor risk assessments, remediation and governance meet organizational standards. Lead cross‑functional initiatives, document processes, and mentor junior assessors to sustain a robust third‑party security posture.
**Expectations**
- Deliver end‑to‑end project management for high‑priority security initiatives.
- Maintain comprehensive program documentation and procedures.
- Coordinate vendor assessments, gather evidence, and drive remediation.
- Act as escalation point and SME for risk findings.
- Build and sustain partnership relationships with Legal, Privacy, Security, and internal stakeholders.
**Key Responsibilities**
- Manage project timelines for tool integrations, system builds, data migrations, and new service launches.
- Develop, update, and circulate program documentation (procedures, templates, training materials).
- Execute security assessments of new or existing vendors, collecting evidence and reviewing controls.
- Identify risks, recommend mitigation controls, and oversee remediation efforts.
- Mentor junior assessors on risk evaluation and evidence collection processes.
- Represent the organization’s security commitment in industry benchmarks and best‑practice discussions.
- Provide clear, effective communication to both technical and non‑technical stakeholders.
- Adapt priorities in a fast‑paced, service‑oriented environment.
**Required Skills**
- 5+ years in third‑party security, risk management, audit, or related field.
- Proven experience managing programs or multi‑workstream projects to completion.
- Strong analytical, problem‑solving, and attention‑to‑detail abilities.
- Ability to conduct risk assessments and furnish practical control guidance.
- Effective written and verbal communication for diverse audiences.
- Proactive, accountable, and collaborative mindset.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Risk Management, Business Administration, or equivalent.
- Relevant security certifications preferred: CISSP, CISM, CRISC, or GRC‑specific credentials.
Redwood city, United states
Hybrid
Mid level
17-03-2026