Client Assurance & TPRM Manager - Assistant Vice President chez iCapital
iCapital · Greenwich, États-Unis d'Amérique · Remote
- Lead, manage, and mentor a team of approximately five professionals supporting Third-Party Risk and Client Assurance activities.
- Provide day-to-day directions, coaching, technical guidance, and professional development to team members.
- Establish clear expectations, priorities, and accountability across both functions.
- Review team deliverables to ensure assessments and client responses are accurate, complete, consistent, and appropriately supported.
- Serve as an escalation point for complex cybersecurity risk assessments, client inquiries, vendor issues, and competing business priorities.
- Maintain the ability to work directly on assessments and client assurance requests when workload, complexity, or business needs require additional support.
- Identify opportunities to improve team processes, documentation, quality, efficiency, and scalability.
- Develop and monitor appropriate metrics and reporting to communicate workload, performance, risk trends, and program effectiveness to management.
- 10 years of relevant professional experience, with significant experience in cybersecurity, information security risk management, technology risk, third-party risk management, client assurance, or related disciplines
- Demonstrated experience completing or reviewing cybersecurity due diligence questionnaires and responding to client or customer security inquiries
- Demonstrated experience performing cybersecurity risk assessments of third-party vendors
- Prior experience leading, mentoring, or managing cybersecurity, risk, or assurance professionals
- Able to manage multiple concurrent assessments, client requests, deadlines, and priorities in a fast-paced environment
- Ability to operate effectively, including independently managing responsibilities, exercising sound judgment, influencing stakeholders, and escalating material issues appropriately
- Strong working knowledge of cybersecurity controls and concepts, including identity and access management, vulnerability and patch management, security monitoring and incident response, data protection and encryption, network and infrastructure security, cloud security, secure software development, business continuity and disaster recovery, and security governance and risk management
- Experience reviewing cybersecurity assurance documentation such as SOC 1/SOC 2 reports, ISO 27001 certifications, penetration testing reports, security policies, and related control evidence
- Strong analytical skills and the ability to distinguish meaningful cybersecurity risks from lower-impact observations
- Excellent written communication skills, including the ability to translate complex technical concepts into clear, concise language appropriate for clients, vendors, business stakeholders, and senior management
- Strong interpersonal skills and the ability to work effectively with both technical and non-technical stakeholders
- Bachelor's degree in cybersecurity, information technology, computer science, risk management, or related discipline, or equivalent professional experience is preferred and master’s degree in the same is a plus
- Relevant professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent is a plus
- Experience within financial services or another highly regulated industry is a plus
- Experience with third-party risk management, GRC, questionnaire automation, or client assurance platforms is a plus
- Experience developing metrics, reporting, procedures, and governance processes for cybersecurity risk or assurance programs is a plus