Security and Compliance Manager (third Party Risk)

Box Box · Enterprise · Warsaw, Poland · Compliance & Risk

This role is for a Security and Compliance Manager focused on Third Party Risk Management (TPRM) at Box, an enterprise AI company. The manager will assess vendor security and compliance, mitigate risks, and manage TPRM tools. While the company is AI-first and mentions increasing AI adoption, the core responsibilities are in risk management and compliance, not direct AI/ML model development or deployment.

What you'd actually do

  1. Deliver third-party risk assessments of Box's suppliers: assess controls, processes, and/or systems to identify risk, develop plans to mitigate against risks, and oversee the remediation plan to completion.
  2. Interact with suppliers and internal stakeholders to understand the business objectives and gather info needed for security and compliance reviews, validations, and audits.
  3. Manage and administer tools for performing supplier security and compliance reviews and risk mitigation. This includes data analytics and reporting on Third Party Risk
  4. Drive initiatives for strategic transformation and operational improvement

Skills

Required

  • Information Security
  • Governance, Risk and Compliance (GRC)
  • Audit
  • Third Party Risk Management
  • SOC 2
  • ISO27001
  • NIST
  • PCI
  • English proficiency
  • written and oral communication
  • organization
  • attention to detail

Nice to have

  • Experience in Third Party Risk Management is preferred but not required.

What the JD emphasized

  • security and compliance posture
  • third-party risk
  • security and compliance reviews
  • risk mitigation
  • Information Security
  • Governance, Risk and Compliance (GRC)
  • Third Party Risk Management
  • security and compliance certifications and frameworks
  • SOC 2
  • ISO27001
  • NIST
  • PCI