Guild Mortgage Logo

Guild Mortgage

Third-Party Security Manager

Posted 24 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
95K-136K Annually
Senior level
Remote
Hiring Remotely in United States
95K-136K Annually
Senior level
Leads and matures the organization’s third-party risk management program, including vendor onboarding, risk assessments, continuous monitoring, remediation, contract security requirements, regulatory alignment, reporting, and executive risk guidance. Partners with Information Security, Legal, Compliance, Procurement, Privacy, and business teams to manage vendor security, privacy, operational, continuity, and concentration risks.
The summary above was generated by AI

Guild Mortgage Company, closing loans and opening doors since 1960. As a mortgage banking firm we are dedicated to serving the home owner/buyer. Our goal is to provide affordable home financing for our customers, utilizing the best terms available while providing a level of professionalism and service unsurpassed in the lending industry.

Position Summary

The Third-Party Security Manager is responsible for leading and maturing the organization's Third-Party Risk Management (TPRM) program. This role oversees the identification, assessment, monitoring, and mitigation of risks associated with vendors, suppliers, service providers, business partners, and other third parties. The position works closely with Information Security, Legal, Compliance, Procurement, Privacy, Enterprise Risk Management, and business stakeholders to ensure third-party relationships align with organizational risk tolerance, regulatory requirements, and security standards. The Third-Party Security Manager possesses strong cybersecurity, risk management, and vendor governance experience with the ability to communicate risk effectively to both technical and executive audiences.

Compensation 

This role is an exempt position with a Targeted Salary Range of $94,882 to $136,097 annually.

Compensation at Guild is influenced by a wide array of factors including but not limited to local and federal minimum wage requirements, education, level of experience, and applicant’s geographical location.

Essential Functions

  • Develop, maintain, and continuously improve the Third-Party Risk Management (TPRM) framework, policies, standards, and procedures.
  • Establish risk-based processes for onboarding, reviewing, monitoring, and offboarding third parties.
  • Define vendor risk assessment methodologies and risk scoring criteria.
  • Ensure alignment with regulatory requirements and industry frameworks including NIST, SOC 2, ISO 27001, FFIEC, GLBA, PCI-DSS, and applicable privacy regulations.
  • Conduct security, privacy, operational, compliance, and business continuity risk assessments for new and existing vendors.
  • Review vendor security documentation including: SOC 1 and SOC 2 reports, ISO certifications, Penetration test reports, Vulnerability management reports, Security questionnaires, Business continuity and disaster recovery plans,
  • Identify control gaps and work with vendors and stakeholders on remediation plans.
  • Evaluate fourth-party dependencies and concentration risks.
  • Maintain an inventory of third-party relationships and associated risk ratings.
  • Develop continuous monitoring processes for critical and high-risk vendors.
  • Monitor external security ratings, threat intelligence, breach activity, financial condition, and compliance status of vendors.
  • Track remediation activities and ensure timely closure of identified risks.
  • Facilitate periodic vendor reviews and risk re-assessments.
  • Partner with Procurement, Legal, Privacy, Compliance, Business Owners, and Information Security teams during vendor selection and contract negotiations.
  • Provide risk guidance to business leaders regarding vendor onboarding and ongoing risk management decisions.
  • Present vendor risk findings and recommendations to leadership committees, risk committees, and executive management.
  • Support internal and external audits related to vendor management controls.
  • Collaborate with Legal and Procurement to establish and maintain security and privacy contractual requirements.
  • Review and recommend contract language related to: Information security controls, Data protection requirements, Breach notification obligations, Audit rights, Business continuity requirements, Regulatory compliance obligations.
  • Ensure vendor agreements include appropriate security, privacy, and reporting requirements.
  • Develop and maintain TPRM dashboards, KPIs, and executive reporting.
  • Track vendor assessment volumes, remediation status, risk trends, and program maturity metrics.
  • Provide regular reporting to Information Security leadership, Enterprise Risk Management, and audit committees.
  • Support risk quantification and business impact analysis efforts.

Qualifications

  • Bachelors Degree directly related to the position or equivalent, preferred.
  • Minimum five years' experience.
  • Minimum three years supervisory or leadership experience
  • Excellent verbal and written communication skills required.
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment required.
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required.
  • Commitment to company values.
  • Customer Service - Proactive attention to each person
  • Integrity - Do and say what's right
  • Respect - Treat others with dignity
  • Collaboration - Listen and work together
  • Learning - Seek knowledge and strive for improvement
  • Excellence – Deliver the unexpected

Supervision

  • Job Scope: Responsible for understanding the department/functional area objectives and goals and how own job contributes to achievement of these goals; may recommend changes and enhancements based on analysis and evaluation of circumstances.
  • Complexity: General precedents may exist for most problems; conducts independent research/analysis to identify the appropriate approach.
  • Impact: Decisions and actions primarily impact own work with limited impact on peers in their area, contributes as team member rather than leader.
  • Interaction/Supervision: Acts as a mentor/guide to less experienced professional contributor staff in a similar role; works independently and only under general direction; guided by professional standards, desired outcomes, and project plan specifications.

Requirements

Physical: Work is primarily sedentary; mobility in an office setting.

Manual Dexterity: Frequent use of computer keyboard and mouse.


Audio/Visual: Ability to accurately interpret sounds and associated meanings at a volume consistent with interpersonal conversation. Regularly required to accurately perceive, distinguish and interpret information received visually and through audio, e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media.


Environmental:  Office environment – moderate noise, no substantial exposure to adverse environmental conditions.

Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow. This role requires effective adaptation to workplace stressors, including customer service complaints, security responsibilities, and competing priorities. Must be able to adhere to process protocol. Must be able to apply established protocols in a timely manner.

Schedules: Work is primarily performed during the business week, Monday - Friday.

Travel: 5% or less

Guild offers a pleasant work environment, competitive compensation and excellent benefits package; including medical, dental, vision, life insurance, AD&D, LTD and 401(k) with employer match.

Guild Mortgage Company is an Equal Opportunity Employer.

REQ#: THIRD018481

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Similar Jobs

An Hour Ago
Remote
USA
330K-500K Annually
Senior level
330K-500K Annually
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
Leads the architecture, development, integration, simulation, testing, and fielding of advanced autonomy capabilities for aerospace and defense systems. Responsibilities include radar and RF signal processing, sensing, perception, guidance, navigation, control, sensor fusion, electronic protection, vehicle simulation, requirements development, hardware integration, technical reviews, customer engagement, and mentoring engineering teams.
Top Skills: CC++DspElectronic WarfareEmbedded ComputingHardware-In-The-Loop SimulationMatlabMonte Carlo AnalysisPythonRadarRf SensingSensor FusionSignal ProcessingSix-Degree-Of-Freedom SimulationSoftware-In-The-Loop Simulation
An Hour Ago
In-Office or Remote
United States
133K-284K Annually
Senior level
133K-284K Annually
Senior level
Automotive
Design, develop, operate, and support mission-critical cloud-native software services for Ford’s connected vehicle platform. Lead architecture and delivery of distributed microservices, improve reliability, observability, performance, security, and scalability, and manage incident response. Provide technical leadership through design reviews, standards, mentoring, roadmap influence, and cross-functional collaboration with product, operations, and platform teams.
Top Skills: Amazon EksApache KafkaArgo CdAWSCi/CdConcourseDatadogDynatraceFossaGitGoogle Cloud PlatformGrafanaGrpcJavaJSONKubernetesOpenapiOpentelemetryPagerdutyPostgresPrometheusRestSonarqubeSpring BootSwaggerTest-Driven DevelopmentTykVictoriametrics
2 Hours Ago
Remote or Hybrid
United States
Mid level
Mid level
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Own the AutoZone national account and GM ACDelco business results by negotiating vendor agreements, driving sales and margin growth, expanding product assortments, managing pricing and promotions, coordinating supply forecasts, resolving order and claims issues, and leading customer business reviews. Analyze sales, inventory, margin, and customer data to recommend actions while coordinating cross-functional teams across Sales, Finance, Supply Chain, Product, Cataloging, and Marketing.
Top Skills: Google WorkspaceImsMicrosoft Suite

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account