The Impact You’ll Make in this Role
In this role, you will be responsible for overseeing the managed services provider (MSP) that conducts day-to-day third-party cybersecurity risk assessments, ensuring that our organization maintains a robust and resilient cybersecurity posture. Your oversight will be crucial in evaluating the effectiveness of the MSP's activities, ensuring that they thoroughly assess the security practices of our third-party vendors, identify potential vulnerabilities, and implement appropriate risk mitigation measures. By closely monitoring the MSP's performance, you will ensure that their assessments are accurate, comprehensive, and aligned with our organization's security standards and regulatory requirements. Through your diligent oversight and strategic guidance, you will play a key role in protecting our organization's data and systems from external threats, thereby safeguarding our business operations and maintaining the trust of our customers and partners.
Here, you will make an impact by:
- Oversee the managed services relationship which is responsible for conducting third-part cybersecurity risk assessments
- Review and approve the quality of vendor risk assessments conducted by managed services, ensuring they meet organizational standards
- Monitor the managed services provider’s performance, ensuring adherence to SLAs and agreed KPIs
- Conduct regular service delivery reviews, providing feedback to improve their performance and efficiency
- Broker with MSs third party security risk management support to businessdepartment/relationshipowner when forming new client relationships or when engaging in new products/services from existing clients
- Collaborate with MSs to address identified risks and ensure timely implementation of remediation plans
- Support escalation from MSs when risk decisions needs to be raised to 3M
- Work with executive leadership to present risk findings from metrics provided by MSs monthly through CISO dashboard
- Partner with Procurement on net new vendor requests/renewals
Your Skills and Expertise:
To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications:
- Bachelor's degree or higher (completed and verified prior to start)
- Ten (10) years of experience in information technology in a private, public, government or military environment
Additional qualifications that could help you succeed even further in this role include:
- Analytical Skills: Excellent analytical and problem-solving skills to evaluate risk assessment findings, identify vulnerabilities, and develop effective mitigation strategies.
- Communication Skills: Strong written and verbal communication skills to effectively convey complex cybersecurity issues and risk assessment results to both technical and non-technical stakeholders.
- Project Management: Proficiency in project management, including the ability to oversee multiple assessments, track progress, and ensure timely completion of remediation activities.
- Collaboration: Ability to work collaboratively with internal teams, including IT, legal, compliance, and business units, to ensure a cohesive approach to cybersecurity risk management.
- Attention to Detail: High level of attention to detail to ensure accuracy and thoroughness in risk assessments and reporting.
- Cybersecurity Knowledge: In-depth understanding of cybersecurity principles, practices, and frameworks, including risk assessment methodologies and threat management.
- Third-Party Risk Management: Proven experience in managing third-party risk, including conducting and overseeing third-party cybersecurity risk assessments.
- Regulatory Compliance: Familiarity with relevant regulatory requirements and industry standards (e.g., GDPR, CCPA, ISO 27001, NIST) and the ability to ensure compliance.
- Vendor Management: Strong experience in managing relationships with managed services providers (MSPs) and other third-party vendors, ensuring service quality and adherence to contractual obligations.
- Continuous Improvement: Commitment to staying current with the latest cybersecurity trends, threats, and best practices, and continuously improving the organization's risk management processes.
Work location:
- Work Your Way Eligible (hybrid) – Minneapolis & Austin
Travel: In-OfficeTuesday/Wednesday/Thursday
Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.
Please access the linked document by clicking select the country where you are applying for employment, and review. Before submitting your application, you will be asked to confirm your agreement with the terms.