Service Manager – Supplier Security Due Diligence & Monitoring Service

AllstateUSA - NC (Remote), NC
$120,000 - $193,725Remote

About The Position

The Supplier Security Due Diligence & Monitoring Service operates at the intersection of Cybersecurity, Legal, Procurement, Supplier Management, and Enterprise Risk Management. The team is responsible for helping the enterprise navigate information security requirements within supplier contracts by providing first-line support during contract negotiations and redline reviews. The Service Manager leads the specialized service responsible for translating supplier risk assessments into practical contractual security positions. The team advises stakeholders on acceptable contractual outcomes, applies approved fallback language, documents security control exceptions, and ensures non-standard contractual positions are reviewed through appropriate governance channels. This service plays a critical role in balancing supplier risk management with business enablement while maintaining alignment with enterprise risk expectations.

Requirements

  • 7+ years of experience in information security, technology risk, third-party risk management, supplier risk management, governance, contracting, procurement, or related disciplines.
  • 3+ years of leadership experience managing teams, services, programs, or operational functions.
  • Experience evaluating cybersecurity and technology risks and applying sound risk-based decision-making principles.
  • Strong understanding of supplier risk management, security controls, and governance practices.
  • Experience working across legal, procurement, business, security, and risk management functions.
  • Excellent written, verbal, stakeholder management, and executive communication skills.

Nice To Haves

  • Experience supporting supplier contract negotiations involving cybersecurity and privacy requirements.
  • Knowledge of third-party risk management programs and supplier security assessment methodologies.
  • Experience with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, NIST 800-53, ISO 27001, CIS Controls, and SOC reporting.
  • Experience with enterprise risk management, governance, and risk acceptance processes.
  • Professional certifications such as CISSP, CISM, CRISC, ITIL, PMP, or related credentials.
  • Experience building, scaling, or transforming operational services and governance functions.

Responsibilities

  • Lead the Supplier Security Due Diligence & Monitoring Service and oversee day-to-day service delivery.
  • Manage and develop a team responsible for supplier security contracting support and risk-based decision making.
  • Review and interpret supplier security assessment outcomes and monitoring results to guide contractual negotiations.
  • Provide guidance on acceptable contractual security positions, fallback language, compensating controls, and alternative risk mitigation approaches.
  • Ensure consistent application of enterprise security requirements across supplier agreements.
  • Oversee documentation and tracking of contractual exceptions, deviations, and risk accommodations.
  • Escalate contractual positions that exceed established risk tolerances through appropriate governance and risk acceptance processes.
  • Partner closely with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier issues.
  • Establish and maintain operational metrics, service-level objectives, reporting, and quality management practices.
  • Lead continuous improvement efforts designed to improve scalability, consistency, and stakeholder experience.

Benefits

  • Comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse.
  • Monthly connectivity reimbursement for employees eligible to work from home.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service