GRC CareersConnecting Talent and Trust. Post a Job Log in

JobsFloridaSt. PetersburgSupervisor, IT Security Vendor Risk Management

Supervisor, IT Security Vendor Risk Management

Raymond James
Third-Party RiskHybridFull-timeSt. Petersburg, FL

Raymond James is hiring for the role of Supervisor, IT Security Vendor Risk Management, St. Petersburg, FL (Hybrid). This is a Third-Party Risk role in the governance, risk, and compliance field. Review the full details below and apply directly with Raymond James.

Organization: Raymond JamesLocation: St. Petersburg, FLWorkplace: HybridFocus: Third-Party RiskPosted: Jul 31, 2026
Raymond James is hiring for this Third-Party Risk role in St. Petersburg, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC roles in St. Petersburg →

Job Description Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and risk‑based prioritization. Dedicated supervision will drive measurable time reduction through operational efficiencies, reduce rework and process overhead, and enable senior leaders to focus on program strategy and regulatory readiness. Job Description This position follows our hybrid workstyle policy: Expected to be in a Raymond James office location a minimum of 10-12 days a month. Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future. Technical Skills/Experience: Foundational experience in IT security, vendor risk management, third party risk, or similar risk functions Working knowledge of core information security and technology risk domains sufficient to review assessments, identify gaps, and escalate complex issues appropriately. Familiarity with internal policies, standards, and common regulatory expectations impacting third party risk management, with the ability to follow established procedures and recognize potential non compliance trends for escalation. Ability to apply basic risk concepts (inherent risk, control effectiveness, residual risk) to support consistent risk ratings and clear, defensible assessment outcomes. Experience reviewing and validating the work of others for completeness, accuracy, and adherence to standards, and providing constructive feedback to improve assessment quality and consistency. Developing people leadership skills, including task prioritization, workload coordination, coaching junior team members, and tracking team deliverables against defined timelines and objectives. Strong written and verbal communication skills, with the ability to summarize assessment results and risks in clear, business appropriate language for stakeholders and management. Responsibilities: Leads a team responsible for conducting risk based due diligence assessments for third party supplier engagements Oversees the evaluation of information security and technology risks associated with vendors, products, and services Ensures vendor risk outcomes align with the firm’s risk appetite and regulatory obligations Accountable for the quality, consistency, and timeliness of vendor risk assessments Translates technical and regulatory findings into clear risk conclusions and actionable recommendations Provides guidance and risk insights to business and technology stakeholders Partners closely with Procurement, Legal, IT, and business owners throughout the vendor lifecycle Ensures adherence to internal policies and external regulatory expectations Drives continuous improvement of the vendor risk management program Manages team performance, development, and day to day execution Education High School (HS) (Required) Work Experience General Experience - 3 to 6 years, Manager Experience - 13 months to 3 years Certifications Travel Less than 25% Workstyle Hybrid The total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com. At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view. We expect our associates at all levels to: • Grow professionally and inspire others to do the same • Work with and through others to achieve desired outcomes • Make prompt, pragmatic choices and act with the client in mind • Take ownership and hold themselves and others accountable for delivering results that matter • Contribute to the continuous evolution of the firm At Raymond James – as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates. When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs. #LI-TC1

Location and market context

This role is based in St. Petersburg on-site. Local candidates benefit from being close to Raymond James's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About third-party risk roles

Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Roles like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.

How to position yourself for this third-party risk role

Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Raymond James would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.

Similar GRC roles

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.