Jobs › Supervisor, IT Security Vendor Risk Management
Supervisor, IT Security Vendor Risk Management
Job at a glance
- Category
- GRC
- Work arrangement
- Hybrid
- Location
- St. Petersburg, FL
- Posted
- Jul 31, 2026
Free. One click to unsubscribe. We never share your address.
Raymond James is hiring a Supervisor, IT Security Vendor Risk Management in St. Petersburg, FL. This is a GRC job in the governance, risk, and compliance field. Review the full details below and apply directly with Raymond James.
Job Description Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and risk‑based prioritization. Dedicated supervision will drive measurable time reduction through operational efficiencies, reduce rework and process overhead, and enable senior leaders to focus on program strategy and regulatory readiness. Job Description This position follows our hybrid workstyle policy: Expected to be in a Raymond James office location a minimum of 10-12 days a month. Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future. Technical Skills/Experience: Foundational experience in IT security, vendor risk management, third party risk, or similar risk functions Working knowledge of core information security and technology risk domains sufficient to review assessments, identify gaps, and escalate complex issues appropriately. Familiarity with internal policies, standards, and common regulatory expectations impacting third party risk management, with the ability to follow established procedures and recognize potential non compliance trends for escalation. Ability to apply basic risk concepts (inherent risk, control effectiveness, residual risk) to support consistent risk ratings and clear, defensible assessment outcomes. Experience reviewing and validating the work of others for completeness, accuracy, and adherence to standards, and providing constructive feedback to improve assessment quality and consistency. Developing people leadership skills, including task prioritization, workload coordination, coaching junior team members, and tracking team deliverables against defined timelines and objectives. Strong written and verbal communication skills, with the ability to summarize assessment results and risks in clear, business appropriate language for stakeholders and management. Responsibilities: Leads a team responsible for conducting risk based due diligence assessments for third party supplier engagements Oversees the evaluation of information security and technology risks associated with vendors, products, and services Ensures vendor risk outcomes align with the firm’s risk appetite and regulatory obligations Accountable for the quality, consistency, and timeliness of vendor risk assessments Translates technical and regulatory findings into clear risk conclusions and actionable recommendations
Full responsibilities and requirements are on Raymond James's application page.
Apply for this job →Location and market context
This job is based in St. Petersburg, FL on a hybrid schedule. Local candidates benefit from being close to Raymond James's teams and regional hiring market, while the hybrid arrangement offers some flexibility. Confirm the exact in-office expectation and any relocation support with the employer.
About third-party risk jobs
Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Jobs like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.
How to position yourself for this third-party risk job
Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Raymond James would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location