Service Manager – Supplier Security Due Diligence & Monitoring Service
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
Team and overall work scopeThe Supplier Security Due Diligence & Monitoring Service operates at the intersection of Cybersecurity, Legal, Procurement, Supplier Management, and Enterprise Risk Management. The team is responsible for helping the enterprise navigate information security requirements within supplier contracts by providing first-line support during contract negotiations and redline reviews.
The Service Manager leads the specialized service responsible for translating supplier risk assessments into practical contractual security positions. The team advises stakeholders on acceptable contractual outcomes, applies approved fallback language, documents security control exceptions, and ensures non-standard contractual positions are reviewed through appropriate governance channels. This service plays a critical role in balancing supplier risk management with business enablement while maintaining alignment with enterprise risk expectations.
What’s exciting about this role?
Lead a highly visible enterprise service that directly influences supplier risk outcomes across the organization. This role sits at the center of cybersecurity, legal, procurement, and business strategy, providing the opportunity to shape contracting decisions, influence enterprise risk management practices, and drive scalable security governance. You will build and mature a service that enables the business to move quickly while ensuring critical security requirements remain protected in an increasingly complex supplier ecosystem.
Ideal Candidate
Strong risk leader with the ability to distinguish between acceptable contractual deviations, temporary accommodations, material control weaknesses, and risks requiring formal escalation or acceptance.
Proven operational leader capable of building structure, driving consistency, and managing a high-demand service with multiple stakeholders and competing priorities.
Brings strong understanding of how information security requirements translate into contractual obligations and can evaluate legal language through a practical risk lens.
Highly disciplined in governance, documentation, exception management, and maintaining defensible audit trails for risk decisions.
Demonstrated ability to influence legal, procurement, business, security, and supplier stakeholders without direct authority.
Pragmatic and commercially aware, balancing risk management objectives with business outcomes and supplier realities.
Service-oriented leader committed to responsiveness, consistency, stakeholder experience, and operational excellence.
Success Measures
Consistent application of enterprise risk tolerances and contractual security standards.
Achievement of service-level commitments and stakeholder satisfaction objectives.
Effective documentation, governance, and escalation of security control exceptions and contractual deviations.
Reduction in unmanaged contractual security risk across supplier agreements.
Operational maturity demonstrated through scalable processes, metrics, reporting, and continuous improvement.
Development of a high-performing team capable of delivering consistent, risk-informed contracting outcomes.
Key Responsibilities
Lead the Supplier Security Due Diligence & Monitoring Service and oversee day-to-day service delivery.
Manage and develop a team responsible for supplier security contracting support and risk-based decision making.
Review and interpret supplier security assessment outcomes and monitoring results to guide contractual negotiations.
Provide guidance on acceptable contractual security positions, fallback language, compensating controls, and alternative risk mitigation approaches.
Ensure consistent application of enterprise security requirements across supplier agreements.
Oversee documentation and tracking of contractual exceptions, deviations, and risk accommodations.
Escalate contractual positions that exceed established risk tolerances through appropriate governance and risk acceptance processes.
Partner closely with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier issues.
Establish and maintain operational metrics, service-level objectives, reporting, and quality management practices.
Lead continuous improvement efforts designed to improve scalability, consistency, and stakeholder experience.
Required Qualifications
7+ years of experience in information security, technology risk, third-party risk management, supplier risk management, governance, contracting, procurement, or related disciplines.
3+ years of leadership experience managing teams, services, programs, or operational functions.
Experience evaluating cybersecurity and technology risks and applying sound risk-based decision-making principles.
Strong understanding of supplier risk management, security controls, and governance practices.
Experience working across legal, procurement, business, security, and risk management functions.
Excellent written, verbal, stakeholder management, and executive communication skills.
Preferred Qualifications
Experience supporting supplier contract negotiations involving cybersecurity and privacy requirements.
Knowledge of third-party risk management programs and supplier security assessment methodologies.
Experience with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, NIST 800-53, ISO 27001, CIS Controls, and SOC reporting.
Experience with enterprise risk management, governance, and risk acceptance processes.
Professional certifications such as CISSP, CISM, CRISC, ITIL, PMP, or related credentials.
Experience building, scaling, or transforming operational services and governance functions.
Skills
Analytical Thinking, Complex Analysis, Compliance Governance, Contract Negotiations, Cybersecurity Risk Management, Employee Supervision, Information Technology (IT) Risk Management, IT Risk Assessments, Risk Mitigation Strategies, Security Governance, Security Risk, Technical Risk Assessment, Third Party Risk Management, Vendor SecurityCompensation
Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications.The candidate(s) offered this position will be required to submit to a background investigation.
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.
To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.
Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.