Cybersecurity Success Manager
Fully Remote • Atlanta
Job Type
Full-time
Description

   

Job Title: Cybersecurity Success Manager

Department: TPRM— Managed Services

Reports To: Senior Director of Security Advisors

Employment Status: Full Time

FLSA Status: Exempt

Effective Date: 9/21/2026


About Us

Meditology Services is a leading healthcare-focused cybersecurity, privacy, compliance, and information risk management consulting firm. We help healthcare organizations manage risk, strengthen security programs, achieve compliance objectives, and improve cybersecurity maturity through practical, business-focused advisory services.


Through CORL Technologies, we deliver third-party risk management as a managed service. Our clients hand us their vendor assessment workload, and we run it — vendor outreach, questionnaire and evidence evaluation, risk reporting, escalation, and remediation follow-up — supported by a proprietary vendor data asset, the CORL portal, and the CORL Cleared Vendor Directory.


Our teams work alongside healthcare security leaders, procurement organizations, business owners, and the vendors themselves to reduce third-party risk in ways clients can see and measure.


Why Meditology

At Meditology, Success Managers are more than coordinators, they own the outcome of a client's managed third-party risk program. You'll work directly with security teams and CISOs, drive real reduction in vendor risk across large healthcare vendor ecosystems, and have visible influence over how the service is delivered.


You'll also see the strategic side of the discipline. Cybersecurity Success Managers work closely with our Professional Services consultants, who design and mature client TPRM programs, and are often the first to recognize when a client needs that help.


If you're looking for a role that combines cybersecurity expertise, program ownership, executive relationship management, and a genuine bias toward driving work forward, we'd love to hear from you.


Position Description

Meditology is seeking a Cybersecurity Success Manager to join our Managed Services team. This role owns the delivery and outcomes of managed third-party risk programs for an assigned portfolio of healthcare clients.


Executing assessments is only part of the job. The value clients experience comes from a steady flow of vendors into the program, consistent risk tiering, persistent vendor escalation, disciplined remediation follow-up, and reporting that demonstrates risk reduction. 


The position is deliberately proactive. Rather than waiting for a client to initiate an assessment and shepherding it through the workflow, the Cybersecurity Success Manager builds and drives the vendor pipeline, anticipates renewal and reassessment cycles, and ensures clients consume and benefit from the full service they purchased.


This role is dedicated to Managed Services delivery. It does not deliver Professional Services engagements, but works closely with those consultants and is expected to recognize when a client's underlying program gaps warrant bringing them in.


Responsibilities 

Own Client Relationships and Program Outcomes

Serve as the primary relationship owner and delivery lead for a portfolio of managed service clients.

• Serving as the day-to-day point of contact for client stakeholders, from analysts to CISOs

• Owning overall program outcomes rather than the throughput of individual assessments

• Running recurring working sessions and quarterly business reviews

• Building trusted relationships across security, procurement, legal, and business stakeholders

• Aligning service delivery to each client's operating model, tools, and existing workflows

• Coordinating Security Advisors, analysts, and offshore research teams assigned to the account

• Maintaining accurate account documentation, tracking, and status reporting


Lead Client Onboarding and Service Integration

Own onboarding from contract signature forward, partnering with Sales and Security Advisors.

• Leading onboarding for new clients, new users, renewals, and expanded service tiers

• Documenting the client's current security assessment, procurement, GRC, and reporting workflows so our delivery fits inside them

• Establishing assessment goals up front: volume, type (Validated, Validated & Remediated, or Reliant), and timeframe

• Defining which vendor populations route through our team versus the client's internal team (as applicable)

• Identifying existing client questionnaires and scoping custom questionnaire development where warranted

• Setting expectations on vendor outreach windows, vendor responsiveness, and security certifications accepted in lieu of questionnaires

• Securing review and approval of client-branded vendor communications issued from the CORL platform

• Training client stakeholders on our processes, the client portal, and reporting outputs


Drive Proactive Assessment Execution

Build and drive the vendor assessment pipeline rather than waiting for clients to initiate work.

• Forecasting assessment demand from contract renewals, new procurement activity, and reassessment cadence

• Sourcing upcoming vendors from client stakeholders and maintaining a queue sufficient to meet contracted volumes

• Tracking utilization against purchased assessment counts and addressing shortfalls early

• Advancing assessments through intake, outreach, evaluation, and reporting within published SLAs

• Monitoring assessment status daily and intervening before delays become schedule risk

• Applying the appropriate assessment type and depth based on vendor risk tier and client requirements

• Escalating internally when capacity, quality, or timeline risks emerge


Manage Vendor Engagement and Escalation

Drive vendor cooperation without the leverage of a direct contract.

• Owning outreach to vendor security, compliance, and executive contacts

• Pursuing unresponsive vendors persistently and through multiple channels

• Leveraging our position across many healthcare clients to encourage vendor participation

• Maintaining accurate records of vendor communications, commitments, and outcomes


Advise on Vendor Risk Decisions and Remediation

Help clients decide what to do about the risk the program surfaces.

• Presenting assessment findings and translating vendor-level issues into business impact

• Recommending risk strategy options based on vendor criticality, data access, and client risk tolerance

• Advising on remediation priorities, timelines, and acceptable risk acceptance decisions

• Applying vendor tiering consistently to determine assessment depth and reassessment cadence

• Recognizing where program-level gaps limit the value of managed assessments, and engaging Professional Services colleagues accordingly


Reporting, Presentation, and Facilitation

Communicate vendor risk, progress, and business impact through clear reporting and confident facilitation.

• Producing vendor risk portfolio and program status reporting

• Leading recurring client working sessions and quarterly business reviews

• Presenting program results, metrics, and recommendations to leadership teams

• Supporting executive and board-level presentations


Support Account Health, Retention, and Growth

Protect and grow an assigned portfolio in partnership with Sales.

• Maintaining a clear view of client health, sentiment, and renewal risk

• Identifying and referring opportunities for additional assessment volume, expanded service tiers, and RITHM subscription components

• Identifying and referring Professional Services opportunities where clients need program design or maturity work

• Partnering with Sales ahead of renewal on timing, budget cycles, and approval paths

• Capturing client feedback and driving corrective action when satisfaction declines

Requirements

Qualifications

• 2+ years of experience in cybersecurity, information risk management, third-party risk, or related service delivery

• Experience owning client relationships and delivery outcomes in a managed service, consulting, or customer success environment

• Experience assessing vendor security controls, certifications, questionnaires, and supporting evidence

• Experience presenting findings and recommendations to client leadership

• Experience managing multiple concurrent client accounts against defined SLAs

• Healthcare industry experience preferred


Technical Knowledge

Experience with one or more of the following:

• HIPAA Security Rule

• HITRUST (e1, i1, and r2)

• SOC 2 Type I and Type II

• Third-party risk management processes and vendor tiering models

• GRC platforms and vendor risk tooling

• Continuous monitoring platforms (e.g., RiskRecon by Mastercard, BitSight)


Professional Skills

Successful candidates demonstrate:

• A proactive, ownership-driven approach to client delivery

• Persistence and comfort with follow-up, escalation, and difficult conversations

• Excellent written and verbal communication skills

• Strong presentation and facilitation abilities

• Executive presence and client-facing confidence

• Ability to manage multiple priorities and a portfolio of accounts

• Strong attention to detail and organizational skills


Physical Requirements: 

This position operates in a remote/home office environment and involves primarily sedentary work.

  • Ability to remain in a stationary position (sitting or standing) for extended periods, typically at a computer workstation
  • Frequent use of hands and fingers to operate a computer keyboard, mouse, and other office equipment
  • Ability to communicate effectively via phone, video conferencing, and in writing
  • Visual acuity sufficient to read documents and view a computer screen for extended periods
  • Occasional travel may be required, including the ability to sit for extended periods during travel and transport standard business materials (e.g., a laptop bag, up to approximately 15–20 lbs)
  • Ability to maintain a reliable distraction-free home office environment conducive to focused work and confidential company and client information
  • Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

Meditology Services is an equal opportunity employer. The company does not discriminate in employment and provides equal employment opportunities to all employees and applicants for employment without regard to race, color, ancestry, national origin, gender, pregnancy, sexual orientation, gender identity, marital status, religion, age, disability, results of genetic testing, service in the military or any other trait that is protected under local, state or federal law. Equal employment opportunity applies to all terms and conditions of employment, including hiring, placement, promotion, termination, layoff, recall, transfer, leave of absence, compensation, and training. 

Salary Description
$75,000-$85,000, Dependent on experience