Job Description
About the Role:Grade Level (for internal use):
10
The Team: As part of Vendor Risk Management, the Vendor Cyber Risk Management team manages the Supply Chain Cyber risks by performing risk assessments of third-party engagements to identify and reduce the risks posed by third parties. This is an extremely important role, considering the fact that large number of data breaches happen due to third parties. It involves working with internal stake holders as well as third parties to achieve the results.
The Impact: Working in Vendor Risk Management offers the opportunity to continuously enhance processes to meet the evolving requirements of various regulators. This challenging environment provides ample opportunities to expand your knowledge and expertise.
Whats in it for you: In addition to risk assessments, recertifications, and continuous monitoring, you will participate in various projects, allowing you to showcase and further develop your skills and experience.
Responsibilities:
- Conduct thorough Cybersecurity, Business Continuity, Artificial Intelligence, Cloud Service Prover and Privacy assessments for Vendors, evaluating their information security policies, procedures, and controls.
- Effectively collaborate with internal teams to identify critical vendors and assess their potential impact on the organization's cyber risk profile.
- Communicate risk assessment findings and recommendations to key stakeholders, including senior management, legal, and compliance teams.
- Work closely with vendors to address identified security gaps and ensure they meet the organization's cybersecurity requirements.
- Review the vendors on the continuous monitoring program and assisting in driving the periodically review the vendors.
- Monitor and stay abreast of evolving cybersecurity threats and industry trends to enhance the effectiveness of the risk assessment process.
- Lead and support enhancement projects within Vendor Risk Management to meet various business and regulatory requirements.
- Assist the team members in balancing the load and managing Ad-hoc projects.
What Were Looking For:
Basic Required Qualifications:
- Bachelors degree in computer science or engineering or equivalent
- Minimum 8 years of experience in Information Security or Technology Risk Management
- Any prior exposure to vendor risk management and/ or privacy laws and regulations is a plus.
- Demonstrable understanding of the concepts of technology controls and information security controls.
- Exposure to cloud technologies and cloud security is highly desired; the familiarity with pubic cloud technologies such as Amazon Web Services (AWS) or Microsoft Azure or Google Cloud is highly preferred.
- Excellent communication skills - a must. The resource should have the ability to communicate with cross-functional teams and vendors, both written and oral communication is critical.
Additional Preferred Qualifications:
- This position is required to work in UK Shift; flexibility is a must, especially when it comes to vendor and internal meetings held during US business hours.
- Strong organizational skills with the ability to multitask and prioritize while maintaining close attention to detail.
- Ability to build strategic partnerships with internal stakeholders.
- Must be a critical thinker with strong qualitative skills.
- Information Security/Risk Management certification would be an advantage.
Progress is not a self-starter. It requires a catalyst to be set in motion. Information, imagination, people, technologythe right combination can unlock possibility and change the world.
Our Values:
-----------------------------------------------------------
-----------------------------------------------------------
Job Classification
Industry: Banking
Functional Area / Department: IT & Information Security
Role Category: IT Infrastructure Services
Role: Software Compliance - License Management
Employement Type: Full time
Contact Details:
Company: S&P Global Market
Location(s): Hyderabad
Keyskills:
risk management
information security
security controls
technology risk
gcp
vendor management
cloud security
supply chain
microsoft azure
cloud technologies
supply
artificial intelligence
apex
vendor risk management
salesforce
recruitment
aws