Third Party Risk Analyst

2 - 5 years

5 - 10 Lacs

Posted:4 months ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Experience

Job responsibilities:

  • Review and establish secure processes and systems at Third Partys end
  • Conduct Third Party risk assessments from information security perspective using ISO27001 or COBIT framework to meet the organization standards.
  • Classification of Third Parties from information security risk perspective
  • Preparation of risk-based questionnaires and reports
  • Undertake extensive Third Party evaluations from an information security perspective and then make active recommendations to the business / Third Party to mitigate the risks and provide risk-based clauses for the agreements with the Third Party.
  • Preferred certifications

    : ISO27001 LA / CISSP / CISA / CTPRA / CTPRA

Competencies / Abilities:

  • Excellent written & verbal communication & presentation skills
  • Independent & self-starter
  • Knowledge in multiple information security technologies and their strengths and shortcomings
  • Exposure to Third Party Risk questionnaires and tools such as Standard Information Gathering (SIG)
  • Proven experience with securing information for various technical solutions
  • Knowledge of IT risk management, common assessment control techniques
  • Knowledge of analytic techniques and methods / Excel
  • Understand security controls from a people, process, and technology perspective.
  • Experience in system security, network security, and information security, covering areas of ISMS Management / COBIT, Technology risk and compliance, BCP & DR planning, Implementation and compliance, IT and IS audits, BCP audits, Security operations assessment, and Cloud security.
  • Ability to interact and work with various senior stakeholders. Manage congruent relationships among different teams.
  • PCI DSS, PA DSS, ISO27001 & COBIT experience.
  • Strong ability to devise, drive, and implement standard processes and best practices (both from security and risk perspective) for all the suppliers

Primary Keywords:

  • Third Party Risk Management
  • IT Risk Management
  • Information Security
  • IT Audit
  • ISO 27001
  • COBIT Framework
  • Vendor Risk Assessment

Technical & Compliance Keywords

  • ISMS
  • PCI DSS, PA DSS
  • BCP & DR
  • Cloud Security
  • Security Operations
  • IT & IS Audits

Tools & Certifications:

  • SIG (Standard Information Gathering)
  • CISA, CISSP, ISO 27001 LA, CTPRA

Work Experience Required

Job Location

Qualification