TPTRM Analyst-Consultant

5 - 7 years

8 - 10 Lacs

Posted:1 month ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Position Purpose

The role of the Third-Party Technology Risk Management Analyst / Consultant is to implement the set of operational activities to be carried out within BNP Paribas (Group entities) to manage ICT Cyber risks for the beneficiaries of sourcing (Outsourcing, purchasing shoring) initiatives supported by ICT service providers and third parties involved in ICT projects or business projects with ICT components. She/he can operate within TPTRM scope governance, providers, beneficiaries SMEs spread throughout global region. As part of his role, she/ he will have to work closely with German stakeholders. Especially, she / he will help clients assess the risks associated to their arrangement and provide recommendations for managing those risks..

Responsibilities

Direct Responsibilities

Perform third-party technology risk assessments to help beneficiaries/contract owners identify and evaluate business and technology risks related to their arrangements, and provide recommendations for managing those risks

Define the contractual ICT security requirements applicable to the arrangement to protect confidentiality, integrity and availability of Beneficiary data and systems

Provide periodic status updates (KPIs/KRIs) including potential risks and delays to the project delivery to beneficiary project manager, conduct workshops wherever necessary

Review thoroughly asset classifications and pre-existing asset related risks control responses ensuring sync with TPTRM assessments responses

Select the requirements to include in the specific ICT due diligence questionnaires to be sent to the shortlisted suppliers and analyze the providers feedback

Support the Beneficiary answering ICT Security questions from the provider as part of the contract negotiation process

List of the risks that should be formalized in a risk management plan given the third party's answers and report on the third party's ability to manage risks

Support the Beneficiary recording the arrangement data in the various Group registers (ServiceNow, RISK360, etc.)

Ensure periodic review of ICT arrangements and contracted ICT services

Demonstrate knowledge in one or more of the following cyber risk domains, including: Security Governance and Management, Security Policies and Procedures, Application Security Controls, Access Controls, Incident Response, Risk Management, Privacy and Data Protection, Encryption.

Contributing Responsibilities
Direct Responsibilities

Perform third-party technology risk assessments to help beneficiaries/contract owners identify and evaluate business and technology risks related to their arrangements, and provide recommendations for managing those risks

Define the contractual ICT security requirements applicable to the arrangement to protect confidentiality, integrity and availability of Beneficiary data and systems

Provide periodic status updates (KPIs/KRIs) including potential risks and delays to the project delivery to beneficiary project manager, conduct workshops wherever necessary

Review thoroughly asset classifications and pre-existing asset related risks control responses ensuring sync with TPTRM assessments responses

Select the requirements to include in the specific ICT due diligence questionnaires to be sent to the shortlisted suppliers and analyze the providers feedback

Support the Beneficiary answering ICT Security questions from the provider as part of the contract negotiation process

List of the risks that should be formalized in a risk management plan given the third party's answers and report on the third party's ability to manage risks

Support the Beneficiary recording the arrangement data in the various Group registers (ServiceNow, RISK360, etc.)

Ensure periodic review of ICT arrangements and contracted ICT services

Demonstrate knowledge in one or more of the following cyber risk domains, including: Security Governance and Management, Security Policies and Procedures, Application Security Controls, Access Controls, Incident Response, Risk Management, Privacy and Data Protection, Encryption.

Contributing Responsibilities

Instruct the 5 European Bank Authority ICT risks categories and follow them throughout TPTRM assessments

Participate in Initialization Committee/ Validation Committee Go-Live committee for Supporting specific arrangements and results

Provide support to beneficiary / contract owner to implement residual actions

Facilitate the business/sponsor/beneficiary/SME decision-making with deep analysis based on relevant flagged risk families

Provide support to contract owners and coordinate/ assist to ensure proper assessments are done

Manage TPTRM inventory with follow-up tracker management

Contribute to process improvement, upkeep with new policies, regulations, standards guidelines

Technical Behavioral Competencies

Functional Skills

Experience in IT Risk and Cyber Security domains in a financial institution demonstrating a high-level of commitment and self-motivation.

Experience in the Finance IT industry with a strong exposure to IT Operations, Application Security, and/or network administration, IPS

Demonstrate knowledge of Risk Compliance, cybersecurity, cyber risk, cyber threats, Third Party Technology Risk Management/ Vendor assessments

Working knowledge of global regulations, frameworks and standards (ISO, NIST, COBIT, PCI-DSS, HIPAA) and conversant in the tactics, techniques and procedures used by Risk adversaries.

Demonstrates a calm professional approach, with a good understanding of delivery within time constraints and the need to escalate/inform departmental management as appropriate.

Good IT knowledge

Technical :

- Good understanding of organizations and IT Businesses

- Good technical understanding of infrastructures and IT Security Productions and Systems

- IT risk /Third Party risk analysis and management methods and should have worked on Risk Management Tools like, ServiceNow etc.

- Knowledge of Cyber Resilience, IT continuity and business continuity

- GRC - Governance, Risk Management and Compliance Management.

- Firewall and Internet technologies; Cloud Security, Banking Tools Technologies.

- Secure access control mechanisms; Encryption and Key management technics

Behavioral :

- Strong Communication, Analytical and problem-solving skills.

- Proven organizational skills with excellent multi-tasking, result oriented and prioritization skills

- Good documentation and reporting skills

- Ability to work independently

- Strong communication and interpersonal skills, able to communicate and relate easily with IT, Finance and back-office users

- Good communication, technical writing/diagramming skills

- Attention to detail and accuracy

Specific Qualifications (if required)

- One or more Industry-recognized information Security certifications such as CISSP, CISA, GCCC, CISM, CEH, CRISC, OSCP or Security+.

- IT Security tools like Firewalls, IPS, WAF, Endpoint protection, Network security, etc.

- IT Auditing (ISO27001/2, NIST 800 Series, ISO27005, ISO42001)

- Regulatory Compliance

MBA in Finance/Systems/IT, Masters in Technology, Bachelor of Commerce, Masters in Commerce, Bachelor in Science, Bachelor in Technology

Skills Referential

Behavioural Skills: (Please select up to 4 skills)

Communication skills - oral written

Attention to detail / rigor

Ability to deliver / Results driven

Creativity Innovation / Problem solving

Choose an item.

Choose an item.

Choose an item.

Transversal Skills: (Please select up to 5 skills)

Analytical Ability

Ability to manage a project

Ability to understand, explain and support change

Ability to develop and adapt a process

Ability to anticipate business / strategic evolution

Other/Specific Qualifications

CISA/CISSP/CISM/CRISC

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
BNP Paribas logo
BNP Paribas

Banking

Paris London

RecommendedJobs for You

Kolkata, Hyderabad, Pune, Ahmedabad, Chennai, Bengaluru, Delhi / NCR, Mumbai (All Areas)