Third-Party Risk Management Analyst
Brak informacji o wynagrodzeniu
MidFull-time·B2B
#382734·Dodano 20 dni temu·0
Źródło: ExperisTech Stack / Keywords
CybersecuritySecurity
Firma i stanowisko
Experis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT.
Wymagania
- 3–5 years of experience in Third-Party Risk Management, Cybersecurity Risk Management, or IT Risk
- Hands-on experience conducting vendor cybersecurity assessments or due diligence reviews
- Familiarity with industry frameworks and standards such as NIST, ISO 27001, and SOC 2
- Strong analytical and problem-solving skills
- Ability to assess risk and make recommendations based on incomplete or evolving information
- Excellent written and verbal communication skills
- Ability to effectively communicate with both technical and non-technical stakeholders
- Strong attention to detail and organizational skills
Obowiązki
Risk Assessment & Due Diligence:
- Perform cybersecurity and risk assessments of third parties using standardized frameworks
- Evaluate suppliers' security posture, controls, and compliance with internal requirements
- Analyze risks across multiple domains including information security, data privacy, and business continuity
- Assign risk ratings and document findings per TPRM standards
Risk Identification & Issue Management:
- Identify control gaps, vulnerabilities, and areas of elevated risk
- Document and track remediation actions with suppliers and internal stakeholders
- Escalate high-risk findings in line with defined risk thresholds and procedures
Ongoing Monitoring:
- Support continuous monitoring activities including review of threat intelligence, security ratings, and supplier updates
- Track changes in vendor risk posture over time
- Assist in periodic reassessments based on risk tiering
Stakeholder Engagement:
- Partner with Procurement, Information Security, Legal, and business stakeholders to support risk-based decision making
- Communicate assessment results clearly to both technical and non-technical audiences
Program Support & Documentation:
- Maintain accurate records of assessments, decisions, and supporting evidence
- Ensure all activities align with TPRM policies, standards, and regulatory expectations, including DORA, NIST, and ISO frameworks
- Support audit and regulatory inquiries by providing required documentation
Benefity
- Multisport card
- Private healthcare (Medicover)
- Access to an e-learning platform
- Group life insurance
Karta sportowa
Opieka zdrowotna
Ubezpieczenie
Experis
332 aktywne oferty