Live opening · Posted 6 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Skills: Cyber Security - GRC - Vendor Risk Assessment~Cyber Security - GRC - Data Security Experience Required: 8-10 Years
MUST HAVE SKILLS: GRC – Vendor risk assessment/ Third party risk assessment
Role Descriptions: Lead and execute end-to-end third-partyvendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies.Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.
Essential Skills: Lead and execute end-to-end third-partyvendor risk assessments across technology| supply chain| SaaS| and hybrid environments| identifying control gaps and recommending risk mitigation strategies.Perform deep technical reviews of solution| application| and solution architectures| security controls| and cloud solutions from a security engineering perspective| translating findings into actionable remediation guidance.Conduct hands-on SOC 2 analysis| evaluate control design and operating effectiveness| and clearly articulate control gaps and risk impacts to stakeholders.Ensure alignment of third-party assessments and internal practices with enterprise security policies| data protection standards| and frameworks such as SOC 2 and ISO 27001.Leverage and administer GRC and risk intelligence platforms such as RSA Archer| Onspring| BitSight| UpGuard| SecurityScorecard| ServiceNow| or similar tools to manage risk lifecycle activities.Coordination with business partners such as Legal| Procurement| IT| Privacy| Audit| and Security Operations to drive timely assessment completion and remediation tracking.Develop and report meaningful risk metrics and program insights to leadership| demonstrating effectiveness and continuous improvement of the TPRM program.Contribute to the development| enhancement| and rationalization of information security policies| standards| and exception processes based on risk findings and industry best practices.Communicate complex technical and risk concepts clearly to both technical and non-technical stakeholders build trusted relationships across business units.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.