Third-party Security Assurance consultant

Details

Status:
Gearchiveerd
Publicatiedatum:
21-7-2020
Weergaven:
56
Reacties:
1
Op locatie:
Eindhoven
FTE:
40 uur per week

Opdrachtomschrijving

Our group, the Third-party Security Assurance team in Corporate Security is highly visible within our Post Merger Integration (PMI) program. As we monitor, analyze, help mitigate, and report risks associated with third-parties, your strong analytical, organizational, and decision-making skills will be an asset to our mission. You will partner with workstreams such as Procurement, IT, Legal, Privacy, etc. across the organization at all levels to ensure that third-party selection and risk management meet corporate standards. This position reports into to Information Security GRC manager and with a dotted line into the Security Workstream Lead.

Key responsibilities

  • Execute Security Integration Plan and update Operational Plan Activities (OPA)

  • Assist security workstream in maintaining PMI program activities by partnering with relationship owners, Procurement, Service Managers, IT, Privacy, and the Legal department to ensure the third-party selection and management process are consistently followed.

  • Maintain a third-party risk register and an action item inventory. Ensure to document and track material actions until completion.

  • Maintain a third-party assessment schedule and update it as needed.

  • Provide analysis and reporting on PMI security compliance, third-party profiles, high-risk activities, etc.

  • Perform a risk-based security due diligence on new third-parties and assess risk at existing third-parties based on schedule, as required by management, and during contract renewal.

  • Review Security schedule in collaboration with Relationship Owners and Procurement.

  • Develop an inventory of critical third-parties and maintain it.

  • Update and maintain third-party self-assessment questionnaire and responses from third-parties.

  • Collect and maintain third-parties’ security artifacts, as required for assessments.

  • Build relationships!

  • Be familiar with Security control standards such as ISO 27001 and NIST 800-53 publications and compliance documentation such ISAE3402, SOC reports, and Security Certifications.

  • Be familiar with internal Security Standards

  • Keep abreast with security industry update knowledge through training, participation in outside seminars and professional publications to ensure compliance with laws and regulations.

  • Perform on-site security assessments at selected third-parties.

  • Ensure all deliverables are met in a timely manner.

Job requirements

  • Bachelor’s degree (or equivalent)

  • 2+ years of relevant experience in Third-party Risk Management

  • Hold valid security certification such as CISM, CISSP, and CISA.

  • Excellent written and verbal communication skills

  • Strong analytical, organizational, and decision-making skills

  • Proficient with Microsoft Office products, including Word, Excel, PowerPoint, and Outlook.

Verder kijken

Vergelijkbare open opdrachten