Third-party Security Assurance consultant
Details
- Status:
- Gearchiveerd
- Publicatiedatum:
- 21-7-2020
- Weergaven:
- 56
- Reacties:
- 1
- Op locatie:
- Eindhoven
- FTE:
- 40 uur per week
Opdrachtomschrijving
Our group, the Third-party Security Assurance team in Corporate Security is highly visible within our Post Merger Integration (PMI) program. As we monitor, analyze, help mitigate, and report risks associated with third-parties, your strong analytical, organizational, and decision-making skills will be an asset to our mission. You will partner with workstreams such as Procurement, IT, Legal, Privacy, etc. across the organization at all levels to ensure that third-party selection and risk management meet corporate standards. This position reports into to Information Security GRC manager and with a dotted line into the Security Workstream Lead.
Key responsibilities
Execute Security Integration Plan and update Operational Plan Activities (OPA)
Assist security workstream in maintaining PMI program activities by partnering with relationship owners, Procurement, Service Managers, IT, Privacy, and the Legal department to ensure the third-party selection and management process are consistently followed.
Maintain a third-party risk register and an action item inventory. Ensure to document and track material actions until completion.
Maintain a third-party assessment schedule and update it as needed.
Provide analysis and reporting on PMI security compliance, third-party profiles, high-risk activities, etc.
Perform a risk-based security due diligence on new third-parties and assess risk at existing third-parties based on schedule, as required by management, and during contract renewal.
Review Security schedule in collaboration with Relationship Owners and Procurement.
Develop an inventory of critical third-parties and maintain it.
Update and maintain third-party self-assessment questionnaire and responses from third-parties.
Collect and maintain third-parties’ security artifacts, as required for assessments.
Build relationships!
Be familiar with Security control standards such as ISO 27001 and NIST 800-53 publications and compliance documentation such ISAE3402, SOC reports, and Security Certifications.
Be familiar with internal Security Standards
Keep abreast with security industry update knowledge through training, participation in outside seminars and professional publications to ensure compliance with laws and regulations.
Perform on-site security assessments at selected third-parties.
Ensure all deliverables are met in a timely manner.
Job requirements
Bachelor’s degree (or equivalent)
2+ years of relevant experience in Third-party Risk Management
Hold valid security certification such as CISM, CISSP, and CISA.
Excellent written and verbal communication skills
Strong analytical, organizational, and decision-making skills
Proficient with Microsoft Office products, including Word, Excel, PowerPoint, and Outlook.