drjobs Lead Security Analyst (Third Party Risk Manger) (IGT1 Lanka: CFC)

Lead Security Analyst (Third Party Risk Manger) (IGT1 Lanka: CFC)

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Colombo - Sri Lanka

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Key responsibilities & accountabilities

We are seeking an experienced and strategic Senior Third Party Risk Manager to join our CISO team. This role is critical in shaping and executing our Third-Party Risk Management (TPRM) strategy ensuring that our external partnerships align with our cybersecurity standards and evolving threat landscape. You will lead the development and continuous improvement of a robust TPRM security framework embedding a dynamic and risk-based approach to third-party oversight.

Key Responsibilities Include:

  • Establish and manage a repeatable risk-based due diligence lifecycle for onboarding monitoring and offboarding third parties including vendors partners and service providers.
  • Create a cycle of security enhanced due diligence for our critical and high value third party suppliers ensuring processes meet key regulation CFC needs to be compliant with in alignment with procurement and legal third party requirements.
  • Design implement and maintain a comprehensive Third Party Risk Management security framework aligned with industry standards (e.g. NIST ISO 27001 SIG etc.) and regulation CFC needs to be compliant with.
  • Lead security risk assessments of third parties identifying control gaps and working with stakeholders to mitigate risks through contractual technical or procedural means.
  • Continuously adapt TPRM practices to reflect the changing regulatory landscape.
  • Collaborate with Legal Procurement IT and Business Units to ensure third-party engagements meet security and compliance requirements.
  • Define and report on key risk indicators (KRIs) and performance metrics to Group CISO providing insights into third-party risk posture and trends.
  • Evaluate and implement TPRM tools and platforms to streamline assessments monitoring and reporting.

 


    Qualifications :

    • Degree in Cybersecurity Information Security Risk Management or a related field.
    • Experience working in multiple time zones
    • 5 years of experience in cybersecurity or risk management with at least 3 years in a TPRM-specific role.
    • Strong knowledge of third-party risk frameworks security controls and regulatory requirements.
    • Experience with TPRM platforms and tools
    • Relevant certifications (e.g. CISM CRISC CISSP CTPRP) are a plus.
    • Ability in working for the UK time zones. 

    Skills & Ability           

    • Proven TPRM experience in a security team 
    • Strong understanding of global regulation for TPRM
    • Exceptional communication and stakeholder management skills.
    • Proven ability to develop TPRM frameworks and KRI reports


    Remote Work :

    No


    Employment Type :

    Full-time

    Employment Type

    Full-time

    Company Industry

    About Company

    Report This Job
    Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.