Information Security Program Manager (Third-Party Risk Assessment)

Not Interested
Bookmark
Report This Job

profile Job Location:

Bengaluru - India

profile Monthly Salary: Not Disclosed
Posted on: 10 hours ago
Vacancies: 1 Vacancy

Job Summary

Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers focusing on cybersecurity and regulatory compliance.
Evaluate third-party security questionnaires audit reports (e.g. SOC 2 ISO 27001) and risk documentation.
Coordinate with vendors to request and verify security controls remediation plans and ongoing compliance.
Oversee facilitation of risk remediation efforts agreed upon with suppliers ensuring timely resolution.
Collaborate during supplier contract development reviewing deviations from security requirements and offering subject matter expertise on risk remediation.
Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profiles.
Participate in continuous security monitoring of existing suppliers to track changing risk profiles.
Partner with Procurement Legal Privacy and InfoSec teams to improve supplier security management processes.
Identify opportunities to automate parts of the assessment process thereby reducing manual work and enhancing efficiency.
Keep abreast of emerging risks industry standards and regulatory requirements affecting third-party vendors.
Manage and mentor contractors and junior team members fostering professional growth and maintaining a collaborative team environment.
Preferred Qualifications:
Bachelors degree in Computer Science Information Security Cybersecurity Risk Management or a related field.
8-10 years of professional experience in third-party risk assessment within cybersecurity or information risk management.
Understanding of relevant information security frameworks including related regulatory compliance requirements such as ISO 27001/2 (including ISO 27017 & 18) FedRAMP SOC 2 Trust Services Criteria PCI DSS NIST CSF.
Solid understanding of risk assessment methodologies and best practices.
Ability to synthesize and communicate complex risk findings to both technical and non-technical audiences.
Detail-oriented process-driven and capable of managing multiple vendor assessments concurrently.
Experience with tools such as Coupa OneTrust JIRA and Coverbase is a plus.
Professional certifications in Information Security or Risk Management (e.g. CISA CISM CISSP CRISC) is a plus.
Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers focusing on cybersecurity and regulatory compliance. Evaluate third-party security questionnaires audit reports (e.g. SOC 2 ISO 27001) and risk documentation. Coordinate with vendors to requ...
View more view more

Key Skills

  • International Development
  • EMC
  • JavaScript
  • Import & Export
  • Airlines
  • Asp.Net MVC