Third Party Risk Management - JD Experience: 2 to 5 years of experience in information security, IT auditing & IT / Third Party risk management processes. Location: Chennai Job responsibilities: Review and establish secure processes and systems at Third Partys end Conduct Third Party risk assessments from information security perspective using ISO27001 or COBIT framework to meet the organization standards. Classification of Third Parties from information security risk perspective Preparation of risk-based questionnaires and reports Undertake extensive Third Party evaluations from an information security perspective and then make active recommendations to the business / Third Party to mitigate the risks and provide risk-based clauses for the agreements with the Third Party. Preferred certifications: ISO27001 LA / CISSP / CISA / CTPRA / CTPRA Competencies / Abilities: Excellent written & verbal communication & presentation skills Independent & self-starter Knowledge in multiple information security technologies and their strengths and shortcomings Exposure to Third Party Risk questionnaires and tools such as Standard Information Gathering (SIG) Proven experience with securing information for various technical solutions Knowledge of IT risk management, common assessment control techniques Knowledge of analytic techniques and methods / Excel Understand security controls from a people, process, and technology perspective. Experience in system security, network security, and information security, covering areas of ISMS Management / COBIT, Technology risk and compliance, BCP & DR planning, Implementation and compliance, IT and IS audits, BCP audits, Security operations assessment, and Cloud security. Ability to interact and work with various senior stakeholders. Manage congruent relationships among different teams. PCI DSS, PA DSS, ISO27001 & COBIT experience. Strong ability to devise, drive, and implement standard processes and best practices (both from security and risk perspective) for all the suppliers.,
Employement Category:
Employement Type: Full time Industry: IT Services & Consulting Role Category: Not Specified Functional Area: Not Specified Role/Responsibilies: Third Party Security Risk Analyst Job in