1 день назад
Third Party Risk Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Third Party Risk Analyst (Cybersecurity): Supporting the end-to-end third-party risk management lifecycle in a hybrid Manila-based role with an accent on security assessments, vendor evidence review, and risk documentation. Focus on evaluating control gaps, tracking remediation, validating closure evidence, and improving TPRM processes and tooling.
Location: Manila, Philippines (flexible hybrid work)
Company
provides an AI-powered experience orchestration platform connecting people, systems, data, and AI for more than 8,000 organizations worldwide.
What you will do
- Manage the third-party risk management workflow from intake and due diligence through assessment completion and ongoing monitoring.
- Conduct initial and recurring third-party security risk assessments, including control evaluation, risk rating, and residual-risk documentation.
- Administer the UpGuard assessment platform, including vendor onboarding, questionnaire distribution, response tracking, evidence collection, and workflow management.
- Review SOC 2 reports, ISO 27001 certificates, policies, standards, penetration-test summaries, and other vendor security artifacts to identify control gaps.
- Document findings, develop risk narratives, recommend remediation or compensating controls, and track closure evidence.
- Improve TPRM processes, templates, playbooks, reassessment cycles, and monitoring activities.
Requirements
- Bachelor’s degree in information security, IT, cybersecurity, or a related field.
- Minimum of 2 years of related experience in information security, IT audit, risk, compliance, vendor management, or GRC is preferred.
- Strong critical-thinking, analytical, documentation, and stakeholder-management skills.
- Ability to interpret vendor security questionnaires, SOC reports, policies, and other complex compliance artifacts.
- Strong verbal and written communication skills, with the ability to translate control gaps into clear risk statements.
- Ability to learn new tools quickly and work effectively in process-driven environments.
Culture & Benefits
- Work with AI-powered technology used by more than 8,000 organizations worldwide.
- Flexible ways of working within a global team of nearly 7,000 employees.
- Mentorship, learning programs, leadership development, and education support.
- Paid volunteer time, August Free Fridays, well-being resources, and regionally tailored employee and family programs.
- is Great Place to Work certified in 17 countries.
Hiring process
- Application review by Talent Acquisition and the hiring team.
- Zoom interview followed by meetings with the hiring manager and interview team.
- Most processes include no more than five interviews before final steps are confirmed.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
GRC Specialist (Cybersecurity)
1 день назад
Regional Information Security Manager (Cybersecurity)
5 дней назад
IT Risk Analyst (Banking)
6 дней назад
Senior Third-Party Cyber Assurance Expert (Cybersecurity)
1 день назад
Junior Information Security Analyst (For Internship Program) (Cybersecurity)
2 дня назад