Назад
Company hidden
1 день назад

Third Party Risk Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Third Party Risk Analyst (Cybersecurity): Supporting the end-to-end third-party risk management lifecycle in a hybrid Manila-based role with an accent on security assessments, vendor evidence review, and risk documentation. Focus on evaluating control gaps, tracking remediation, validating closure evidence, and improving TPRM processes and tooling.

Location: Manila, Philippines (flexible hybrid work)

Company

hirify.global provides an AI-powered experience orchestration platform connecting people, systems, data, and AI for more than 8,000 organizations worldwide.

What you will do

  • Manage the third-party risk management workflow from intake and due diligence through assessment completion and ongoing monitoring.
  • Conduct initial and recurring third-party security risk assessments, including control evaluation, risk rating, and residual-risk documentation.
  • Administer the UpGuard assessment platform, including vendor onboarding, questionnaire distribution, response tracking, evidence collection, and workflow management.
  • Review SOC 2 reports, ISO 27001 certificates, policies, standards, penetration-test summaries, and other vendor security artifacts to identify control gaps.
  • Document findings, develop risk narratives, recommend remediation or compensating controls, and track closure evidence.
  • Improve TPRM processes, templates, playbooks, reassessment cycles, and monitoring activities.

Requirements

  • Bachelor’s degree in information security, IT, cybersecurity, or a related field.
  • Minimum of 2 years of related experience in information security, IT audit, risk, compliance, vendor management, or GRC is preferred.
  • Strong critical-thinking, analytical, documentation, and stakeholder-management skills.
  • Ability to interpret vendor security questionnaires, SOC reports, policies, and other complex compliance artifacts.
  • Strong verbal and written communication skills, with the ability to translate control gaps into clear risk statements.
  • Ability to learn new tools quickly and work effectively in process-driven environments.

Culture & Benefits

  • Work with AI-powered technology used by more than 8,000 organizations worldwide.
  • Flexible ways of working within a global team of nearly 7,000 employees.
  • Mentorship, learning programs, leadership development, and education support.
  • Paid volunteer time, August Free Fridays, well-being resources, and regionally tailored employee and family programs.
  • hirify.global is Great Place to Work certified in 17 countries.

Hiring process

  • Application review by Talent Acquisition and the hiring team.
  • Zoom interview followed by meetings with the hiring manager and interview team.
  • Most processes include no more than five interviews before final steps are confirmed.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →