Epicareer Might not Working Properly
Learn More

Risk Analyst

  • Full Time, onsite
  • MANPOWER STAFFING SERVICES (M) SDN BHD
  • Petaling Jaya, Malaysia
Salary undisclosed

Checking job availability...

Original
Simplified
Key Responsibilities: 1. Risk Assessment: Conduct comprehensive risk assessments of third-party vendors, focusing on areas such as data security, infrastructure security, compliance, and operational resilience. Evaluate vendor risk profiles and categorize vendors based on risk levels and criticality to the organization. 2. Due Diligence: Perform due diligence on prospective and existing vendors, including reviewing security controls and compliance with regulatory standards. Ensure that all vendors meet the organization's security requirements before engagement. 3. Vendor Monitoring: Continuously monitor third-party vendors for changes in risk profiles, compliance status, and performance. Maintain a vendor risk dashboard to track key metrics and provide regular updates to management. 4. Issues Management: Identify, document, and prioritize findings from risk assessments and vendor evaluations. Develop and track remediation plans for identified findings or issues, ensuring timely resolution and mitigation of risks. Communicate issues and remediation status to relevant stakeholders and ensure follow-up actions are completed. 5. Collaboration and Communication: Collaborate with internal departments such as DPO, Tech team, legal, procurement, and compliance to integrate third-party risk management practices into business processes. Communicate risk assessment findings and recommendations to stakeholders, ensuring transparency and informed decision-making. 6. Policy and Procedure Development: Assist in the development and implementation of third-party risk management policies, procedures, and frameworks. Ensure that all processes align with industry best practices and regulatory requirements. 7. Training and Awareness: Conduct training sessions and workshops to raise awareness of third-party risk management practices among internal teams. Provide guidance and support to business units on managing vendor risks effectively. 8. Gen AI capabilities: The Third Party Risk Analyst should grasp AI fundamentals, recognize the evolving landscape of LLMs (Large Language Models) and their practical applications, and integrate this awareness to anticipate vendor alignment while critically assessing risks and advocating for mitigation when necessary. Qualifications: Bachelor's degree in Computer Science, Risk Management, Information Security, or a related field. More than 3 years of experience in risk management, vendor management, or a related role. Strong understanding of risk assessment methodologies and third-party risk management best practices. Familiarity with regulatory requirements and industry standards such as ISO 27001, NIST, GDPR, etc. Excellent analytical, communication, and interpersonal skills. Ability to work collaboratively with cross-functional teams and manage multiple tasks simultaneously. Proficiency in GRC software and tools is a plus.