Ops - Risk Analyst
RM 8,000 - RM 10,500 / month
Checking job availability...
Original
Simplified
Job Description:
Position Title: Third Party Risk Analyst
Department: Cyber Assurance / Cyber Security
Position Overview:
The Third Party Risk Analyst is responsible for managing and mitigating risks associated with third-party vendors and partners. This role involves assessing risks, monitoring vendor compliance, and working with internal teams to ensure third-party engagements comply with risk management policies and regulatory standards.
Key Responsibilities:
- Risk Assessment:
- Conduct risk assessments of third-party vendors, focusing on data security, compliance, and operational resilience.
- Categorize vendors based on risk levels and importance to the organization.
- Due Diligence:
- Perform due diligence on vendors to ensure compliance with security and regulatory standards before engagement.
- Vendor Monitoring:
- Continuously track vendor risk profiles, compliance, and performance.
- Maintain a vendor risk dashboard and provide regular updates to management.
- Issues Management:
- Identify and prioritize findings from risk assessments.
- Develop and track remediation plans for identified issues.
- Communicate issues and resolutions to stakeholders.
- Collaboration and Communication:
- Work with internal teams (DPO, tech, legal, procurement) to integrate third-party risk management into business processes.
- Share findings and recommendations with stakeholders.
- Policy and Procedure Development:
- Assist in creating and implementing third-party risk management policies and frameworks.
- Ensure compliance with industry best practices and regulations.
- Training and Awareness:
- Conduct training to raise awareness of third-party risk management within the organization.
- Support business units in managing vendor risks effectively.
- AI Awareness:
- Stay updated on AI trends, particularly Large Language Models (LLMs), and assess their impact on vendor risk management.
Qualifications:
- Bachelor's degree in Computer Science, Risk Management, Information Security, or a related field.
- 3+ years of experience in risk management, vendor management, or a related field.
- Strong knowledge of risk assessment methodologies and best practices for third-party risk management.
- Familiarity with regulatory standards like ISO 27001, NIST, GDPR, etc.
- Strong analytical, communication, and interpersonal skills.
- Ability to manage multiple tasks and collaborate with cross-functional teams.
- Experience with GRC software is a plus.
Must-Have Skills:
- 3-5+ years in cybersecurity risk assessments, vendor risk management, or IT security audits.
- Knowledge of security frameworks like NIST CSF, ISO 27001, SOC 2.
- Experience with vendor risk management platforms (e.g., CyberGRX, OneTrust, BitSight).
- Familiarity with cloud security (AWS, Azure, Google Cloud) and SaaS security evaluations.
Good to Have:
- Knowledge of compliance standards (GDPR, CCPA, HIPAA, PCI-DSS).
- Security certifications (e.g., CISA, CRISC, CISSP, CISM).
- Experience with AI-driven tools for third-party risk assessment.
Job Type: Contract
Contract length: 12 months
Pay: RM8,000.00 - RM10,500.00 per month
Schedule:
- Monday to Friday
Work Location: In person