Position Title: Third Party Risk Analyst
Department: Cyber Assurance / Cyber Security
Location: First Avenue
Position Overview:
The Third Party Risk Analyst is responsible for assessing and managing risks associated with third-party vendors and partners. The role includes conducting risk assessments, monitoring compliance, managing findings, and collaborating with internal teams to ensure compliance with risk management policies and regulations.
Key Responsibilities:
Risk Assessment:
- Assess third-party vendors’ risks in data security, infrastructure security, compliance, and operational resilience.
- Categorize vendors based on risk levels and their importance to the organizationn
Due Diligence:
- Review vendors’ security controls and regulatory compliance before engagement.
- Ensure all vendors meet security requirements.
Vendor Monitoring:
- Continuously monitor vendors for changes in risk, compliance, and performance.
- Maintain a vendor risk dashboard to track metrics and update management.
Issues Management:
- Identify, document, and prioritize risk findings.
- Develop and track remediation plans to resolve risks.
- Communicate issues and ensure follow-up actions are completed.
Collaboration & Communication:
- Work with internal teams (e.g., DPO, Tech, Legal, Procurement, Compliance) to integrate risk management practices.
- Share risk findings and recommendations with stakeholders.
Policy & Procedure Development:
- Assist in developing and implementing risk management policies and frameworks.
- Ensure alignment with best practices and regulatory requirements.
Training & Awareness:
- Conduct training on third-party risk management.
- Guide business units on managing vendor risks.
Gen AI Capabilities:
- Understand AI fundamentals, including Large Language Models (LLMs), and apply this knowledge to assess and mitigate vendor risks effectively.
Qualifications:
- Bachelor's degree in Computer Science, Risk Management, Information Security, or related field.
- 3+ years of experience in risk management or vendor management.
- Strong knowledge of risk assessment methods and third-party risk management.
- Familiarity with standards like ISO 27001, NIST, GDPR, etc.
- Excellent analytical, communication, and interpersonal skills.
- Experience with GRC software and tools is a plus.
Must-Have Skills:
- 3-5+ years in cybersecurity risk assessments or vendor management.
- Familiarity with security frameworks like NIST CSF, ISO 27001, SOC 2.
- Experience with vendor risk management platforms such as CyberGRX, OneTrust, BitSight, SecurityScorecard.
- Understanding of cloud security (AWS, Azure, Google Cloud) and SaaS security evaluations.
Good to Have:
- Knowledge of regulatory compliance standards (GDPR, CCPA, HIPAA, PCI-DSS).
- Security certifications (CISA, CRISC, CISSP, CISM).
- Experience with AI-driven security tools for risk assessment.
Job Types: Full-time, Contract
Contract length: 12 months
Pay: RM8,000.00 - RM10,500.00 per month
Benefits:
- Health insurance
- Professional development
Schedule:
- Monday to Friday
Work Location: In person