Description:
About the Role: This role helps reduce the cyber risk posed by third parties and protects S&P Global brands against possible attacks against our information assets by threat actors via backdoor created by our vendors. Primary responsibilities will include assessing Cybersecurity, Business Continuity controls for S&P third parties by conducting control risk assessments, risk recertifications, and continuously monitoring the vendors engaged by S&P.
Responsibilities and Impact: Working in Vendor Risk Management offers the opportunity to continuously enhance processes to meet the evolving requirements of various regulators. This challenging environment provides ample opportunities to expand your knowledge and expertise. In addition to risk assessments, recertification, and continuous monitoring, you will participate in various projects, allowing you to showcase and further develop your skills and experience.
- Conduct thorough Cybersecurity, Business Continuity, Artificial Intelligence, Cloud Service Prover and Privacy assessments for Vendors, evaluating their information security policies, procedures, and controls.
- Effectively collaborate with internal teams to identify critical vendors and assess their potential impact on the organization's cyber risk profile.
- Communicate risk assessment findings and recommendations to key stakeholders, including senior management, legal, and compliance teams.
- Work closely with vendors to address identified security gaps and ensure they meet the organization's cybersecurity requirements.
- Review the vendors on the continuous monitoring program and assisting in driving the periodically review the vendors.
- Monitor and stay abreast of evolving cybersecurity threats and industry trends to enhance the effectiveness of the risk assessment process.
- Lead and support enhancement projects within Vendor Risk Management to meet various business and regulatory requirements.
- Assist the team members in balancing the load and managing Ad-hoc projects.
What We’re Looking For
Basic Required Qualifications:
- Bachelor’s degree in computer science or engineering or equivalent
- Minimum 5 years of experience in Information Security or Technology Risk Management
- Any prior exposure to vendor risk management and/ or privacy laws and regulations is a plus.
- Demonstrable understanding of the concepts of technology controls and information security controls.
- Exposure to cloud technologies and cloud security is highly desired; the familiarity with pubic cloud technologies such as Amazon Web Services (AWS) or Microsoft Azure or Google Cloud is highly preferred.
- Excellent communication skills - a must. The resource should have the ability to communicate with cross-functional teams and vendors, both written and oral communication is critical.
Additional Preferred Qualifications
- This position is required to work in UK Shift; flexibility is a must, especially when it comes to vendor and internal meetings held during US business hours.
- Strong organizational skills with the ability to multitask and prioritize while maintaining close attention to detail.
- Ability to build strategic partnerships with internal stakeholders.
- Must be a critical thinker with strong qualitative skills.
- Information Security/Risk Management certification would be an advantage.