Information Security - Third-Party Risk Management Senior Associate (CEBU SITE)

icon building Company : Ey
icon briefcase Job Type : Full Time

Number of Applicants

 : 

000+

Click to reveal the number of candidates who applied for this job.

Job Description - Information Security - Third-Party Risk Management Senior Associate (CEBU SITE)

Information Security - Third-Party Risk Management Senior Associate (CEBU SITE)

Security (Information & Communication Technology)

We’re looking for a Senior Security Consultant with expertise in cyber/information security, risk and controls concepts. This is an opportunity to be part of a market-leading, multi-disciplinary consulting firm whilst being instrumental in the growth of the risk, compliance, and resilience sub-competency, in the only integrated global transaction business worldwide. 

Your key responsibilities:

  • Ensure smooth delivery of third-party risk management engagements, which involve performing security assessments of the client’s third-party service providers/vendors. Activities may include, but are not limited to:
  • Performing security assessments of new and existing service providers which includes assessing vendor responses and following up with vendor directly for clarifications or additional documentation 
  • Conducting a risk analysis and assessment of vendor information and documentation against client IT security and data privacy requirements
  • Defining appropriate risk levels and corrective actions
  • Identifying process gaps, risks to the client’s environment and providing risk remediation recommendations 
  • Working with the client’s business units and/or vendors to understand and accept recommended remediation steps
  • Monitoring risk exposures through closure
  • Understanding, reviewing, revising or drafting client security policies, basing on client requirements and industry security standards =
  • Develop and maintain productive working relationships with client personnel
  • Work effectively as an individual contributor and as a team member, consistently demonstrating accountability, providing support, effectively communicating within the unit 
  • Execute engagement requirements, along with review of work by junior team members
  • Proactively developing, maintaining and sharing accurate engagement and deliverable status reporting to relevant stakeholders at different levels 
  • Build strong internal relationships within EY Consulting Services and with other services across the organization
  • Understand and follow workplace policies and procedures
  • Contribute to people-related initiatives including recruiting and retaining Cyber Transformation professionals
  • Support skills development of junior/staff level peers 
  • Building a quality culture at EY GDS
  • Provide feedback for performance reviews staff/junior level team members, where applicable 
  • Manage the performance management for direct reportees, as per the organization policies
  • Foster teamwork and lead by example
  • Participating in the organization-wide people initiatives

Primary Qualifications: 

  • Strong knowledge of cybersecurity and industry leading frameworks
  • 3-5 Years of relevant experience (i.e. IT auditing, information security audit/assessment experience)
  • Experience in MS Office – Excel, PowerPoint, Word
  • Strong stakeholder management skills – ability to communicate with various stakeholders timely and effectively
  • Strong project management skills – executing day-to-day operations within established deadlines
  • Strong team management skills - leading medium to large engagements and coaching junior team members 
  • Effective written and verbal communication skills where ideas are expressed clearly and can be understood by the intended audience
  • Collaborative mindset – when working with peers on internal initiatives and when working with clients, understanding of challenges as well as showcasing ability to provide meaningful insights on cybersecurity projects or internal EY initiatives 
  • Strong knowledge in key components of cybersecurity including (but not limited to):
    • Regulations/standards such as ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, NIST 800-53
    • Third Party Vendor/Supplier Risk Assessments and Risk Management
    • Business Continuity & Disaster Recovery
    • Cyber Strategy & Governance, Cyber Transformation, Cyber Dashboarding
  • Experience working in client-facing roles, direct interaction with client stakeholders (business units, third parties, leadership), assessing different kinds of environments (IT and non-IT) and ability to apply cyber security concepts in all these sectors
  • Effective written and verbal communication skills where ideas are expressed clearly and can be understood by the intended audience 
Your application will include the following questions:

What's your expected monthly basic salary?

EY Global Delivery Services (GDS) is a dynamic global delivery network working across ten locations – Argentina, China, India, Poland, UK, Hungary, Sri Lanka, Mexico, Spain, and the Philippines – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. By combining skilled professionals, automation and advanced technology to build new solutions and services, EY GDS helps EY teams transform the client experience and deliver greater value, increasing efficiency and agility for clients while maintaining the same high quality and global standards that the EY organization is renowned for – from anywhere in the world. In the Philippines, EY GDS was set up in Manila in 2015. Starting out with just 25 employees, it has now grown to an organization with a strong 4,500+ headcount.

EY Global Delivery Services (GDS) is a dynamic global delivery network working across ten locations – Argentina, China, India, Poland, UK, Hungary, Sri Lanka, Mexico, Spain, and the Philippines – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. By combining skilled professionals, automation and advanced technology to build new solutions and services, EY GDS helps EY teams transform the client experience and deliver greater value, increasing efficiency and agility for clients while maintaining the same high quality and global standards that the EY organization is renowned for – from anywhere in the world. In the Philippines, EY GDS was set up in Manila in 2015. Starting out with just 25 employees, it has now grown to an organization with a strong 4,500+ headcount.

Don’t provide your bank or credit card details when applying for jobs.

What can I earn as a Management Associate

#J-18808-Ljbffr
Original job Information Security - Third-Party Risk Management Senior Associate (CEBU SITE) posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
icon no cv required No CV Required icon fast interview Fast Interview via Chat

Share this job with your friends

icon get direction How to get there?

icon geo-alt Cebu City, Central Visayas

icon get direction How to get there?
View similar Others jobs below

Similar Jobs in the Philippines

GrabJobs is the no1 job portal in the Philippines, connecting you to thousands of jobs fast! Find the best jobs in the Philippines, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2024 Grabjobs Pte.Ltd. All Rights Reserved.