Third Party Governance
3 days ago
**Third Party Governance Role**:
- **Vendor Risk Identification and Analysis**:
- Revise the Vendor Risk Assessment Playbook, Process, and Procedures to ensure they re up-to
- date with industry practices.
- Construct a risk assessment plan using a standardized approach to minimize the bank s exposure to third-party vendor risks.
**Third Party Cyber Risk Assessments**:
- Analyse third-party cyber risk assessment documents and procedures to ensure comprehensive risk management.
- Continually monitor and adapt to new risks, ensuring that assessment strategies are proactive.
**Tools, Measurement, and Analysis**:
- Scrutinize and validate cyber tools and create test cases to assess the effectiveness of third
- party cyber risk tools.
- Optimize the use of JIRA for improved tracking and management of cyber assessments.
**Program Governance - Cyber PMO**:
- Establish a Cyber Program Management Office to oversee and align cyber risk projects with organizational goals.
- Provide ongoing support for cyber risk initiatives and ensure effective communication among all stakeholders.
**Vendor Risk Assessment and Mitigation**:
- **Assessment Scope and Connectivity**: Defining the scope of the assessment and identifying how
- vendor services connect with the organization s existing architecture.
- **Questionnaire Distribution and Assistance**: Tailoring assessment questionnaires based on vendor service applicability and facilitating stakeholders in completing them.
- **Evidence Review and Follow-ups**: Reviewing the evidence provided by stakeholders and conducting follow-up meetings for clarification and understanding of responses.
- **Gap Analysis and Validation**: Analysing the questionnaires to identify gaps and conducting validation sessions with stakeholders on the findings.
- **Risk Assessment Reporting**: Compiling the findings into a Risk Assessment Report that details the risks and their ratings.
The deliverables from this stage include a controls checklist for vendors and a comprehensive Risk Assessment report.
**For Risk Mitigation**:
- Propose recommendations and create an action plan for risk treatment.
- Review and evaluate proposed actions against the organization s risk acceptance criteria. For the **Cyber TPG Vendor Assessment**:
- Study and evaluate advanced assessment methodologies for vendors, including their effectiveness and applicability.
- Compare assessment methodologies like vBSIMM, SAMM against current vendor risk profiles.
- Evaluate vendors implementation and maintenance of Cloud SIEM solutions. For **Inherent Risk Profiling of the vendors**:
- Review the inherent cyber risk profiles (IRPs) for vendors within scope.
- Present a categorization of the vendors based on risk and determine the necessity of onsite assessments.
- Outline the scope of the assessment domains for the vendors.
- Analyze the alignment of vendor risk profiles with the organization s cybersecurity framework.
- Assess the necessity for an onsite assessment based on the vendor s risk tier and engagement level.
- Develop a comprehensive risk assessment timeline that accounts for the complexity and scope of vendor services.
The deliverables for these stages include detailed Inherent Risk Profiling which encompasses risk categorization, engagement level risk tiering, scheduling for assessments, and the approach and scope for each vendor.
- Min 5 to Max 10 yrs of relevant experience.
**Location**:
- Pune (Onsite role)
**Notice Period**
- Immediate to 30 days.
The roles will start remotely and those selected to convert to Full time would be expected to be onsite in Pune (preferred) or Chennai.
Hybrid - 3 days onsite/2 remote
-
Associate, Third Party Governance Ii
1 week ago
Pune, Maharashtra, India The Bank of New York Mellon Corporation Full time**Associate, Third Party Governance** At BNY, our culture empowers you to grow and succeed. As a leading global financial services company at the center of the world’s financial system we touch nearly 20% of the world’s investible assets. Every day around the globe, our 50,000+ employees bring the power of their perspective to the table to create...
-
Third-Party Risk Management
3 days ago
Pune, Maharashtra, India HSBC Full timeSome careers shine brighter than others.If you're looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.HSBC is one of the largest banking and...
-
Third-Party Risk Management
4 days ago
Pune, Maharashtra, India HSBC Full timeSome careers shine brighter than others.If you're looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.HSBC is one of the largest banking and...
-
Technology Third Party Risk Officer
3 days ago
Pune, India HSBC Full time-Job description Some careers shine brighter than others. If you’re looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further. HSBC is one of...
-
Third-party Risk Management
2 days ago
Pune, Maharashtra, India HSBC Global Services Limited Full timeSome careers shine brighter than others If you re looking for a career that will help you stand out join HSBC and fulfil your potential Whether you want a career that could take you to the top or simply take you in an exciting new direction HSBC offers opportunities support and rewards that will take you further HSBC is one of the largest banking and...
-
Third Party Technology Assurance Lead
4 days ago
Pune, Maharashtra, India Apex Group Full time ₹ 15,00,000 - ₹ 20,00,000 per yearA Third Party Technology Assurance Lead plays a critical role in safeguarding an organisations technology landscape by managing and assessing the risks associated with third-party vendors and service providers. The Lead proactively analyses, monitors, and assures the compliance, security, and operational effectiveness of external technology services upon...
-
Third Party Security Assessor
1 week ago
Mumbai, Maharashtra, India WTW Full timeRole: - Leading and coordinating the completion of Third-party assessment requests against WTW best practice and global standards and controls.- Scheduling periodical re-assessment in line with standards and controls- Agree scheduled checkpoints with the Third Party and WTW Service Owner on evidencing remediations and maintaining central repository, these...
-
Third Party Risk Management
1 week ago
Peth, Pune, India IDESLABS PRIVATE LIMITED Full time ₹ 9,00,000 - ₹ 12,00,000 per yearThird Party Risk Management Job Description:Conduct third party risk assessments in alignment with company security policies and industry standardsPerform on site assessments of vendors to identify opportunities for improvementProvide input and aid in the development of policies focused on the security of third party business processesFoster relationships...
-
Third Party Technology Assurance Analyst
2 weeks ago
Pune, Maharashtra, India Apex Group Ltd Full time ₹ 15,00,000 - ₹ 25,00,000 per yearThe Apex Group was established in Bermuda in 2003 and is now one of the world's largest fund administration and middle office solutions providers.Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully...
-
Third-Party Engagement Risk Lead, VP
4 days ago
Pune, Maharashtra, India Deutsche Bank Full time ₹ 9,00,000 - ₹ 12,00,000 per yearThe Global Real Estate (GRE) Divisions primary objective is to manage the building real estate portfolio of Deutsche Bank, inclusive of procurement, operations, and strategic planning. GRE has three key functions to support the delivery of these objectives, including Service Delivery Management.As the Third-Party Engagement Risk (TPER) Lead, you will part of...