Epicareer Might not Working Properly
Learn More

Third Party Security Risk Lead

Salary undisclosed

Apply on


Original
Simplified
Do you want to take the first step in making Filipinos’ lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation! G ka ba? Join the G Nation today!

Third Party Security Risk Lead Job Description

  • Organize and manage the execution of periodic and onboarding Third Party Security Risk Management activities
  • Perform comprehensive cybersecurity risk assessments of third-party vendors and partners to identify potential risks and evaluate their overall risk profile. Work and build strong relationships with Relationship or Engagement Managers to complete assessments and monitor remediation plans where applicable.
  • Identify gaps or issues from the third party cybersecurity risk assessments and monitor remediation of gaps identified during the assessment process.
  • Develop and maintain a robust risk assessment framework for third-party relationships, including conducting due diligence, reviewing contracts, and assessing third party security controls, and providing recommendations to remediate risks, as appropriate.
  • Provide guidance and support to business units on selecting and engaging with third-party vendors, including evaluating potential risks and negotiating contractual terms.
  • Identify and escalate any emerging risks or issues related to third-party relationships to senior management, and propose appropriate risk mitigation strategies.
  • Stay abreast of industry trends, regulatory changes, and emerging best practices in third-party risk management, and proactively recommend enhancements to the risk management program.
  • Conduct regular assessments of third-party risk management processes to ensure effectiveness and compliance with internal policies and external regulations.
  • Maintain accurate and up-to-date documentation of third-party risk assessments, remediation plans, and other related activities.
  • Create reports on third party security risk team KPIs for management and relevant stakeholders
  • Assist with the Third Party Cybersecurity Risk Management Awareness and Training initiatives


Qualifications

  • 3+ years of demonstrated experience in Cybersecurity and understanding of Cybersecurity domains
  • Strong understanding of Third Party Cybersecurity Risk Management framework
  • Experience with TPRM tools such as Archer, ServiceNow, etc.
  • Demonstrated knowledge of standards such as ISO 27001/2, PCI DSS, NIST 800-53/NIST Cybersecurity Framework, etc.


Good To Have

  • Certifications (CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer)


What We Offer

Opportunity for career growth and development in the #1 FinTech company in the country Working with a dynamic and highly collaborative team who want to change the game A company that values their people with highly competitive and flexible compensation and benefits package