Third Party Risk
2 months ago
Top Skills' Details
* Knowledgeable in multiple areas of technology, with hands-on experience and technical expertise across all Information Security domains
* Experienced with local, national, and international financial services and privacy regulations, such as GLBA, NYDFS, GDPR, CCPA, etc. and credit card industry standards, such as PCI-DSS.
* An agile thinker, passionate and energetic; highly collaborative, possessing strong cultural awareness
* Fantastic written and verbal communication skills
Job Description
In this role, the candidate will work closely with General Counsel Organization, Third Party Lifecycle Management, Global Procurement, and Global Business Units to ensure third parties adhere to security requirements.
The candidate will participate in and represent Information Security and IT Risk during contract negotiations relevant to third party cybersecurity oversight and will develop and maintain cybersecurity requirements for third parties.
Primary Responsibilities
* Provide Information Security subject matter expertise to General Counsel Organization, Third Party Lifecycle Management, Global Procurement, and Global Business Units organizations for the inclusion of Information Security and IT Risk requirements into third party supplier and non-supplier contracts
* Negotiate cybersecurity contractual addendums, riders, etc. directly with third party account managers, attorneys, and information security staff; effectively communicate requirements to technical and non-technical representatives of third parties
* Facilitate alignment across internal and external third party stakeholders
* Evaluate criticality of issues and advise internal stakeholders with a risk-based approach and an understanding of Business objectives
Additional Responsibilities
* Provide feedback to leadership, including regular reporting and metrics, in order to assist with the governance and overall growth of the third party security program
* Provide guidance during risk acceptance process relating to third parties
* Understand cybersecurity and regulatory issues specific to the third party landscape by connecting with peers, experts, standards organizations, and industry forums
* Provide training, including the development of training materials, to internal stakeholders
* Partner with internal stakeholders to develop, improve, and document processes
* Assist with and participate in third party cyber incident response and outreach activity as needed
Qualifications
* 7-10 years of experience, in positions of increasing responsibility, in Information Security risk assessments, cyber security operations, threat and vulnerability management, security architecture, or cyber security incident response
* Prior experience with contract negotiation
* Ability to effectively communicate and articulate Information Security risks
* Understanding of what information or assets are of value to threat actors and how organizations and data are breached, including through relationships with external third parties
* Strong familiarity with industry standards and control frameworks, risk assessment frameworks, security assurance auditing standards, best practices guidelines, such as ISO27001, NIST CSF, FAIR, SSAE16/18, CSA, CIS Top 20, OWASP Top 10, etc.
* Understanding of and experience with modern security controls, technologies, and procedures, including: vulnerability scanning, penetration testing, encryption, endpoint and anti-malware protection, network security, DLP systems, logging systems, physical security systems etc.
* Strong familiarity with cloud based services, architectures, and underlying management frameworks
* Familiar with network architectures and data exchange protocols, such as API usage, secure file transfers, etc.
* Familiar with cyber resiliency, disaster recovery, and business continuity concepts
* Basic understanding of cyber incident response, investigation, and forensic analysis
* Must have excellent verbal and written communication skills, interpersonal collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences.
* Must possess the ability to multitask, prioritize, and manage time effectively
* Must be able to pay strong attention to detail
* Bachelor's degree in Cybersecurity, Computer Science or Information Systems, or equivalent combination of education and experience preferred
* CISSP, CISM or similar certifications preferred
***NOTE: some off-hours work may be required depending on candidate time zone.
-
Third Party Risk Specialist
2 weeks ago
New York, New York, United States TEKsystems Full timeJob SummaryTEKsystems is seeking a highly skilled Third Party Risk Specialist to join our team. As a key member of our Information Security team, you will be responsible for ensuring the security and compliance of third-party vendors and suppliers.Key Responsibilities:Provide Information Security subject matter expertise to internal stakeholders for the...
-
Third Party Risk Management Specialist
2 weeks ago
New York, New York, United States Amalgamated Bank of NY Full timeJob SummaryThe Third Party Risk Management Analyst plays a crucial role in the development and execution of the Bank's Enterprise Third Party Risk Management Program. This program aims to measure, monitor, assess, and report on the control of third-party vendor risk throughout the enterprise.The ideal candidate will have a strong understanding of finance,...
-
IT Manager, Third Party Risk Professional
2 weeks ago
New York, New York, United States Brookfield Properties Full timeJob Title: IT Manager, Third Party Risk ProfessionalAbout the Role:We are seeking an experienced IT Manager, Third Party Risk Professional to join our team at Brookfield Properties. As a key member of our Information Security team, you will play a crucial role in overseeing the operational and strategic aspects of our third-party cyber risk program.Key...
-
AVP Third Party Risk
4 months ago
New York, United States Broadgate Full timeWhat You’ll Do • Support the Maturity of the Third-Party Risk Management Program by providing recommendations and helping to provide strategy deliverables. • Be open to change and provide leadership by leading TPRM staff across the enterprise to welcome/accept change. • Provide periodic reports to management and stakeholders. • Manage vendor...
-
Third Party Risk Management Specialist
1 month ago
New York, New York, United States Amalgamated Bank of NY Full timeJob SummaryWe are seeking a highly skilled Third Party Risk Management Analyst to join our team at Amalgamated Bank of NY. The successful candidate will be responsible for supporting the development and execution of our Enterprise Third Party Risk Management Program.Key ResponsibilitiesCollaborate with business stakeholders to ensure compliance with...
-
Third-Party Risk Management Lead
4 weeks ago
New York, New York, United States Federal Reserve System Full timeJob Title: Third-Party Risk Management, 4th Party Program LeadAt the Federal Reserve System, we are seeking a highly skilled Third-Party Risk Management, 4th Party Program Lead to join our team. As a key member of our Risk Management department, you will be responsible for developing, implementing, and administering the Third-Party Risk Management 4th Party...
-
Third-Party Vendor Risk Management Specialist
1 month ago
New York, New York, United States IntelliPro Group Inc. Full timeJob DescriptionIntelliPro Group Inc. is seeking a highly skilled Third-Party Vendor Risk Management Specialist to join our team. As a key member of our risk management team, you will be responsible for overseeing the Financial Services Third-Party Vendor Risk Management program.The ideal candidate will have prior experience independently managing Third-Party...
-
Third-Party Vendor Risk Management Specialist
2 weeks ago
New York, New York, United States IntelliPro Group Inc. Full timeJob DescriptionIntelliPro Group Inc. is seeking a highly skilled Third-Party Vendor Risk Management Specialist to join our team. As a key member of our risk management team, you will be responsible for overseeing the Financial Services Third-Party Vendor Risk Management program.The ideal candidate will have prior experience independently managing Third-Party...
-
Third Party Vendor Risk Management Specialist
2 weeks ago
New York, New York, United States Brandon Consulting Associates, Inc. Full timeJob DescriptionBrandon Consulting Associates, Inc. is seeking a highly skilled Third Party Vendor Risk Management Specialist to join our team. The ideal candidate will have a strong background in risk management and be able to oversee the company's third-party vendor risk management program. The Specialist will be responsible for identifying, assessing, and...
-
Third Party Risk Measurement Program Manager
2 weeks ago
New York, New York, United States Tik Tok Full timeJob Summary TikTok is seeking a highly motivated and experienced Privacy Program Manager to lead our Third Party Risk Measurement program. As a key member of our Privacy and Data Protection Office, you will be responsible for identifying, managing, and mitigating risks associated with Bytedance's third parties. Responsibilities • Support the program to...
-
Third Party Risk Measurement Program Manager
2 weeks ago
New York, New York, United States Tik Tok Full timeAt TikTok, we're committed to creating an inclusive environment where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe, and so does our workplace.We're passionate about inspiring creativity and bringing joy to our users. To achieve this goal, we're dedicated to celebrating our...
-
New York, New York, United States Tik Tok Full timeAbout the RoleWe are seeking a highly motivated and experienced Privacy Program Manager to join our team in Third Party Risk Measurement. As a key member of our Privacy and Data Protection Office, you will be responsible for leading, supervising, and empowering all TikTok's privacy work in an accountable and industry-leading way.Key ResponsibilitiesSupport...
-
New York, New York, United States Tik Tok Full timeJob Title: Privacy Program Manager, Third Party Risk MeasurementTikTok is a leading destination for short-form mobile video, and we're committed to inspiring creativity and bringing joy to our users. As a Privacy Program Manager, Third Party Risk Measurement, you'll play a critical role in ensuring the privacy and security of our users'...
-
New York, New York, United States Tik Tok Full timeJob SummaryTikTok is seeking a highly skilled Privacy Program Manager to lead our third-party risk management efforts. As a key member of our Privacy and Data Protection Office, you will be responsible for identifying, managing, and mitigating risks associated with Bytedance's third-party vendors.Key Responsibilities Support the development of our...
-
New York, New York, United States Tik Tok Full timeJob Title: Privacy Program Manager, Third Party Risk MeasurementAbout the Role:TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. We create together and grow together, driving impact for ourselves, our company, and the communities we serve.The Privacy and Data Protection Office (PDPO) leads,...
-
New York, New York, United States Tik Tok Full timeJob DescriptionTikTok is a leading destination for short-form mobile video, and we're looking for a talented individual to join our team as a Privacy Program Manager, Third Party Risk Measurement. As a key member of our Privacy and Data Protection Office, you will play a critical role in driving privacy best practices across the...
-
Lead Security Analyst, Third Party Security
1 month ago
New York, New York, United States CIRCLE Full timeAbout CircleCircle is a pioneering financial technology company at the forefront of the emerging internet of money. Our mission is to create an inclusive financial future with transparency at our core.Job SummaryWe are seeking a highly skilled Lead Security Analyst to join our Third Party Security team. As a key member of our security team, you will design...
-
Third-Party Vendor Compliance Specialist
2 months ago
New York, New York, United States Vista Global Full timeAbout the RoleVista Global is a leading private aviation business, renowned for its exceptional service, safety, and reliability. We are seeking a highly motivated Auditor to join our Malta Head Office or work remotely from the United Kingdom.Key ResponsibilitiesConduct ongoing vetting of third-party vendors to ensure compliance with Vista Global's...
-
Third-Party Vendor Approvals Auditor
2 months ago
New York, New York, United States Vista Global Full timeAbout Vista GlobalVista Global is a leading private aviation business, operating the world's largest wholly owned large cabin private jet fleet. We pride ourselves on delivering exceptional service, safety, security, reliability, and value to our clients.Our CultureWe believe our employees are our greatest asset, and we strive to create an environment that...
-
Third-Party Vendor Approvals Auditor
4 months ago
New York, United States Vista Global Full timeJob Profile Vista is a fast-growing private aviation business, operating the world’s largest wholly owned large cabin private jet fleet, embracing the highest levels of service, safety, security, reliability, and value. Providing exceptional and unparalleled standards of quality, style, and service. Our employees are regarded as our greatest...