OCRA /Third Party Risk Assessor
3 days ago
United States - New York
Information Technology (IT)
Group Functions
Job Reference #
324367BR
City
New York
Job Type
Full Time
Your role
You will be responsible for evaluating the security posture of third-party vendors that have access to sensitive information or systems of UBS. You will conduct risk assessments to identify and evaluate potential security threats posed by third-party vendors and recommend risk mitigation strategies to minimize the organization's exposure to cyber threats. You will also work closely with internal stakeholders to ensure that third-party vendors comply with our cybersecurity policies and procedures.
Are you keen on working in world class Cyber Security Operations Center for one of the best Swiss private banks? Do you have related experience and are willing to take it further by learning how to defend an enterprise against cyber-attacks? Do you have the right attitude and are eager to join a multinational team of Cyber Security professionals?
We are looking for OCRA/Third Party Risk Assessor to:
- be responsible for evaluating the security posture of third-party vendors that have access to sensitive information or systems of UBS
- conduct risk assessments to identify and evaluate potential security threats posed by third-party vendors and recommend risk mitigation strategies to minimize our organization's exposure to cyber threats and identify potential security threats and vulnerabilities
- work closely with internal businesses to ensure that third-party vendors comply with our cybersecurity policies and procedures and conduct Cloud assessments and audits
- analyze and evaluate vendor security controls, policies, and procedures to ensure compliance with regulatory requirements and industry best practices
- develop and implement risk mitigation strategies to address identified vulnerabilities and reduce our organization's exposure to cyber threats and communicate assessment findings and recommendations to leads, including management, legal, and compliance teams
- monitor and track vendor compliance with security policies and procedures through ongoing assessment activities
Detailed salary information:
- New York: the salary range for this role is $140000 to $180000
The expected salary range(s) for this role as of the date of this posting is/are based on factors including, but not limited to, experience, qualifications, education, location and skill level. This role may also be eligible for discretionary incentive compensation. For benefits information, please visit
Your team
You'll be working in the CISO/OCRA (Operational Consolidate Risk assessment) team in New York. You'll take a part in supporting colleagues from different areas of our firm, including Risk Taxonomy Owners, Compliance & Operational Risk Controllers and Outsourcing & Supplier Management, in improving the overall risk assessment process and implementing the most effective remediation measures.
Your expertise
- Bachelor's degree with professional certification in Cybersecurity, Cloud Security, or a related field of study
- audit experience/mindset
- ideally 5+ years of experience in third-party risk assessment or cybersecurity assessment with strong analytical and problem-solving skills
- certifications such as Certified Third-Party Risk Professional (CTPRP) or Certified Information Systems Security Professional (CISSP) are a plus
- experience with industry recognized standards for IT security controls and best practices like NIST, ISO27001, PCI DSS, COBIT, SOC 2 etc.;
- one of the following professional qualifications obtained: CEH, CISSP, CISA, CISM, CRISC or ITIL.
- ability to communicate effectively with good spoken and written English
"At UBS, we appreciate our Veterans and are committed to providing opportunities in Financial Services."
- LI-UBS
- UBS-MOGUL
About us
UBS is the world's largest and the only truly global wealth manager. We operate through four business divisions: Global Wealth Management, Personal & Corporate Banking, Asset Management and the Investment Bank. Our global reach and the breadth of our expertise set us apart from our competitors.
We have a presence in all major financial centers in more than 50 countries.
How we hire
We may request you to complete one or more assessments during the application process. Learn more
Salary information
US Only: The expected salary range for this role is $140000 to $180000 based on factors including, but not limited to, experience, qualifications, education, location and skill level. Please see «Your role» section for detailed salary information.
Join us
At UBS, we know that it's our people, with their diverse skills, experiences and backgrounds, who drive our ongoing success. We're dedicated to our craft and passionate about putting our people first, with new challenges, a supportive team, opportunities to grow and flexible working options when possible. Our inclusive culture brings out the best in our employees, wherever they are on their career journey. We also recognize that great work is never done alone. That's why collaboration is at the heart of everything we do. Because together, we're more than ourselves.
We're committed to disability inclusion and if you need reasonable accommodation/adjustments throughout our recruitment process, you can always contact us.
Contact Details
UBS Business Solutions SA
UBS Recruiting
Disclaimer / Policy statements
UBS is an Equal Opportunity Employer. We respect and seek to empower each individual and support the diverse cultures, perspectives, skills and experiences within our workforce.
-
Program Manager: Third Party Risk Management
3 days ago
New York, New York, United States Matlen Silver Full time $80,000 - $120,000 per yearJob Title:Contract Program Manager – Third Party Risk Management (TPRM)Contract Length:6–12 Months (with potential for extension)Location:NYC- hyrbidOverview:We're seeking an experiencedContract Program Managerto support and strengthen ourThird Party Risk Management (TPRM) Program. This role is responsible for driving integration across the full...
-
New York, New York, United States American Express Full time $219,000 - $338,250 per yearAt American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new...
-
Third Party Risk Analyst
4 days ago
New York, New York, United States Agency Cybersecurity Full time $60,000 - $80,000 per year*About Agency Cybersecurity:*Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance. Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently. We're backed by top tier investors like Y...
-
VP, Enterprise Risk Management
5 days ago
New York, New York, United States Coda Search│Staffing Full time $150,000 - $250,000 per yearOur client is a publicly traded real estate investment platform with a diversified portfolio of mortgage-related assets and a growing advisory and mortgage-origination footprint. Through recent strategic acquisitions, the firm has expanded into residential mortgage origination, real estate credit asset management, and third-party advisory services. The...
-
Manager - Risk Management
3 days ago
New York, New York, United States American Express Full time $89,250 - $150,250At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new...
-
Operational Risk Management Department
3 days ago
New York, New York, United States Bank of China USA Full time $100,000 - $150,000 per yearEstablished in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade...
-
New York, New York, United States JPMorganChase Full time $150,000 - $250,000 per yearJOB DESCRIPTIONJoin the Advanced Media Solutions team, a team of media and technology professionals focused on AI configuration and enablement across JPMorganChase Paid Media. This team works in close partnership with paid media subject matter experts, Controls, Compliance, Legal and Sourcing. They ensure the solutions are delivered end-to-end, while...
-
New York, New York, United States Pfizer Full time $256,100 - $426,000 per yearRole SummaryOur Global Cybersecurity Governance, Risk, and Compliance (GRC) team plays a critical role in safeguarding Pfizer's digital assets, ensuring regulatory compliance, and protecting sensitive data across all business functions. As part of our strategic commitment to strengthening our cybersecurity posture, we are enhancing and modernizing our GRC...
-
VP, Buy Side Market Risk
14 hours ago
New York, New York, United States Coda Search│Staffing Full time $150,000 - $250,000 per yearOur client is a publicly traded, internally managed real estate investment platform with a diversified portfolio across mortgage-related assets and growing complementary businesses. With more than 400 employees, the organization is scaling rapidly and investing in leadership talent to strengthen governance, controls, and enterprise risk management.The firm...
-
Director, Governance, Risk, and Compliance
5 days ago
New York, New York, United States adswizz Full time $182,000 - $245,000 per yearNew York, New YorkRegular Employee Full-TimeR HybridWho We Are:SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners - in the car, at home, and anywhere on...