GDS Advisory - Third Party Risk Management Consultant Ernst & Young Pvt. Ltd. Philippines (Philippines) (Salary Not Disclosed)

November 29, 2018 | Job Postings

Job Description:

Assist Managers in the delivery of third party risk management engagements, such engagements involve performing a security assessment of a clients third party service providers.

This involves:

  • Performing security assessments of new and existing service providers
  • Performing vendor assessment reviews leveraging a SIG Lite or Full SIG
  • Verifying that all required SIG (Lite) questions have been answered by vendor and all required documentation has been received
  • Assessing vendor answers and follow up with vendor directly for questions
  • Conducting a risk analysis and assessment of vendor information and documentation against a clients IT security and data privacy requirements
  • Identifying whether additional information should be obtained from the vendor
  • Defining appropriate risk levels and corrective actions
  • Identifying issues and work with vendor to resolve/accept
  • Following up on corrective action plans
  • Maintaining issues/items tracker and status updates for each vendor review.
  • Provide risk acceptance and/or risk remediation recommendations
  • Understanding of key industry control frameworks (NIST Cyber Security Framework, COSO, COBIT, ISO 27000, Unified Compliance Framework, etc.)

Provide guidance and share knowledge with team members and participate in performing procedures focusing on complex, judgmental and/or specialized issues.

Maintain relationships with client management to manage expectations of service, including work products, timing, and deliverables. Demonstrate a thorough understanding of complex information systems and apply it to client situations

Use extensive knowledge of the client's business/industry to identify technological developments and evaluate impacts on the client's business. Demonstrate strong project management skills, inspire teamwork and responsibility with engagement team members, and use current technology/tools to enhance the effectiveness of deliverables and services. Understand EY and its service lines and actively assess what the firm can deliver to serve clients

For More Info. Go To: