freehire launches on Product Hunt on 26 August.

Follow →

Third-Party Risk Analyst

Open 41d

To rola z obszaru Third-Party Risk Management (TPRM), która łączy elementy cyberbezpieczeństwa, IT Risk, Vendor Risk Management oraz Compliance. Jest mocno skoncentrowana na ocenie ryzyka dostawców i partnerów zewnętrznych.

Główne wymagania

Technical / Domain Knowledge

  • 3–5 lat doświadczenia w:

    • Third-Party Risk Management (TPRM)

    • Vendor Risk Management (VRM)

    • Cybersecurity Risk

    • IT Risk Management

  • Praktyczne doświadczenie w:

    • vendor security assessments

    • supplier due diligence

    • cybersecurity questionnaires

    • security reviews

    • risk assessments

  • Znajomość frameworków:

    • NIST CSF

    • ISO 27001

    • SOC 2

    • ewentualnie CIS Controls

  • Rozumienie:

    • Information Security

    • Data Privacy

    • Business Continuity

    • Cloud Security

    • Identity & Access Management

    • Third-Party Security

Regulatory / Compliance

  • DORA

  • GDPR

  • SOX

  • ISO 27001

  • NIST

  • EBA Guidelines

  • PCI DSS (mile widziane)

  • HIPAA (jeżeli sektor healthcare)

Narzędzia:

  • ServiceNow VRM

  • OneTrust

  • Archer

  • ProcessUnity

  • BitSight

  • SecurityScorecard

  • RiskRecon

  • CyberGRX

  • Shared Assessments SIG

  • Jira

  • Confluence

Soft Skills

  • Risk Analysis

  • Critical Thinking

  • Vendor Management

  • Stakeholder Management

  • Communication

  • Documentation

  • Report Writing

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available