Vendor Infrastructure IT Risk Manager - Chief Risk Office

Selby Jennings

  • New York, NY
  • 1 day ago
  • $45–$65 Per Hour
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Artificial Intelligence (AI)unmatched
  • Auditingunmatched
  • Cloud Computingunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Control Objectives for Information and related Technology (COBIT)unmatched
  • Customer Support/Serviceunmatched
  • Due Diligenceunmatched
  • Geographyunmatched
  • ISO (International Organization for Standardization)unmatched
  • Identity Data Managementunmatched
  • Industry Standardsunmatched
  • Information Architectureunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Infrastructure Softwareunmatched
  • Internal Auditunmatched
  • International Electro-Technical Commission (IEC)unmatched
  • Leadershipunmatched
  • Legalunmatched
  • Network Securityunmatched
  • Operations Planningunmatched
  • Operations Processesunmatched
  • PCI-DSSunmatched
  • Performance Metricsunmatched
  • Presentation/Verbal Skillsunmatched
  • Privacy Controlsunmatched
  • Privacy Regulationsunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Attacksunmatched
  • Software Developmentunmatched
  • Strategic Planningunmatched
  • Team Playerunmatched
  • Trend Analysisunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vendor/Supplier Evaluationunmatched
  • Vendor/Supplier Managementunmatched

Description

Base pay range $45.00/hr - $65.00/hrRole Senior Vice President (Cloud, Infrastructure & Software Development - EMEA & USA - Contracts) - Specialising in Financial ServicesWhat\u2019s The Role?We are looking for a Vendor Risk Manager with a strong background in Information Security, Operational Resilience, Technology Audit and/or Risk Management. You will work with our clients departments and subsidiaries to perform the inherent risk assessment of their vendor engagements, create and maintain the risk profile of vendors and vendor products / services, and drive control assessment and risk remediation activities across our vendor population while contributing to strategic initiatives to enhance the overall Vendor Risk program in line with our transformation roadmap. Your work will add value to my clients departments and subsidiaries that use third parties to achieve their goals, by helping them appropriately manage vendor risk throughout the vendor lifecycle.Responsibilities Liaise with business and technology teams to understand their use of vendor services and products and appropriately assess the inherent risks related to information security, privacy, resiliency, concentration, regulatory compliance, subcontracting, location / geography, among others.Maintain the vendor and vendor engagement inventory and risk profilesConduct due diligence control assessments, continuously monitor and report on Vendor and vendor engagement risksCoordinate risk mitigation activities with vendors and client departments and subsidiariesInterpret, train and enforce compliance with clients Vendor Risk Management PolicyCultivate and leverage relationships with CISO, Legal, Compliance, Enterprise Risk Management (ERM) and other control functions to accomplish objectivesLead key VRM activities and demonstrate understanding of the top and material risks affecting the client, our supply chains, and our clientsAct as subject matter expert on VRM matters supporting client departments for which you are responsibleProvide advisory support to client departments on riskProvide and coordinate input to key compliance, legal and regulatory initiativesDemonstrate existing or develop targeted material to deliver actionable risk reporting to client departments as neededParticipate in select risk committees / working groupsQualifications Bachelor\u2019s or master\u2019s degree in Computer Science, Information Security, Business Management or equivalent industry experience5+ years of experience working in the field of Risk Assurance, Risk Management, Internal Audit or other Compliance-related experienceAn understanding of Cloud Computing and how to assess cloud-related risksFamiliarity with international regulations regarding third-party service providersKnowledge of international regulations governing third-party service providersExperience with industry frameworks and standards such as NIST 800-53, COBIT 5, ISO/IEC 27001/2, HITRUST, PCI DSS, CSA CAIQ/CCM, CIS CSC, and NIST 800-171Understanding of global data privacy laws and regulations, including GDPR, Schrems II, CCPA, and HIPAAFamiliarity with emerging regulatory requirements, such as the Digital Operational Resilience Act (DORA) and the EU Artificial Intelligence ActExperience working with vendor risk assessment frameworks and tools (e.g., SIG, VSAQ)Technical knowledge in multiple risk domain areas such as application, architecture, system and network security, identity/access management, etc.Knowledge of current Information Security threats, trends, and mitigationsSkilled in risk management, technical risk analysis, and making complex business/risk trade-off recommendations and decisionsUnderstanding of impact of financial, technology and privacy regulations on Fintech products and servicesDemonstrated ability to lead and influence othersSenior level written and verbal communication skillsDemonstrated leadership, teamwork and collaboration skillsNice to Have An understanding of supplier agreements, contractual terms and service level agreementsExperience in developing and deploying operational performance metrics to measure IT security effectiveness and operational resilienceExperience with Cloud-based IT architectures and securitySeniority level Mid-Senior levelEmployment type ContractJob function Information Technology#J-18808-Ljbffr

Numbers & Facts

LocationNew York, NY
Salary$45–$65 Per Hour

Similar Jobs

See more jobs