KEY RESPONSIBILITIES: 

Conduct comprehensive cybersecurity risk assessments of third-party vendors and partners to evaluate their security controls and practices.
Ensure alignment to third-party cybersecurity risk management framework and related policies and procedures.
Collaborate with internal stakeholders, including sourcing, legal, and Technology teams, to assess contractual agreements and ensure cybersecurity requirements are met.
Monitor and track third-party cybersecurity incidents, vulnerabilities, and compliance with contractual obligations, and collaborate with the Cybersecurity Intelligence and Security Operations Centre (CiSOC) to respond.
Provide expertise and guidance on cybersecurity risk mitigation strategies to mitigate risks associated with third-party relationships.
Prepare detailed third-party risk assessment reports and present findings and recommendations to senior management and stakeholders.
Provide input into Cyber Security risk and control self-assessments by leveraging knowledge in third party cyber security and mitigating information and cyber risks identified by various assurance teams such as Information Risk and Audit.
Stay current with industry trends, emerging threats, and best practices in third-party risk management and cybersecurity. 
Support in the development, management, implementation, and delivery of the security awareness program for both third parties and internal staff in liaison with Learning and Development, and Sourcing.

The person:
For the above position, the successful applicant should have the following:

Bachelor's degree in information technology/computer science/Telecommunications / Engineering (Electrical, Electronic) or related field
At least one security certifications from the list: CISA, CISM, CISSP, CRISC, GIAC Certifications, CEH, COBIT, ISO270001 Implementor/Auditor
At least 2 years' experience in IT/Information/Cyber security  
At least 1 year experience in third party management, third party engagements, working with a third party, auditing third parties
  • ICT
  • Computer