
URGENT IT Security Vendor Risk Analyst
23 hours ago
ROLE AND RESPONSIBILITIES
The IT Security Vendor Risk Analyst is responsible for maintaining, improving, and monitoring the Vendor Risk Management program as it relates to IT security. The IT Security Vendor Risk Analyst is expected to lead coordination efforts with internal and external parties in conducting Teleperformance vendor and supplier risk assessments, provides control recommendations, conducts vendor contract review, performs compliance checks against Teleperformance security policies, legal and regulatory requirements, documenting security issues, monitoring risk remediation status and provides communication to management. The IT Security Vendor Risk Analyst is expected to ensure that vendors and suppliers are managed appropriately and in accordance to the Teleperformance security policies and procedures. Additionally, the IT Security Vendor Risk Analyst will develop and implement independent reporting and analysis to assist in the Vendor Risk Management program.
The IT Security Vendor Risk Analyst coordinates with different internal stakeholders such as Information Technology, Operations, Security, Legal, Procurement and Administrative organizations to ensure vendors are evaluated in meeting business requirements while maintaining security and privacy controls. Additionally, the IT Security Vendor Risk Analyst is expected to stay abreast with security and regulatory updates and be able to mentor and provide leadership to others in the Corporate Security Department.
The successful candidate will have a firm understanding of vendor risk management principles, IT security, and is able to easily articulate that understanding while helping others to improve. Is willing to actively seek opportunities to develop new approaches to meet goals. Grasps and applies advanced concepts. Stays abreast of new tools, technologies, and techniques related to vendor risk management, IT security, and implements them as solutions to problems. In the role, the Vendor Risk Analyst will define vendor frameworks, communicate vendor risk concepts, policies, standards, procedures, and provide ongoing support.
Responsibilities also include:
• Oversees the IT security third-party risk assessment process to include due diligence through partnerships with various internal stakeholders to ensure all requirements are met (certifications, BCP/DR, data security and privacy, brand reputation, connectivity, encryption, etc.).
• Evaluate vendor documents to determine acceptability based on line of business needs and information security and privacy requirements.
• Oversees the day-to-day risk mitigation, monitoring, and reporting for third-party relationships, conducting independent risk assessments that provides greater insight into risk exposures and mitigation efforts.
• Provide updated policy, procedures and control compliance evidence related to Teleperformance vendor and supplier management
• Perform IT security vendor risk assessment to potential vendors prior engagement and due diligence to existing vendors.
• Review IT security vendor risk assessment outputs to ensure risk has been appropriately assessed.
• Coordinate and verify inclusion of terms of contracts related to SaaS, IaaS, software integration, and other business critical deployments that involve PII, PCI, PHI, and other regulatory data classifications.
• Assist in the development of corrective action plans and third-party contingency plans for high risk vendors.
• Collaborate with stakeholders in the Corporate Security Department to assist in further development of governance structure and oversight of security framework and controls in compliance with PCI-DSS, ISO 27001, HITRUST, HIPAA, and other frameworks and guidelines.
• Delivers reporting from the vendor risk management platform and presents to stakeholders, including to senior management.
• Obtain and maintain necessary training to keep current on the discipline of vendor risk management and IT security, including regulatory and industry practices.
• Ensure documents and activities are performed in compliance with applicable laws, regulatory standards and company policies and procedures.
• Lead and participate in internal and external audits and examinations.
• Assist with the creation of policies and procedure for the Vendor Risk Management program.
• Performs other duties and responsibilities as assigned.
QUALIFICATIONS AND EDUCATION REQUIREMENTS
• A Bachelor's degree in risk management, computer science, or a related discipline, or the equivalent combination of education, technical training or work/military experience.
• 3 years of IT security vendor risk management and information security experience.
• Experience with regulatory requirements, including but not limited to PCI-DSS, ISO27001, HITRUST, HIPAA, etc.
• Advanced knowledge and work experience in Vendor Risk Management or related fields, such as audit, IT security, or business continuity, however, other IT disciplines are eligible.
• Technical knowledge to understand detailed issues around security, business continuity, and overall risk in IT.
PREFERRED SKILLS
• In addition to the qualifications and education requirements identified above, a candidate with the following is highly desired:
o Experience in a regulated (financial, pharmaceutical, health care, etc.) industry is highly desired"
o One or more of the following certifications is highly preferred: CRISC, CISM, CISA, and CISSP.
-
Senior Vendor Risk Analyst
24 hours ago
Quezon City, National Capital Region, Philippines Manulife Full time $80,000 - $100,000 per yearJob Description:The Senior Analyst, Vendor Governance reports locally to the Director Vendor Risk in MBPS and works operationally with the Sr Director, Vendor Governance Management in North America (Business Unit) and is responsible for ensuring effective risk management of the Company's vendors globally. The incumbent will have a deep understanding of...
-
URGENT Information Security Analyst II
1 day ago
Makati City, National Capital Region, Philippines Teleperformance Full time $104,000 - $130,878 per yearSecurity Analyst will be able to perform alert triage and incident handling, assist in basic Incident response tasks, support different security platforms, and report creation. Security Analyst will have an advanced understanding of the Teleperformance network layout, and an intermediate understanding of the functionality of the tools in use. Security...
-
Information Security Analyst
6 days ago
Makati City, National Capital Region, Philippines Smart Communications, Inc. Full timeInformation Security Analyst - Risk ManagementReports To: Vulnerability LeadCareer Band: Vulnerability Management DivisionAre you ready to be at the frontline of cyber defense? Join our elite Cyber Security Operations Group as a Vulnerability Analyst and help safeguard critical systems against emerging threats. If you're passionate about penetration testing,...
-
Mandaluyong City, National Capital Region, Philippines Vertiv Full time $60,000 - $80,000 per yearBusiness Continuity and Disaster Risk Recovery AnalystVertiv Mandaluyong, National Capital Region, PhilippinesBusiness Continuity and Disaster Risk Recovery AnalystVertiv Mandaluyong, National Capital Region, Philippines1 week ago Be among the first 25 applicants Direct message the job poster from VertivThe Analyst will communicate the Business Continuity...
-
Information Security Manager
2 days ago
Mandaluyong City, National Capital Region, Philippines beBeeRisk Full time ₱900,000 - ₱1,200,000Job Summary:We are seeking a seasoned professional to lead our risk assessment initiatives. As Talent Acquisition Officer @ Bank of Commerce - an affiliate of San Miguel Corporation, you will oversee employees, consultants, subsidiaries and vendor's compliance with ISPP regarding the security of the Bank's information assets.You will monitor the adequacy and...
-
Cyber Security Analyst
24 hours ago
Mandaluyong City, National Capital Region, Philippines ConnectOS Full time $90,000 - $120,000 per yearWhat are we looking for?Skills Required: Experience as a Cyber Security Analyst or in a similar IT security roleStrong background in applications, infrastructure, and network security supportHands-on experience with SIEM tools, firewalls, and vulnerability testingFamiliarity with compliance frameworks such as ISO, Essential 8, and SMB1001Knowledge of risk...
-
Security Analyst level 1
24 hours ago
Mandaluyong City, National Capital Region, Philippines Radenta Technologies, Inc. Full time $60,000 - $80,000 per yearJob Summary:The Security Analyst plays a critical role in safeguarding the organization's information systems and data from cyber threats and attacks. They are responsible for monitoring, analyzing, and responding to security incidents, as well as implementing security controls and measures to prevent unauthorized access and breaches.Key...
-
Senior Governance Risk and Compliance
1 day ago
Mandaluyong City, National Capital Region, Philippines Vertiv Full time $90,000 - $120,000 per yearJoin a High-Performance Culture That Drives Innovation and ExcellenceAt Vertiv, we don't just hire talent—we cultivate leaderswho driveinnovation and engageteams to push the limits of what's possible. As a global leader in critical digital
-
IT Security Analyst IV
24 hours ago
Makati City, National Capital Region, Philippines Sealed Air Full time $800,000 - $1,000,000 per yearSealed Air designs and delivers packaging solutions that protect essential goods transported worldwide, preserve food, enable e-commerce and digital connectivity, and help create a global supply chain that is touchless, safer, less wasteful, and more resilient. We strive to foster a caring, high-performance growth culture that will deliver consistent,...
-
security analyst
23 hours ago
Mandaluyong City, National Capital Region, Philippines Asticom Full time $60,000 - $80,000 per yearOperationsPerform security architecture and design reviews, service and data flow reviews to check for security/privacy flaws and gaps, and recommend remediation and/or mitigation. Utilize knowledge and understanding of application architecture, network design, infrastructure security, and data security standards to identify findings and clearly communicate...