The posting
Responsibilities:
- Lead Third-Party Risk Management activities, including third-party cyber risk assessments and evidence gathering.
- Conduct Security Assessments and control gap assessments to identify security risks and gaps.
- Assess Cybersecurity risks, controls, policies, and standards across relevant environments.
- Review Information Security policies, standards, and risk frameworks and recommend improvements.
- Support Regulatory Engagement activities related to Cybersecurity and Information Security.
- Coordinate Internal Audit engagements, including audit-team liaison, evidence gathering, and follow-up.
- Analyse security assessment findings and identify appropriate risk mitigation actions.
- Prepare assessment documentation, reports, and recommendations for stakeholders.
- Work with stakeholders to address identified risks and implement feasible security improvements.
Requirements:
- Bachelor of Engineering degree or equivalent technical qualification.
- 16+ years of experience in Third-Party Risk Management, Cybersecurity, Information Security, Security Assessments, Regulatory Engagement, and Internal Audit.
- Strong Banking/Financial Services domain experience, preferably within a large banking organisation.
- Strong experience in Third-Party Risk Management, including third-party cyber risk assessment and evidence gathering.
- Strong experience performing Security Assessments and control gap assessments.
- Strong understanding of Cybersecurity controls, Information Security policies, standards, and risk frameworks.
- Strong experience in Regulatory Engagement and coordination with regulatory stakeholders.
- Strong experience in Internal Audit engagements, including evidence gathering and audit-team coordination.
- Strong analytical, documentation, report-writing, communication, and stakeholder management skills.



