The job is to assess the controls at a supplier site to ensure that they are adequate to mitigate the risk of outsourcing to that supplier.
This would be accomplished by interpreting independent assessments of the supplier, minimal OnSite reviews and testing at the supplier, as well as utilizing the available tools (MS Office, Archer, Hiperos, etc), to automate and communicate the scoring of inherent and residual risks involved in supplier relationships.
Requirements:
Active Directory, networking and data classification knowledge
Archer knowledge from a user standpoint is a plus
Information Security experience (preferably Third Party Risk Management and Compliance)
Familiarity with SOC 1 (SSAE 16*) and SOC 2 (**AT101) reports
Knowledge of regulatory and industry standards such GLBA, HIPAA, COBIT, FFIEC
Ability to write process, procedures and flowcharts
Risk Analysis experience
Candidates should be more knowledgeable in security risk as opposed to security engineering
Candidates are somewhat technical. They should have basic networking and data security experience
Possible domestic travel, up to 10%
Preferred Skills:
IT Audit Experience
Knowledge of FS-ISAC Shared Assessments, Pen Test results , PCI DSS
Experience performing on-site third party reviews
CISA, CISSP, CRISC or other security certifications
Archer (eGRC) or Hiperos (Supplier Management) experience
Knowledge of Visual Basic and Macro Coding for MS Office applications
Verbal and written communication skills are key. This resource will be working with people across the organization.
You received this message because you are subscribed to the Google Groups "CVMSCRM" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cvmscrm+unsubscribe@googlegroups.com.
To post to this group, send email to cvmscrm@googlegroups.com.
Visit this group at https://groups.google.com/group/cvmscrm.
For more options, visit https://groups.google.com/d/optout.
No comments:
Post a Comment