Premium Employer

i

This company page is being actively managed by AECOM Team. If you also belong to the team, you can get access from here

AECOM Verified Tick

Compare button icon Compare button icon Compare
filter salaries All Filters

150 AECOM Jobs

IT Third Party and Client Security Assurance Analyst

2-3 years

Bangalore / Bengaluru

1 vacancy

IT Third Party and Client Security Assurance Analyst

AECOM

posted 19hr ago

Job Description

The use of third parties is an essential element in AECOMs service delivery model and creates the need for management oversight and continuous monitoring of their security capabilities and performance. AECOM works with many third parties (e.g., vendors, partners, suppliers) each of which poses security, compliance and operational risks. AECOM is recruiting Third Party and Client Security Analysts to support the centralized Third Party and Client Risk Management Function.

In this role, the analyst is expected to support the framework, operating model and supervise processes to ensure: (1) third parties are compliant with AECOMs security standards and (2) that AECOM provides the same type of assurance to our clients that its security program is compliant with regulatory requirements, standards and client expectations.

Responsibilities & Duties

  • Evaluate requests for third party engagements
  • Conduct initial and periodic third-party risk assessments
  • Collaborate with business requestors, procurement, legal and other teams to ensure questionnaires are completed timely
  • Collaborate with security/IT team members to ensure a full understanding of security controls, technology and architecture
  • Review responses to security questionnaires, SOC 1 and SOC 2 assessment reports received from third parties to identify potential risk to AECOM
  • Identify gaps/issues based on third party and/or client standards relative to security postures
  • Devise remediation plans and monitor to ensure adherence by third parties and AECOM security/IT
  • Manage, enhance and implement the framework, policies, procedures and program governance to ensure alignment of TPRM with industry best practices and regulatory requirements (NIST, ISO27001, FedRamp, etc.)
  • Develop tactical and strategic plans to evolve the third-party risk management program to ensure compliance with new regulations and alignment with industry best practices
  • Triage/complete requests from AECOM clients regarding AECOMs control environment
  • Manage AECOMs response to existing and potential business partners/clients/third parties security due diligence (questionnaires, site visits, etc.)
  • Assistance with RFI/RFP processes and responses to client inquiries, ensuring comprehensive risk management throughout the process
  • Review third party and client contracts to validate appropriate security requirements and commitments
Qualifications
  • Bachelors degree in information technology, Information Security, Risk Management or a related field
  • 2-3 years of career experience related to information security, IT, audit, third party and/or risk
  • Strong understanding of risk management principles and security frameworks (e.g., NIST, ISO 27001, SOC2, PCI-DSS)
  • Extensive experience in evaluating vendor security and compliance in relation to regulatory and industry standards.
  • Familiarity with industry GRC tools such as UpGuard, Audit Board, ServiceNow etc. is a plus/desirable
  • Strong prioritization and organizational skills
  • Ability to develop, document and maintain procedures
  • Strong verbal communication with the ability to advise management regarding third party and client risk management
  • Ability to work independently and collaborate with cross-functional teams
Additional Information
  • Ability to effectively communicate and collaborate within a specific group of internal and external customers. (Communication)
  • Ability to maintain good customer relationship with the ability to proactively support customer needs and requirements. (Customer Service)
  • Ability to be thorough and meticulous in completing assigned tasks and identifying errors, duplicates & discrepancies through defined methods. (Attention to Detail)
  • Ability to identify, assess and resolve simple to moderate issues by following defined policies and procedures. (Problem Solving)

Employment Type: Full Time, Permanent

Read full job description

AECOM Interview Questions & Tips

Prepare for AECOM roles with real interview advice

Top AECOM Assurance Analyst Interview Questions

Q1. What are the components to be considered in the Rate analysis?
Q2. Where do we get the permission to fix barricade board
Q3. Tolerance limit in various structure members Pile
View all 61 questions

What people at AECOM are saying

What AECOM employees are saying about work life

based on 1.6k employees
58%
47%
40%
98%
Flexible timing
Monday to Saturday
No travel
Day Shift
View more insights

AECOM Benefits

Submitted by Company
Free Transport
Job Training
Soft Skill Training
Free Food
Submitted by Employees
Health Insurance
Soft Skill Training
Job Training
Free Transport
Work From Home
Cafeteria +6 more
View more benefits

Compare AECOM with

Jacobs Engineering Group

4.1
Compare

Fluor Corporation

4.3
Compare

Bechtel

4.0
Compare

Worley

4.1
Compare

Black & Veatch

4.3
Compare

TCS

3.7
Compare

Larsen & Toubro Limited

4.0
Compare

Infosys

3.6
Compare

Tech Mahindra

3.5
Compare

Wipro

3.7
Compare

Shapoorji Pallonji Group

4.1
Compare

Alstom Transportation

3.7
Compare

Saint-Gobain

4.0
Compare

AtkinsRealis

4.0
Compare

Saipem

4.1
Compare

Nasser S. Al Hajri Corporation

3.6
Compare

Consolidated Contractors

4.4
Compare

Samsung E&A

4.1
Compare

McDermott International

4.3
Compare

Ramboll

4.1
Compare

Similar Jobs for you

Technology Auditor at Riskpro

Bangalore / Bengaluru, Mumbai

2-5 Yrs

₹ 3.5-8 LPA

Information Security and Compliance Manager at CyberSRC

Noida, Navi Mumbai

2-7 Yrs

₹ 4.25-9.25 LPA

Assistant Risk Manager at Uniqus Consultech

Mumbai

2-4 Yrs

₹ 4-7 LPA

Governance Analyst at Wipro Limited

Ahmedabad

2-6 Yrs

₹ 4-8 LPA

Senior Associate at BNY Mellon International Operations (India)

Pune

2-5 Yrs

₹ 7-11 LPA

Senior Client Partner at Access Healthcare

Chennai

2-7 Yrs

₹ 4-7 LPA

Risk Management at EY

Hyderabad / Secunderabad, Gurgaon / Gurugram + 1

3-7 Yrs

₹ 6-12 LPA

Security at Priceline.com

Mumbai

3-5 Yrs

₹ 5-7 LPA

Information Security Consultant at ANRGI TECH

Mumbai

3-6 Yrs

₹ 5-9 LPA

Technology at EY

Kolkata, Hyderabad / Secunderabad + 1

3-6 Yrs

₹ 1-3.25 LPA

IT Third Party and Client Security Assurance Analyst

2-3 Yrs

Bangalore / Bengaluru

19hr ago·via naukri.com

Senior Urban Designer

13-20 Yrs

Gurgaon / Gurugram

16hr ago·via naukri.com

Semiconductor Plant Design & Execution Expert

16-26 Yrs

Guwahati, Kolkata, Gurgaon / Gurugram

16hr ago·via naukri.com

Senior Architect - ID

5-8 Yrs

Gurgaon / Gurugram

19hr ago·via naukri.com

Billing - Sr Analyst

4-5 Yrs

Bangalore / Bengaluru

19hr ago·via naukri.com

Senior Engineer - Water

5-10 Yrs

Bangalore / Bengaluru

19hr ago·via naukri.com

Principal Engineer - Electrical ( Secondary Substation )

8-12 Yrs

Bangalore / Bengaluru

19hr ago·via naukri.com

Engineer - Highways

2-5 Yrs

Bangalore / Bengaluru

19hr ago·via naukri.com

Sr. / Lead Engineer - Water

5-9 Yrs

Bangalore / Bengaluru

19hr ago·via naukri.com

Senior Designer - HVAC BIM

6-8 Yrs

Gurgaon / Gurugram

19hr ago·via naukri.com
write
Share an Interview