119 Burgeon IT Services Jobs
Third Party Security Assurance Analyst (5-8 yrs)
Burgeon IT Services
posted 14d ago
Flexible timing
Key skills for the job
Position : Third Party Security Assurance (TPSA)
Location : Bangalore
EXP : 5-8 years
Duration : Contract to Hire
JD :
Third Party Security Assurance (TPSA) Analyst JD
This role is for a Third party Security Assurance Analyst in the Vendor Security team. The aim of this team is to ensure security checks are carried out on any third parties to the organisation to ensure there are no security vulnerabilities or risks that could cause an incident. A large number of security incidents begin with a vendor or third party so it is very important that any supplier or third party has a security assessment carried out to ensure their security profile is to the level required.
Main tasks will be :
- Managing and conducting supplier risk assessments including report output and recommendations.
- Liaising with business and external vendors to ensure Vendor services and products meet baseline security requirements as defined by policy.
- Tracking the closure of supplier assessments and issues identified from TPSA reviews
- Utilizing Bitsight software to carry out non intrusive technical assessments of current and future third parties.
- Security reassessments in line with the criticality / Tier of the Vendor and conduct off-boarding assessments at the end of the contract
- Advising & supporting management on Compliance and Security issues for third parties.
- Assisting in remedial action taken as a result of failures from a security or governance perspective.
- Producing monthly & quarterly progress/ status reports.
- Assisting with incident management and investigation.
Mandatory skills :
- 5+ years of Information Security Experience.
- Previous experience in a vendor security management role.
- Understanding of Information security management best practices, including knowledge of policies and standards (ISO27001, 27005, 22301, PCI-DSS)
- Understanding of Third Party Security Assurance activities
- A knowledge of network security management technologies including firewalls, Cisco, Databases, Unix, Windows and middleware.
- Must be capable of providing easy to understand documentation and training materials
Functional Areas: Other
Read full job description