A complete application in a minute — tailored resume and cover letter, ready to send.
NTT DATA in Metro Manila is seeking an experienced cybersecurity professional to identify, assess, and manage risks across the third-party vendor ecosystem. You will work with clients and service providers to conduct security assessments, evaluate risks, and support remediation strategies in a collaborative, client-focused environment.
The role emphasizes TPRM engagements, security controls, and industry frameworks, with opportunities to mentor juniors and contribute to policy development.
Join NTT DATA and take your cybersecurity career to the next level. We are looking for an experienced cybersecurity professional who can help organizations identify, assess, and manage risks across their third-party vendor ecosystem.
In this role, you will work closely with clients, business stakeholders, and service providers to conduct security assessments, evaluate cybersecurity and data privacy risks, recommend practical remediation strategies, and support the delivery of high-quality risk management engagements.
If you have a strong background in Third-Party Risk Management, IT Audit, Information Security, or Cybersecurity Assessments, this is an opportunity to apply your expertise in a collaborative, client-focused environment.
Deliver Third-Party Risk Management (TPRM) engagements, including security assessments of new and existing vendors and service providers.
Review vendor responses, supporting evidence, security documentation, and other materials to identify potential cybersecurity risks.
Conduct risk assessments against client IT security, cybersecurity, and data privacy requirements.
Assess vendor risks and define appropriate risk ratings, corrective actions, and remediation recommendations.
Identify security control gaps and potential risks to client environments.
Work directly with clients, business units, and third-party vendors to clarify findings and agree on appropriate remediation actions.
Monitor identified risks and remediation activities through closure.
Review, develop, and enhance security policies based on client requirements and recognized industry standards.
Manage day-to-day engagement activities, deliverables, timelines, and stakeholder reporting.
Review the work of junior team members and provide coaching, guidance, and constructive feedback.
Build strong working relationships with clients and internal stakeholders.
Contribute to team development, knowledge sharing, recruitment, and other people initiatives.
2 to 5 years of relevant experience in cybersecurity, information security assessments, IT audit, IT risk, third-party risk, or related disciplines.
Strong knowledge of cybersecurity controls, risk assessment methodologies, and industry-leading security frameworks.
Experience conducting Third-Party Vendor/Supplier Risk Assessments and managing identified risks.
Client-facing experience with the ability to communicate effectively with business units, vendors, technical teams, and leadership stakeholders.
Strong stakeholder and project management skills with the ability to manage multiple activities within established deadlines.
Experience leading engagements or workstreams and coaching junior team members.
Excellent written and verbal communication skills.
Strong analytical skills with the ability to translate security findings into clear and practical recommendations.
Proficiency in Microsoft Excel, PowerPoint, and Word.
Collaborative mindset with the ability to work effectively both independently and as part of a team.
You should have knowledge or experience across several of the following areas:
ISO 27001
PCI DSS
HIPAA and HITRUST
GDPR and CCPA
FISMA/FedRAMP
COBIT
OWASP Top 10
NIST 800-53
Third-Party/Vendor Risk Management
Business Continuity and Disaster Recovery
Cyber Strategy and Governance
Cyber Transformation
Cybersecurity reporting and dashboarding
Bachelor's or postgraduate qualification in Computer Science, Information Technology, Engineering, Cybersecurity, Business Administration, or a related discipline.
Professional certifications such as CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer are highly regarded.
Knowledge or hands-on experience reviewing configurations for firewalls, routers, and other network devices.
Understanding of security logging and monitoring, including SIEM platforms.
Hands-on experience with a SIEM solution would be an advantage.
At NTT DATA, you'll have the opportunity to work on challenging cybersecurity engagements while collaborating with professionals across different technology and business disciplines. You'll be able to strengthen your expertise in cybersecurity risk, third-party security, governance, compliance, and transformation while contributing to solutions that help organizations operate more securely.