We are seeking a Technology Risk & Third-Party Risk Analyst to assess and manage the technology, information security, cybersecurity, and outsourcing risks associated with external vendors and service providers. The successful candidate will conduct vendor due diligence, security and control assessments, identify control gaps, and work with internal stakeholders and third parties to ensure risks are appropriately documented, monitored, and remediated.
Key Responsibilities:
- Conduct third-party and vendor risk assessments, including initial due diligence, periodic reviews, and ongoing monitoring.
- Assess vendors' information security, cybersecurity, technology, cloud, data protection, business continuity, and outsourcing controls.
- Review security questionnaires, supporting documents, audit reports, certifications, policies, penetration-test reports, and other evidence provided by vendors.
- Perform control gap assessments and evaluate the adequacy and effectiveness of vendors' risk-management controls.
- Identify, document, and evaluate risks arising from third-party services, technology platforms, cloud environments, and outsourcing arrangements.
- Prepare clear assessment reports detailing identified risks, control gaps, recommendations, and remediation requirements.
- Work with vendors and internal stakeholders to develop and track remediation plans through to closure.
- Escalate material risks, overdue remediation actions, and control weaknesses to the relevant stakeholders and management.
- Maintain accurate third-party risk records, risk ratings, assessment results, supporting evidence, and remediation status.
- Support the development and improvement of third-party risk-management policies, procedures, assessment methodologies, and reporting standards.
- Collaborate with Information Security, Technology Risk, Compliance, Procurement, Legal, Audit, and business teams.
- Support regulatory reviews, internal audits, and external audits relating to third-party, outsourcing, technology, and cybersecurity risks.
- Monitor relevant regulatory and industry developments and incorporate applicable requirements into the assessment process.
Requirements:
Relevant experience in one or more of the following areas:
- Third-Party Risk Management
- Vendor Risk Management or Vendor Due Diligence
- Technology Risk
- Information Security or Cybersecurity
- IT Risk, IT Controls, or IT Audit
- Practical experience conducting security assessments, control reviews, or control gap assessments.
- Good understanding of third-party, vendor, and outsourcing risk-management principles.
- Familiarity with cybersecurity and cloud security risks and controls.
- Ability to evaluate control evidence, identify weaknesses, and recommend practical remediation measures.
- Familiarity with the Monetary Authority of Singapore's regulatory expectations and technology risk requirements is preferred.
- Strong analytical, problem-solving, documentation, and report-writing skills.
- Strong stakeholder-management and communication skills, with the ability to engage both technical and non-technical stakeholders.
- Ability to manage multiple assessments, priorities, and remediation activities simultaneously.
- High attention to detail and the ability to exercise sound risk-based judgement.
Preferred Qualifications:
- Degree or diploma in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline.
- Relevant certifications such as CISA, CISM, CRISC, CISSP, CCSP, ISO 27001, or equivalent would be advantageous.
- Experience within banking, financial services, insurance, or another regulated industry would be an advantage.
- Knowledge of recognised frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, CSA CCM, SOC 2, or COBIT would be beneficial.
EA Licence No.:18S9405 / EA Reg. No.:R1330864
Percept Solutions is expanding and actively seeking talented individuals. We encourage applicants to follow Percept Solutions on LinkedIn at https://www.linkedin.com/company/percept-solutions/ to stay informed about new opportunities and events.