Technology Risk & Third-Party Risk Analyst

PERCEPT SOLUTIONS PTE. LTD.

Singapore

On-site

SGD 70,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

PERCEPT SOLUTIONS PTE. LTD. is seeking a Technology Risk & Third-Party Risk Analyst to assess and manage technology, information security, cybersecurity, and outsourcing risks from external vendors and service providers.

You will perform due diligence, review evidence, identify control gaps, and collaborate with stakeholders to ensure risks are documented, monitored, and remediated across the enterprise.

Qualifications

  • Experience conducting security assessments and control reviews.
  • Understanding of third-party, vendor and outsourcing risk-management principles.
  • Knowledge of cybersecurity and cloud security risks and controls.
  • Familiarity with MAS Singapore regulatory expectations is a plus.

Responsibilities

  • Conduct third-party and vendor risk assessments including due diligence and ongoing monitoring.
  • Assess vendors' information security, cybersecurity, technology, cloud, data protection, BC and outsourcing controls.
  • Review security questionnaires, audit reports, policies, and penetration-test evidence provided by vendors.
  • Identify control gaps and evaluate risk-management controls for effectiveness.
  • Document risks, remediation requirements and escalate material issues to stakeholders.

Skills

Third-Party Risk Management
Vendor Risk Management
Technology Risk
Information Security
IT Risk/IT Audit

Education

Degree or diploma in IT/Cybersecurity/Risk Management

Tools

CISA/CISM/CRISC/CISSP/CCSP

Job description

We are seeking a Technology Risk & Third-Party Risk Analyst to assess and manage the technology, information security, cybersecurity, and outsourcing risks associated with external vendors and service providers. The successful candidate will conduct vendor due diligence, security and control assessments, identify control gaps, and work with internal stakeholders and third parties to ensure risks are appropriately documented, monitored, and remediated.

Key Responsibilities:
  • Conduct third-party and vendor risk assessments, including initial due diligence, periodic reviews, and ongoing monitoring.
  • Assess vendors' information security, cybersecurity, technology, cloud, data protection, business continuity, and outsourcing controls.
  • Review security questionnaires, supporting documents, audit reports, certifications, policies, penetration-test reports, and other evidence provided by vendors.
  • Perform control gap assessments and evaluate the adequacy and effectiveness of vendors' risk-management controls.
  • Identify, document, and evaluate risks arising from third-party services, technology platforms, cloud environments, and outsourcing arrangements.
  • Prepare clear assessment reports detailing identified risks, control gaps, recommendations, and remediation requirements.
  • Work with vendors and internal stakeholders to develop and track remediation plans through to closure.
  • Escalate material risks, overdue remediation actions, and control weaknesses to the relevant stakeholders and management.
  • Maintain accurate third-party risk records, risk ratings, assessment results, supporting evidence, and remediation status.
  • Support the development and improvement of third-party risk-management policies, procedures, assessment methodologies, and reporting standards.
  • Collaborate with Information Security, Technology Risk, Compliance, Procurement, Legal, Audit, and business teams.
  • Support regulatory reviews, internal audits, and external audits relating to third-party, outsourcing, technology, and cybersecurity risks.
  • Monitor relevant regulatory and industry developments and incorporate applicable requirements into the assessment process.
Requirements:

Relevant experience in one or more of the following areas:

  1. Third-Party Risk Management
  2. Vendor Risk Management or Vendor Due Diligence
  3. Technology Risk
  4. Information Security or Cybersecurity
  5. IT Risk, IT Controls, or IT Audit
  • Practical experience conducting security assessments, control reviews, or control gap assessments.
  • Good understanding of third-party, vendor, and outsourcing risk-management principles.
  • Familiarity with cybersecurity and cloud security risks and controls.
  • Ability to evaluate control evidence, identify weaknesses, and recommend practical remediation measures.
  • Familiarity with the Monetary Authority of Singapore's regulatory expectations and technology risk requirements is preferred.
  • Strong analytical, problem-solving, documentation, and report-writing skills.
  • Strong stakeholder-management and communication skills, with the ability to engage both technical and non-technical stakeholders.
  • Ability to manage multiple assessments, priorities, and remediation activities simultaneously.
  • High attention to detail and the ability to exercise sound risk-based judgement.
Preferred Qualifications:
  • Degree or diploma in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline.
  • Relevant certifications such as CISA, CISM, CRISC, CISSP, CCSP, ISO 27001, or equivalent would be advantageous.
  • Experience within banking, financial services, insurance, or another regulated industry would be an advantage.
  • Knowledge of recognised frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, CSA CCM, SOC 2, or COBIT would be beneficial.

EA Licence No.:18S9405 / EA Reg. No.:R1330864

Percept Solutions is expanding and actively seeking talented individuals. We encourage applicants to follow Percept Solutions on LinkedIn at https://www.linkedin.com/company/percept-solutions/ to stay informed about new opportunities and events.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technology Risk Analyst – Third-Party Risk _ Contract
Technology Risk Analyst – Third-Party Risk _ Contract

NTT SINGAPORE PTE. LTD. • Singapore

On-site
SGD 78,000 - 100,000
Cybersecurity and Technology Risk Engineer
Cybersecurity and Technology Risk Engineer

AVENSYS CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Third Party Risk Management Specialist with a Leading Organisation in the Payments Industry
Third Party Risk Management Specialist with a Leading Organisation in the Payments Industry

CHARTERHOUSE PTE. LTD. • Singapore

On-site
SGD 70,000 - 110,000
Third Party Risk Management Specialist with a Leading Organisation in the Payments Industry
Third Party Risk Management Specialist with a Leading Organisation in the Payments Industry

Charterhouse Pte Ltd • Singapore

On-site
SGD 70,000 - 110,000
Security Risk Management Consultant
Security Risk Management Consultant

Infinite Computer Solutions Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Vendor Risk Analyst - Banking Domain
Vendor Risk Analyst - Banking Domain

PERSOL SINGAPORE PTE. LTD. • Singapore

On-site
SGD 70,000 - 110,000
Cybersecurity and Technology Risk Engineer
Cybersecurity and Technology Risk Engineer

UNIZEN TECHNOLOGIES PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Technology Risk & Cybersecurity Engineer - Vendor Risk
Technology Risk & Cybersecurity Engineer - Vendor Risk

AVENSYS CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity & Technology Risk Engineer
Cybersecurity & Technology Risk Engineer

IoTalents Pte. Ltd. • Singapore

On-site
SGD 120,000 - 180,000
Security Risk Management Consultant
Security Risk Management Consultant

TALENTWORKZ PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000