Dis-ChemPharmacies hasanopportunityavailablefora Third-Party Risk Management Specialist responsible for assessing and managing security risks arising from Dis-Chem’s external vendors, technology partners, and service providers. The role establishes and maintains Dis-Chem’s third-party security due-diligence framework, evaluates vendor controls before onboarding, and monitors ongoing compliance across the vendor lifecycle. Works closely with CISO, Enterprise Architecture, Procurement, and IT platform teams to ensure third-party risks are identified early, assessed consistently, and addressed through contractual, technical, or operational controls. Strengthens resilience in a landscape heavily reliant on external IT partners.
Requirements
- Degree in Information Security, IT, Risk Management, or related field
- 5+ years’ experience in IT security or vendor risk management, preferably in a multi-vendor environment
- Exposure to outsourced service models, SOC/MDR providers, and cloud-hosted solutions.
Responsibilities
Information Security Governance & Compliance
- Develop and maintain the third-party security assessment and onboarding framework for all technology vendors
- Establish security requirements, minimum controls, and contractual clauses for IT suppliers in alignment with enterprise architecture and CISO standards
- Maintain a central third-party risk register and ensure risk ratings, remediation actions, and exceptions are documented and reviewed
- Collaborate with Procurement to embed security reviews into sourcing and renewal
Third-Party Security Risk Management
- Conduct risk assessments for new vendors and high-risk services; evaluate security certifications, architecture, hosting, data flows, access models, and operational processes
- Identify control gaps and recommend mitigation across domains (e.g., IAM, data protection, resilience, patching, monitoring)
- Partner with IT platform teams to validate integration risks and enforce secure configuration requirements
- Track remediation progress with vendors and elevate overdue or critical issues to CISO
Monitoring, Incident Support & Reporting
- Monitor vendor security posture continuously through attestations, performance metrics, and threat intelligence
- Support incident investigation when a vendor-driven outage or cyber event impacts Dis-Chem (noted as a known pain point)
- Provide reporting to CISO, Procurement, and Leadership on vendor risk levels, trends, and areas requiring uplift
Competencies
Domain Expertise
- Strong understanding of third-party risk, vendor security controls, and security assessment methods
- Knowledge of risk domains relevant to retail pharmacy (hosting, data protection, resilience, availability, integrations)
- Familiarity with regulatory and contractual securityrequirements.
Leadership & Commercial Acumen
- Ability to influence vendors and internal stakeholders toward secure-by-design decisions
- Strong negotiation and communication skills to articulate risks and requiredmitigations.
Key Performance Indicators
- % of vendors assessed and risk-rated before onboarding
- Remediation closure rate for vendor findings
- Contribution to culture, accountability, engagement, and continuous improvement
- Reduction in vendor-related incidents or outages
- Quality and completeness of vendor risk documentation
- Stakeholder satisfaction with vendor risk process
SpecialConditionsofEmployment:
SouthAfricancitizen
MIE,clearcriminalandcredit
Driver’slicenseand/orownreliabletransport
Remunerationandbenefits:
- Marketrelatedsalary
- Medicalaid
- Providentfund
- Staffaccount
Dis-Chem Pharmacies is an equal opportunity employer. Dis-Chem’s approved Employment Equity Plan and Targets will be considered as part of the recruitment process aligned to Dis-Chem’s Employment Equity & Transformation Strategy. Dis-Chem actively supports the recruitment of People with Disabilities.