Jobiglo

Aucun resultat.

IT Third Party Risk Specialist

Kerry Consulting · Singapour

Nouveau
🇬🇧 English
SOC reports ISO certifications cloud security IT controls security frameworks

Description du poste

About the role

You will be responsible for assessing, monitoring, and managing IT and cybersecurity risks associated with third‑party vendors and service providers. The role works closely with Procurement, Legal, Compliance, Cybersecurity and IT teams to ensure risks are identified, evaluated and mitigated throughout the vendor lifecycle.

Key responsibilities

  • Lead and perform IT risk assessments on third‑party vendors, including cloud services, SaaS, infrastructure providers and managed services.
  • Define and maintain the third‑party risk management (TPRM) framework, processes and controls in line with internal policies, regulatory requirements and industry best practices.
  • Collaborate with procurement and business units during vendor onboarding and renewal to conduct due diligence, risk reviews and control assessments.
  • Evaluate vendor responses to security questionnaires and assess supporting documentation such as SOC reports, ISO certifications and penetration test results.
  • Track and monitor identified risks, issues and remediation plans with vendors to ensure timely resolution.
  • Conduct periodic reassessments of critical vendors to ensure ongoing compliance with security and data‑protection requirements.
  • Support regulatory, audit and internal reporting by maintaining accurate third‑party risk records.
  • Develop risk metrics, dashboards and reports for senior management and governance forums.

Required profile

  • Bachelor’s degree in Information Technology, Cybersecurity, Risk Management or a related field.
  • 3–8 years of experience in IT risk management, third‑party/vendor risk assessment or cybersecurity within a regulated industry.
  • Strong knowledge of IT controls and security frameworks.
  • Familiarity with regulatory requirements such as MAS TRM, GDPR, PDPA or equivalent.
  • Excellent stakeholder management, communication and analytical skills.

Required skills

  • Experience reviewing SOC reports, ISO certifications, penetration testing results and cloud security documentation.
  • Knowledge of IT controls and security frameworks.
  • Understanding of regulatory standards like MAS TRM, GDPR and PDPA.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Kerry Consulting.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Pourquoi signalez-vous cette offre ?

Merci pour votre signalement. Nous allons examiner cette offre.

Postulez en 30 secondes

Entrez votre email pour postuler. Un compte sera cree automatiquement.

En continuant, vous acceptez nos conditions d'utilisation.

Deja un compte ? Connexion

Publie il y a 4 jours

Expire dans 1 mois

9 vues · 0 candidatures

Boostez vos chances

Importez votre CV : nous vous proposons les offres qui matchent votre profil.

Analyse de votre CV en cours...

Kerry Consulting

Singapour