Team Member - Vendor Risk Reviews
Role & responsibilities :
- Handle the Vendor (Third-Party) Risk Review Management Program independently
- Ensure support to Operations Risk Management Team on vendor onboarding process (review of details from cyber security perspective)
- Maintain and update Third-party Policies, Procedure & Process documents.
- On demand review of vendor agreements (cyber security requirements)
- Review and update third party audit checklists based on the industry events, internal policies / process changes / regulatory requirements / advisories.
- Prepare yearly calendar for vendor audits and circulate the same to business owners.
- Conduct risk based and checklist-based vendor audits as per calendar in stipulated time.
- Ensure new vendors are included in vendor audits calendar as per defined criteria.
- Prepare the reports and track the observations raised for closure with business teams.
- Maintain and manage audit and observations tracker / dashboards.
- Present periodic updates and dashboards to relevant management team and during management presentations
- Handle the escalation related to Vendor risk review.
- Handle periodic audits from regulator / government agencies / internal audits independently for Vendor risk review.
Preferred candidate profile
- Strong Vendor Audit Experience
- Experience in BFSI industry is a must.
- CISA, CRISC, CISSP, CISM, PCI DSS QSA, ISO 27001:2013 LA are added advantage
- Strong experience in guidelines, compliances