Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Senior Vendor Cyber Risk Analyst @ S&P Global

Home > Assessment / Advisory

 Senior Vendor Cyber Risk Analyst

Job Description

About the Role: Cyber Risk Analyst - This role helps reduce the cyber risk posed by third parties and protects S&P Global brands against possible attacks against our information assets by threat actors via backdoor created by our vendors. Primary responsibilities will include assessing Cybersecurity, Business Continuity controls for S&P third parties by conducting control risk assessments, risk recertifications, and continuously monitoring the vendors engaged by S&P.

The Team: As part of Vendor Risk Management, the Vendor Cyber Risk Management team manages the Supply Chain Cyber risks by performing risk assessments of third-party engagements to identify and reduce the risks posed by third parties. This is an extremely important role, considering the fact that large number of data breaches happen due to third parties. It involves working with internal stake holders as well as third parties to achieve the result

Responsibilities and Impact: Working in Vendor Risk Management offers the opportunity to continuously enhance processes to meet the evolving requirements of various regulators. This challenging environment provides ample opportunities to expand your knowledge and expertise. In addition to risk assessments, recertification, and continuous monitoring, you will participate in various projects, allowing you to showcase and further develop your skills and experience.

  • Conduct thorough Cybersecurity, Business Continuity, Artificial Intelligence, Cloud Service Prover and Privacy assessments for Vendors, evaluating their information security policies, procedures, and controls.
  • Effectively collaborate with internal teams to identify critical vendors and assess their potential impact on the organization's cyber risk profile.
  • Communicate risk assessment findings and recommendations to key stakeholders, including senior management, legal, and compliance teams.
  • Work closely with vendors to address identified security gaps and ensure they meet the organization's cybersecurity requirements.
  • Review the vendors on the continuous monitoring program and assisting in driving the periodically review the vendors.
  • Monitor and stay abreast of evolving cybersecurity threats and industry trends to enhance the effectiveness of the risk assessment process.
  • Lead and support enhancement projects within Vendor Risk Management to meet various business and regulatory requirements.
  • Assist the team members in balancing the load and managing Ad-hoc projects.

What Were Looking For:

Basic Required Qualifications:

  • Bachelors degree in computer science or engineering or equivalent.
  • Minimum 3 years of experience in Information Security or Technology Risk Management
  • Any prior exposure to vendor risk management and/ or privacy laws and regulations is a plus.
  • Demonstrable understanding of the concepts of technology controls and information security controls.
  • Exposure to cloud technologies and cloud security is highly desired; the familiarity with pubic cloud technologies such as Amazon Web Services (AWS) or Microsoft Azure or Google Cloud is highly preferred.
  • Excellent communication skills - a must. The resource should have the ability to communicate with cross-functional teams and vendors, both written and oral communication is critical.

Additional Preferred Qualifications:

  • This position is required to work in UK Shift; flexibility is a must, especially when it comes to vendor and internal meetings held during US business hours.
  • Strong organizational skills with the ability to multitask and prioritize while maintaining close attention to detail.
  • Ability to build strategic partnerships with internal stakeholders.
  • Must be a critical thinker with strong qualitative skills.
  • Information Security/Risk Management certification would be an advantage.

Job Classification

Industry: Banking
Functional Area / Department: Risk Management & Compliance,
Role Category: Assessment / Advisory
Role: Risk Analyst
Employement Type: Full time

Contact Details:

Company: S&P Global Market
Location(s): Hyderabad

+ View Contactajax loader


Keyskills:   Cyber Risk Analysis vendor risk management risk management cloud security security controls technology risk information security artificial intelligence

 Fraud Alert to job seekers!

₹ Not Disclosed

Similar positions

Sr. HR Risk Analyst IND

  • Ameriprise Financial
  • 3 - 5 years
  • Noida, Gurugram
  • 4 days ago
₹ Not Disclosed

Intern - Governance, Risk and Compliance (GRC)

  • Coindcx
  • 3 months duration
  • Bengaluru
  • 18 days ago
₹ Unpaid

Senior Engineer - Risk Management

  • WSP
  • 8 - 12 years
  • Bengaluru
  • 20 days ago
₹ Not Disclosed

HR Risk Analyst IND

  • Ameriprise Financial
  • 2 - 4 years
  • Noida, Gurugram
  • 26 days ago
₹ Not Disclosed

S&P Global

S&P Capital IQ, a business line of The McGraw-Hill Companies (NYSE:MHP), is a leading provider of multi-asset class and real time data, research and analytics to institutional investors, investment and commercial banks, investment advisors and wealth managers, corporations and universities aroun...