Position : Sr TPRM Analyst (Third Party Risk Analyst )
Location : San Jose, CA or Santa Clara CA ( Onsite)
Duration : 12 Months
Experience : 10+ Years
Note : Candidate who is staying in USA and have work authorization to work in USA can only apply for this position
THE ROLE:
The Third-Party Risk Management (TPRM) Analyst will coordinate with IT stakeholders, project managers, and business owners to facilitate a vendor risk assessment to onboard a cloud solution or managed service. He/she will be responsible for collaborating with vendors for responses to TPRM vendor assessment questionnaire, perform third-party risk assessments in a timely manner, and facilitate the risk sign-off in accordance with established set of processes. He/She will comply with SLA's, provide periodic status updates to relevant stakeholders, and mature these processes over time in conjunction with Management.
KEY RESPONSIBILITIES:
• Follow the established foundational set of processes for onboarding a cloud solution or managed service.
• Coordinate input from multiple stakeholders to facilitate the review of the vendor.
• Perform risk assessments of third-party cloud solutions by reviewing responses to questionnaire, including supporting documents and information captured during discussions, to evaluate vendor's internal controls environment.
• Facilitate the risk sign-off in accordance with established set of processes.
• Maintain third-party risk assessment documentation within the defined structure.
• Generate metrics on solutions and report to AMD
• Perform periodic ongoing risk assessment of implemented cloud solutions and managed services.
• Refine and mature TPRM processes over time, in conjunction with Management.
PREFERRED EXPERIENCE:
• Be CISA/CTPRA/CCAK certified.
• Have at least 5 years of experience in IT, with 3 or more years of this experience in TPRM, risk assessments, and/or internal IT control testing/ IT audits.
• Have working knowledge of information security and risk frameworks/standards (i.e. ISO 27001/2, NIST 800-53, NIST CSF, SOC1/SOC2, CSA CCM and Shared Assessments SIG) and cloud security practices.
• Have knowledge of and the ability to use a PC as well as Microsoft Office Suite, Visio, and SharePoint software.
• Possess strong communication skills (both written and verbal).
• Possess strong interpersonal skills and can adapt information based on the audience.
• Be able to handle confidential information in a professional manner.
• Have the ability to recognize and communicate potential control related issues in a timely manner.
• Be a strong team player and able to work effectively with colleagues and management.
• Be highly organized and self-reliant, with the ability to multi-task.
• Have excellent process and time management skills.
• Able to appropriately identify issues and raise them to management by paying close attention to detail.
• Have excellent process and time management skills.
• Able to appropriately identify issues and raise them to management by paying close attention to detail.
• Have the ability to listen effectively and communicate with honesty.
• Be able to acquire and evaluate data.
Regards
Paras Nath Singh
Senior Associate -Talent Acquistion
KAnand Corporation
Direct no # 512-355-1243
Paras.Singh@KAnandcorp.com