

Search by job, company or skills

Responsibilities
- Understand and scope properly third-party organization structure to apply necessary controls to be assessed
- Perform risk assessment and remediation of identified findings as per process documents
- Ensure third-party compliance to the business agreement, policies, procedures, & regulations along with ability to map controls and compliance requirements
- Review third-party supplied policies & procedures, internal/external assessment reports, agreements, and provide feedback
- Executive summaries with recommendations & direction regarding remediation efforts and disposition of the third-party
- Communicate, escalate, and track third-party remediation progress on assessment remediation activities
- Understand information security risks that are inherent to a business and articulate those risks in business terms
- Maintain current knowledge on information security topics and their applicability program requirements
- Engage leadership regarding any escalations/delays/deviations during assessment/remediation
- Conducts quality checks and provide feedback as necessary
- Create reports and presentation needed for operational process
- Other duties assigned ( Peer reviewer and lead assessor)
Software tools/skills needed:
Advance level experience in Microsoft 365 (Excel, Word, PowerPoint, etc.)
Qualifications
- Experience in information security risk audit/assessments
- Experience working with senior levels of management
- Strong listening, communication, and presentation skills
- Good follow-up skills and detail oriented
- Security expertise including knowledge on different security risk assessment frameworks, standards, and act. (HITRUST/ISO27001/NIST/HIPAA)
- Experience in examining audit reports such as HITRUST, ISO 27001, SOC 2 Type II, PCI DSS, etc.
- Knowledge and understanding of different security products (MFA, encryption, threat & vulnerability, antivirus, network protection, etc.)
- Knowledge on software development methodologies, application security, and OWASP Top 10 guidelines
- Ability to document assessment work papers and preparing assessment report
- Ability to manage third-party assessment independently with minimal supervision
Preferred:
CISA, CISSP, CPISI, ISO 27001, Security+, ISC2 CC
What skills/attributes are nice to have:
Good project management skills
Job ID: 151883871
Skills:
Antivirus, Dlp, Hipaa, Iso27001, Excel, Pci Dss, Vulnerability Testing, Itil, Microsoft 365, Firewall, Application Security, Owasp Top 10, NIST standards, HITRUST, Word, GLBA, email filtering, SOC 2, disk encryption, SSAE 16 Audit, NY Cyber Security, Cobit, Powerpoint, auditing security assessments