Continuous Monitoring Lead for OCRA( for RFP purposes)
4 tygodni temu
Wroclaw Metropolitan Area, DS, Polska
Luxoft
Pełny etat
Bezpłatnie za pośrednictwem poczty elektronicznej lub Google
Zapisz tę ofertę pracy i uporządkuj wyszukiwanie
Utwórz bezpłatne konto, aby zapisywać oferty pracy, tworzyć alerty i wracać do tego ogłoszenia ze swojego pulpitu nawigacyjnego.
Bezpłatnie za pośrednictwem poczty elektronicznej lub Google
Kontynuując, akceptujesz nasze Warunki & Politykę prywatności.
🔥Become a Luxoft employee🔥
Our
Benefits:
💰Paid Referrals 💻Equipment: laptop and monitor 🩺Private Medical & Dental care & Life Insurance covered 🏋🏽 ♀️ MyBenefit program (sports card, well-being program etc.) 🌎 Internal Mobility program
- possibility of rotation between projects, locations, accounts 🎓 LuxTalent platform (webinars, training, courses) ...and more Project Description: Are you fascinated by the third-party cyber threat landscape? Do you have a strong technical background and proven expertise in Cyber and Information Security and Technology Risk Management? In this role, you’ll collaborate closely with internal stakeholders to ensure third-party vendors comply with our cybersecurity policies and procedures. We’re looking for a Cyber and Information Security (CIS) professional to help design, develop, and enhance continuous monitoring processes and controls to manage cyber risks arising from third parties.
Responsibilities:
Execute and further develop the third-party continuous monitoring process Analyse alerts from third-party monitoring solutions, assess risks, and drive follow-up actions Assess the impact of cyber events (e.g., zero-day vulnerabilities) on the third-party portfolio Coordinate risk remediation actions with internal stakeholders and third parties Maintain and enhance the products and tools used in the monitoring process Design and implement additional technical processes and controls to manage third-party risk and reduce the attack surface Conduct deep dives into the bank’s third-party cyber and information security capabilities, drawing conclusions on overall risk posture Proactively challenge the status quo by identifying operational risks, proposing remediation or improvement solutions, and balancing potential tradeoffs Serve as a trusted technical partner and advocate for security risk culture in a highly federated environment Mandatory Skills Description: Knowledge and interest in third-party cyber risk management (TPCRM) Degree in Computer Science, Computer Engineering, Electrical Engineering, Information Security, or a related discipline Strong knowledge of Cyber and Information Security risk management and control frameworks (e.g., ISO 27001, NIST CSF, CSA Cloud Control Matrix) Broad expertise in areas such as network security, cloud security, application security, infrastructure and system hardening, security architecture, and technical security controls Ability to assess the effectiveness of security controls against evolving threats and risk scenarios Passion for enabling secure technologies and processes Excellent problem-solving and analytical skills, with a structured yet pragmatic approach Team player who can also work independently, taking initiative to organize, manage, and deliver projects on time Strong interpersonal and communication skills, with the ability to write clear and concise risk assessment reports A strong communicator, fluent in spoken and written English A collaborative team player with analytical skills to provide practical risk solutions Well-organized, detail-oriented, and able to collect data, coordinate tasks, and lead projects Comfortable taking the lead, but also value the expertise of your colleagues Skilled in risk identification and articulation Able to build and maintain strong stakeholder relationships Proactive, decisive, and goal-oriented, even in ambiguous situations Nice-to-Have Skills Description: Experience with industry-recognized standards for IT security controls and best practices (e.g., NIST, ISO 27001, PCI DSS, COBIT, SOC 2) Professional qualifications such as CEH, CISSP, CISA, CISM, CRISC, or ITIL Languages: English: C1 Advanced
Benefits:
💰Paid Referrals 💻Equipment: laptop and monitor 🩺Private Medical & Dental care & Life Insurance covered 🏋🏽 ♀️ MyBenefit program (sports card, well-being program etc.) 🌎 Internal Mobility program
- possibility of rotation between projects, locations, accounts 🎓 LuxTalent platform (webinars, training, courses) ...and more Project Description: Are you fascinated by the third-party cyber threat landscape? Do you have a strong technical background and proven expertise in Cyber and Information Security and Technology Risk Management? In this role, you’ll collaborate closely with internal stakeholders to ensure third-party vendors comply with our cybersecurity policies and procedures. We’re looking for a Cyber and Information Security (CIS) professional to help design, develop, and enhance continuous monitoring processes and controls to manage cyber risks arising from third parties.
Responsibilities:
Execute and further develop the third-party continuous monitoring process Analyse alerts from third-party monitoring solutions, assess risks, and drive follow-up actions Assess the impact of cyber events (e.g., zero-day vulnerabilities) on the third-party portfolio Coordinate risk remediation actions with internal stakeholders and third parties Maintain and enhance the products and tools used in the monitoring process Design and implement additional technical processes and controls to manage third-party risk and reduce the attack surface Conduct deep dives into the bank’s third-party cyber and information security capabilities, drawing conclusions on overall risk posture Proactively challenge the status quo by identifying operational risks, proposing remediation or improvement solutions, and balancing potential tradeoffs Serve as a trusted technical partner and advocate for security risk culture in a highly federated environment Mandatory Skills Description: Knowledge and interest in third-party cyber risk management (TPCRM) Degree in Computer Science, Computer Engineering, Electrical Engineering, Information Security, or a related discipline Strong knowledge of Cyber and Information Security risk management and control frameworks (e.g., ISO 27001, NIST CSF, CSA Cloud Control Matrix) Broad expertise in areas such as network security, cloud security, application security, infrastructure and system hardening, security architecture, and technical security controls Ability to assess the effectiveness of security controls against evolving threats and risk scenarios Passion for enabling secure technologies and processes Excellent problem-solving and analytical skills, with a structured yet pragmatic approach Team player who can also work independently, taking initiative to organize, manage, and deliver projects on time Strong interpersonal and communication skills, with the ability to write clear and concise risk assessment reports A strong communicator, fluent in spoken and written English A collaborative team player with analytical skills to provide practical risk solutions Well-organized, detail-oriented, and able to collect data, coordinate tasks, and lead projects Comfortable taking the lead, but also value the expertise of your colleagues Skilled in risk identification and articulation Able to build and maintain strong stakeholder relationships Proactive, decisive, and goal-oriented, even in ambiguous situations Nice-to-Have Skills Description: Experience with industry-recognized standards for IT security controls and best practices (e.g., NIST, ISO 27001, PCI DSS, COBIT, SOC 2) Professional qualifications such as CEH, CISSP, CISA, CISM, CRISC, or ITIL Languages: English: C1 Advanced