Cybersecurity and Technology Risk Engineer
Job Description – Technology Risk & Third-Party Security Assessment Specialist
We are seeking an experienced Technology Risk & Third-Party Security Assessment Specialist to support the security review and assessment of third-party service providers and outsourcing arrangements. The successful candidate will conduct vendor due diligence reviews, assess information security, technology, and compliance risks, evaluate control evidence and documentation, identify risk gaps, and provide clear recommendations for risk mitigation.
Key Responsibilities
Perform third-party and outsourcing risk assessments. Review vendor security controls, policies, certifications, and audit reports. Assess information security, technology, compliance, and cloud-related risks. Identify control gaps and recommend remediation actions. Prepare risk assessment reports and document findings. Collaborate with business, technology, security, compliance, and vendor stakeholders. Requirements
5+ years of experience in Technology Risk, Cybersecurity, IT Audit, Information Security, or Vendor Risk Management. Strong understanding of third-party risk management and vendor due diligence processes. Knowledge of cybersecurity controls, cloud security, and outsourcing risk management. Familiarity with MAS Technology Risk Management (TRM) and Outsourcing Guidelines is preferred. Excellent analytical, report-writing, and stakeholder management skills. Relevant certifications such as CISSP, CISA, CRISC, CISM, or ISO 27001 are advantageous. Preferred Background Experience within banking, financial services, fintech, or other highly regulated environments is highly desirable.