Technology Risk Analyst – Third-Party Risk _ Contract
Must-have:CloudSecurity
Technology Risk Analyst – Third-Party Risk
We are seeking an experienced Technology Risk Analyst to support the security review and assessment of third-party service providers and outsourcing arrangements for a leading financial institution.
This is a 06 -month contract position based in Changi, with employment through NTT Singapore.
Key Responsibilities
- Conduct due diligence and technology-risk assessments of third-party service providers and outsourcing arrangements.
- Assess information security, cybersecurity, cloud, technology, operational and compliance risks.
- Review vendor questionnaires, policies, certifications, audit reports and supporting control evidence.
- Evaluate the design and effectiveness of security and technology controls.
- Identify control gaps, risk exposures and areas of non-compliance.
- Document assessment findings, risk ratings and practical remediation recommendations.
- Engage vendors, business stakeholders, technology teams and control owners to clarify findings and obtain evidence.
- Track identified risks, remediation actions and outstanding documentation through closure.
- Prepare clear assessment reports and management updates.
- Support compliance with internal policies, control frameworks and applicable MAS regulatory expectations.
Requirements
- Diploma or degree in Information Technology, Cybersecurity, Information Systems, Risk Management or a related discipline.
- Relevant experience in third-party risk management, vendor due diligence, technology risk, cybersecurity risk, IT audit or information security reviews.
- Experience reviewing technology controls, supporting evidence and audit documentation.
- Knowledge of IT general controls, access management, change management, vulnerability management, incident management and business continuity.
- Familiarity with cloud security, outsourcing risk and technology-risk controls.
- Understanding of recognised frameworks such as ISO 27001, NIST, COBIT, SOC 1 or SOC 2.
- Familiarity with MAS technology-risk and outsourcing expectations would be advantageous.
- Strong analytical, documentation, report-writing and stakeholder-management skills.
- Ability to work independently and manage multiple assessments within agreed timelines.
- Professional certifications such as CISA, CISSP, CRISC, CISM or ISO 27001 would be advantageous.
Interested candidates are kindly requested to email their CV with their experience to sandeep.sringeripai@global.ntt
We look forward to your application!
Contact person
Listed by the employer in the job posting — for questions and your application.
- sandeep.sringeripai@global.nttsandeep.sringeripai@global.ntt