Senior Supplier Risk Assurance Analyst
6 days left
- Full time
EY GDS (Global Delivery Services) means 40.000 specialists providing globally IT, project management and strategic business services to EY member firms. In addition we deliver support and solutions to clients from all over the world.
The Supplier Risk Assurance program evaluates and monitors information security risk associated with the Firm’s use of third party technology suppliers. We measure risk against Firm security controls, industry standards, regulations and laws, and EY business practices. We then advise our engagement and project managers, our procurement team, and our Legal teams in the recommended treatment of the risk assessment conclusions.
In a working world where there is an increasing reliance on third party provided products and services the role offers interaction with some of the most interesting and important technology related activities of the Firm across the spectrum of services offered.
This role is an important and very visible contributor offering highly valued and critical services within a highly collaborative team environment. A more exciting challenge is difficult to find!
Your key responsibilities:
The person chosen will conduct inherent risk assessments, supplier research, reporting, data analytics, communications with our stakeholders, and other required tasks associated with the execution of the Supplier Risk Assurance mission.
Skills and attributes for success:
- Well-developed and creative analytic abilities to synthesize technical data, project related information, interview and survey results, and other information to inform risk decisions.
- Ability to manage and deliver on multiple and shifting priorities to provide high quality, timely, and effective service to our customers.
- Advanced interpersonal skills to engage and collaborate with multiple internal and external stakeholders within a matrixed and global organization.
- Highly developed communications skills, both oral and written in the English language
- Must be able to rapidly learn a complex business process that involves acquisition of knowledge and familiarity with related regulations, EY Policies and Standards, and international standards such as ISO 27001:2013
To qualify for the role you must have:
- Bachelor level or higher degree in computer science or related discipline such as engineering or an equivalent in experience (minimum of 3years in a related function)
- Experience in any of the following: information security, IT risk management, internal audit, IT process and analytics, or compliance
- Awareness of Information Security controls such as ISO27001:2013, NIST, or SOC.
Ideally, you’ll also have:
- Certifications such as the Certified Information Systems Security Professional (CISSP), Global Security Essentials Certification (GSEC), or Certified in Risk and Information Systems Control (CRISC).
- Good working knowledge of data analytic methods and tools, including but not limited to Spotfire, and Microsoft Excel. Good knowledge and skills with Microsoft Office and Sharepoint.
- Experience, skills, or education in Information Security technical areas.
What we look for:
The ideal candidate will enjoy the challenge of rapid acquisition of knowledge and have the skills and determination to join a high performing team. We are looking for someone who is agile, flexible, serious about providing top flight service to our customers, and above all a great team member.
If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.
Make your mark.
For further information, and to apply, please visit our website via the “Apply” button below.