Ideas | People | Trust
We're BDO. An accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today's changing world.
We work with the companies that are Britain's economic engine - ambitious, entrepreneurially-spirited and high-growth businesses that fuel the economy - and directly advise the owners and management teams leading them.
Role Purpose
The Third Party Risk Manager is responsible for implementation of the BDO third party security framework. This includes assessing the information security risks of our 3rd parties, by evaluating the 3rd parties' security controls and ensuring supplier and supply chain information security risks to BDO and BDO client services are identified, assessed and managed.
This role reports to the Information Security Manager.
Principal Accountabilities
1. Leads in the execution and continuous improvement of the information security supply chain framework, which includes ensuring that security controls are implemented within the supply chain lifecycle at BDO.
2. Co-ordinates the BDO supplier and supply chain information security due supplier risk assessment framework and due diligence procedure and delivery of service to stakeholders.
3. Supports risk-based planning for supplier information security due diligence and risk assessment activities.
4. Partners with procurement, contract management and other key stakeholders to ensure the end-to-end third-party processes consider information security.
5. Coordinates the gathering of vendor risk assessment data and prepares risk assessments for vendors as needed, to be published and communicated to stakeholders.
6. Understands and applies relevant regulatory and legal compliance requirements.
7. Assesses vendor risks against BDO contractual requirements and controls.
8. Conduct due diligence and assessments of third-party security controls and posture.
9. Coordinates the identification and ranking of vendor risks.
10. Coordinates the classification and tiering of vendors by risks and risk impacts.
11. Communicates identified risk requirements to internal stakeholders.
12. Builds communication and escalation plans around vendor risk management activities.
13. Ensures that vendor remediation actions, mitigation and contingency plans are identified and communicated to business owners.
14. Tracks identified risks and risk events through the supplier lifecycle.
15. Maintain required activity and risk metrics and other data.
16. Report on activities related to third party supplier assurance as required.
17. Collate, analyse, and track evidence provided and gathered via direct and indirect external sources to understand information security supply chain risk.
18. Supports review and continual improvement of information security supplier due diligence and risk assessment procedures.
19. Together with legal, develop and maintain a set of security contractual clauses and service level agreements.
Knowledge and Experience
1. Demonstrable experience with supplier and supply chain due diligence frameworks, procedures, data gathering and information security risk and controls assessment.
2. Experience of supplier information security risk management at all stages of the supplier lifecycle from procurement, contracting, on-boarding, contract management and off-boarding.
3. Experience with business service, system and data architectures.
4. Experience of information security audit and assurance.
5. Familiarity with formal information security frameworks and certifications such as SOC 2, ISO27001, CE+, CIS top 20, OWASP.
6. Experience with contract review of information security schedules and terms.
7. Excellent verbal, written and interpersonal communication skills. Listens and communicates technical subjects to both technical and nontechnical audiences, flexes style to suit the needs of the audience.
8. Excellent stakeholder engagement and management experience and skills with the ability to understand complex business structures and services and to advise senior stakeholders on information security risks, mitigations and management strategies.
9. Self-motivated with keen attention to detail.
10. Have a relevant industry certification such as CISSP, CISM, CRISC or equivalent.
#J-18808-Ljbffr