- Management and completion of Chubb inherent risk ranking of ALL suppliers in compliance with the Global Third-Party Cyber Risk policy. This includes liaising with and working alongside the Global Third-Party team as well as Business relationship Owners.
- Risk assessments of Cloud providers
- Identification, tracking and management of issues and control deficiencies relating to Third Parties, including liaising with the business owners to support remediation activities.
- Maintenance and management of the Information Security Third Party Inventory and the Issues Register in co-ordination with the Enterprise Risk Management strategy and approach.
- Performance and execution of Third Party Cyber Risk assessments initiated by business.
- Where applicable, executing, management and oversight of performing Third Party assessments meeting applicable SLA's.
- Reviewing information security policies, standards, guidelines and baselines in place and being developed.
- Assist with internal security reporting, including steering committees and updates for senior management.
- Management of Third-Party related information security projects.
- Develop and enhance the programme, progressing currently identified and future improvements to make the function more effective and efficient.
- Provide support to the TPCR Regional Lead and engage with the wider information Security team.
- High level of business acumen, preferably in a regulated/financial industry
- Five + years of information security experience with a focus on risk assessments and controls, governance, risk management, program development, compliance, and/or auditing. Previous experience of supporting or managing a Third-Party risk assessment programme is essential.
- Expert-level knowledge of both the business and technical aspects of information security, including third party security risk and European data protection regulation.
- Demonstrated ability to understand and analyse complex business processes and technologies to make sound recommendations to non-technical constituents
- Strong broad-based technical background (distributed/mainframe, database, web-based application development,
- Strong risk-based analysis and decision-making skills
- Experience interpreting and applying information security standards and frameworks (., ISO/IEC 27001/27002, PCI-DSS, NIST Cybersecurity Framework, or attestation reports (., SOC 1/2)
- eGRC system or similar system administration experience a plus
- Experience reviewing, and redlining agreements is a plus
- Ability to multitask and manage competing priorities
- Excellent time management and organizational skills
- Excellent interpersonal, customer service and conflict management skills
- Excellent written and verbal communication skills
- Proficient use of personal computers and Microsoft Office Suite
-
Central Risk Monitoring Analyst
hace 4 días
Heineken Monterrey, MéxicoEjecutar las pruebas y evaluaciones a los procesos de manera centralizada, dejando evidencia documental y reportando en tiempo y forma los hallazgos y/o problemas encontrados durante las revisiones ejecutadas, mediante la utilización de herramientas tecnológicas para apoyar en el ...
-
Central Risk Monitoring Analyst
hace 1 semana
Heineken Monterrey, MéxicoHEINEKEN MÉXICO representa al grupo cervecero de mayor tradición en México desde su fundación en 1890, con un equipo en México de más de 18,000 colaboradores. Los valores de nuestra compañía incluyen llevar diversión a la vida de nuestros consumidores y colaboradores haciendo pro ...
-
Operational Risk Assessments and Testing Analyst
hace 1 semana
GM Financial Monterrey, MéxicoOverview: · As a member of the International Operations Operational Risk Management team within the GM Financial's Global Compliance and Privacy organization, you will facilitate the team's risk analytics and reporting activities. This will include the preparation of management r ...
-
Cbsm - Third Party Cyber Risk Analyst
hace 3 semanas
Chubb INA Holdings Inc. Monterrey, MéxicoJob Requirements · **Key Responsibilities**: · Management and completion of Chubb inherent risk ranking of ALL suppliers in compliance with the Global Third-Party Cyber Risk policy. This includes liaising with and working alongside the Global Third-Party team as well as Business ...
-
enterprise risk management analyst
hace 3 días
CEMEX San Pedro Garza García, MéxicoJob Description · Support the identification, analysis, assessment, mitigation and follow up of the main risks and opportunities that could impact Cemex's strategic objectives. · Main Responsibilities · Support the development of the Enterprise Risk Agenda · Develop profiles and ...
-
Enterprise Risk Management Analyst
hace 3 semanas
Cemex, Inc. San Pedro Garza García, MéxicoSelect how often (in days) to receive an alert: · (CEN) ENTERPRISE RISK MANAGEMENT ANALYSTDate: May 10, 2024 · Job Description Support the identification, analysis, assessment, mitigation and follow up of the main risks and opportunities that could impact Cemex's strategic objec ...
-
Credit Manager
hace 2 semanas
Michael Page Monterrey, MéxicoEvaluate the creditworthiness of customers using financial statements, credit reports, and other data. · Analyze risks to set appropriate credit limits and terms, considering payment history and market trends. · Create and enforce credit policies to ensure effective credit manage ...
-
Credit Manager
hace 2 semanas
Michael Page Monterrey, MéxicoDetalles del cliente · International Manufacturing Company · Descripción de la vacanteEvaluate the creditworthiness of customers using financial statements, credit reports, and other data. · Analyze risks to set appropriate credit limits and terms, considering payment history and ...
-
QA Analyst
hace 23 horas
CHUBB Monterrey, México Regular - De jornada completaChubb has an exciting job opportunity available for a ServiceNow Quality Assurance Analyst to join our team. With us, you'll serve as a quality assurance analyst, partnering with product owners, stakeholders, project managers, ServiceNow platform team and external implementation ...
-
Analista y Desarrollador SR de Sistemas de Pago
hace 2 días
09516 Banco Nacional de Mexico, S.A., integrante del Grupo Financiero Banamex Leon, México De jornada completaThe Applications Development Senior Programmer Analyst is an intermediate level position responsible for participation in the establishment and implementation of new or revised application systems and programs in coordination with the Technology team. The overall objective of thi ...
-
Claims Analyst l
hace 1 semana
AIG Monterrey, México De jornada completaClaims Analyst IWho we are? · American International Group, Inc. (AIG) is a leading global insurance organization. AIG member companies provide a wide range of property casualty insurance in approximately 70 countries and jurisdictions. These diverse offerings include products an ...
-
IT Compliance Analyst
hace 3 semanas
British American Tobacco Monterrey, México PermanentBAT is evolving at pace - truly like no other organization. · To achieve the ambition, we have set for ourselves, we are looking for colleagues who are ready to live our ethos every day. Come be a part of this journey · BAT MEXICO IS LOOKING FOR AN IT COMPLIANCE ANALYST · SEN ...
-
Analista de Infraestructura Unisys-1
hace 2 semanas
09516 Banco Nacional de Mexico, S.A., integrante del Grupo Financiero Banamex Monterrey, México De jornada completaThe Infrastructure Intermediate Technology Analyst is an intermediate level role responsible for assisting with LAN / WAN and help desk administration activities, including network maintenance, technical guidance, and security in coordination with the Technology Infrastructure te ...
-
Acceleration Center
hace 3 días
PwC Monterrey, México De jornada completaDescription · & SummaryA career in our Managed Services team will provide you an opportunity to collaborate with a wide array of teams to help our clients implement and operate new capabilities, achieve operational efficiencies, and harness the power of technology. · Our Applic ...
-
Restructure Analyst I
hace 3 semanas
Caterpillar Monterrey, México OTHERJob Description: · Your Work Shapes the World at Caterpillar Inc. · When you join Caterpillar, you're joining a global team who cares not just about the work we do – but also about each other. We are the makers, problem solvers, and future world builders who are creating strong ...
-
Business Analyst – Commercial Wholesale
hace 3 semanas
GM Financial Monterrey, MéxicoWhy GMF? · [This is a temporary position for a period of 5 months. Please apply with a resume in English] · GM Financial International Operations conducts business in Latin America and China. International Operations offers a wide range of wholesale and retail automotive finan ...
-
Value Realization Manager
hace 1 semana
The British American Tobacco Group Monterrey, MéxicoBAT is evolving at pace - truly like no other organization. To achieve the ambition, we have set for ourselves, we are looking for colleagues who are ready to live our ethos every day. Come be a part of this journey BAT MEXICO IS LOOKING FOR A VALUE REALIZATION MANAGER SENIORITY ...
-
Seguridad Digital
hace 4 días
Hb Soluciones Monterrey, MéxicoEmpresa Americana de manufactura y refrigeración busca:IT Cybersecurity Analyst- Monitor and analyze intrusion detection to identify security issues- Monitor and manage next-generation anti-virus, EDR and DLP- Monitor and respond to threat alert from SIEM- Recognize potential, su ...
-
Financial Analyst
hace 1 semana
Johnson Controls International Nuevo León, México PermanentJohnson Controls is a global diversified technology and multi industrial leader serving a wide range of customers in more than 150 countries. Our 130,000 employees create intelligent buildings, efficient energy solutions, integrated infrastructure and next generation transportati ...
-
Asesor De Procesos E Implantación
hace 1 semana
Citigroup Inc. León, MéxicoThe Ops Sup Analyst 2 is an intermediate level position responsible for providing operations support services, including but not limited to; record/documentation maintenance, storage & retrieval of records, account maintenance, imaging and the opening of accounts in coordination ...
Third Party Cyber Risk Analyst - Monterrey, México - CHUBB
![Default job background](https://contents.bebee.com/public/img/bg-user-ex-1.jpg)
Descripción
This resourcing requirement is responsible for supporting the management of Third-Party Information Security Risk for the Chubb organization.This includes performing the inherent risk ranking of all suppliers in relation to Information Security Risk, and responsibility for completing remote and on-site assessments of higher risk third parties and prioritizing reviews where appropriate.
The role directly contributes to the Global and regional Third Party Cyber Risk teams by providing metrics, maintaining a Third-Party Asset inventory and tracking both risk remediation and control compliance.
The successful candidate will also have the opportunity to be involved in a number of different high-profile Information Security work streams with a broader focus on information security risk management, control assurance, policy governance and compliance.
Part of the remit of this role will also be to develop and enhance the programme into an automated tool and align process and procedure with other functions to help streamline the broader scope of Vendor Management and onboarding.