Join EY as a Senior in the Third-Party Risk as a Service (RSS) team and help clients enhance their business performance by translating their strategies into realities. As a leader in the team, you will be responsible for delivering Third-Party Risk Management (TPRM) engagements and working closely with the manager to achieve exceptional client service.
Requirements
- 4-8 years of demonstrated experience with Risk Management across the Third-Party engagement lifecycle
- Strong understanding of the TPRM framework, Risk Management, Information Security practices
- Hands-on exposure to TPRM tools and technology solutions
- Demonstrated knowledge of standards such as ISO 27001/2, ISO 22301, ISO 27018, PCI – DSS, HITRUST, etc.
- Good knowledge of privacy regulations such as GDPR, CCPA, etc.
- Good knowledge of regulations such as FISMA, HIPAA, Reg SCI, MAS, etc.
- Good knowledge of TCP/IP, concepts of OSI layer and protocols, networking and security concepts, Physical & Environmental Security, Asset Security and Identity & Access Management.
- Good knowledge of OS (Windows / Linux) security, Database security, IT infrastructure (switches, routers, firewalls, IDS, IPS, etc.), Security architecture design, and review.
- Good familiarity with OWASP, and Secure SDLC standards/frameworks, anti-virus solutions (e.g., Symantec, McAfee, etc.).
- Good experience in LAN/WAN architectures and reviews.
- Good knowledge of incident management, disaster recovery, and business continuity management, cryptography.
- Certifications - CISSP, CISA, CISM, CTPRP, CIPP, ISO 27001 Lead Auditor or Lead Implementer
Benefits
- Competitive salary
- Opportunities to develop new skills and progress your career
- The freedom and flexibility to handle your role in a way that’s right for you
- Support, coaching, and feedback from engaging colleagues
- Opportunities to work on inspiring and meaningful projects
- Individual progression plan
- Challenging and stimulating assignments
- Interdisciplinary environment that emphasizes high quality and knowledge exchange