Cyber Security Risk Specialist - Grc, Third-Party Risk Assessments, Iso27001
Current• I managed the entire Vendor Risk Management Framework using GRC tools like One Trust.• I handled the Security Compliance Assessment of numerous third party vendors/suppliers ensuring they are compliant with Security standards as well as Data Privacy regulations• I worked within scrum teams working in an agile manner whilst collaborating with other business departments• I reviewed vendor risk reports highlighting cybersecurity impacts• I created risk review documentation and used a risk tiering formula to prioritize for remediation the risks identified based on their severity.• I created a risk treatment plan using ISO27001 standards which was used by the organization to carry out risk assessments and compliance analysis across all areas of the business.• I managed the Information Technology Risk Management Framework including the Risk register for the organization• I acted in a Second line of defence capacity challenging, reviewing and reporting of risk exposure, events and emerging issues • I supported the renewal of the organization’s Cyber Essential plus certification• I created a compliance discovery questionnaire template which we sent to all business areas to answer which aided in my analysis of the different business areas • Based on the responses of the compliance questionnaire, I carried out risk assessments on their business processes and procedures. • Using a Risk Management tool I managed the Risk backlog and took actions to remediate all open risks • Worked very closely with Legal team during third-party negotiation sessions to ensure contracts where compliant with our security objectives• I identified all business owners for all suppliers and ensured that all risks associated with that vendor is brought to acceptable levels. • Managed relationships with key stakeholders to influence and support the delivery of appropriate Cyber security products