Role Summary:
Manage and strengthen the organization's Third-Party Risk Management (TPRM) program by conducting security due diligence, vendor risk assessments, and ongoing monitoring of third-party security posture. Support regulatory compliance and ensure third-party engagements align with banking security requirements and industry standards.
Qualifications & Experience
· 5–8 years of Information Security or GRC experience.
· Minimum 3 years of hands-on experience in Third-Party Risk Management.
· Banking or Financial Services experience preferred.
· Strong understanding of vendor security assessments and risk management methodologies.
· Experience with GRC platforms (ServiceNow GRC, RSA Archer, OneTrust, SAP GRC, or equivalent) is preferred.
· Bachelor's degree in Computer Science, Information Security, or related discipline.
Key Responsibilities:
1. Privacy Governance
- Design and implement the enterprise Privacy Governance Framework.
- Develop privacy policies, standards, procedures, and guidelines.
- Conduct DPIAs, PIAs, and privacy risk assessments.
- Maintain Records of Processing Activities (RoPA).
- Review lawful basis, data retention, disposal, and cross-border data transfers.
- Support Privacy by Design/Default implementation.
- Conduct data discovery and personal data mapping.
- Assess third-party privacy compliance and data-sharing arrangements.
- Support data subject rights, privacy audits, and regulatory compliance.
- Develop privacy awareness and training programs.
- Recommend privacy automation and GRC solutions.
2. Compliance & Framework Alignment
- Support implementation and maintenance of ISO 27701 and ISO 27001.
- Review privacy-related policies, procedures, and SOPs.
- Ensure privacy controls are embedded across business and technology functions.
- Support regulatory audits and privacy compliance assessments.
3. Reporting & Continuous Improvement
- Prepare privacy compliance reports and management dashboards.
- Monitor privacy risks and remediation activities.
- Deliver privacy awareness sessions.
- Drive continuous improvement through automation and governance enhancements.