GDS Consulting_Cyber Risk, Compliance & Resilience - Senior
EY
- Location
- Taguig, PH, 1634 +1 more…
- Work model
- On-Site
- Level
- Senior
Skills
About this role
EY- Cyber Security (Risk, Compliance and Resilience) – Technology Consulting – Senior As part of our EY Cyber Risk, Compliance and Resilience Technology Consulting team, you would work on various projects for our global customers, spanning a diverse range of businesses industries, and in collaboration with EY Consulting practices and teams. An important part of your role will be to actively establish, maintain and strengthen internal and external relationships. You’ll also identify potential business opportunities for EY and GDS within existing engagements and escalate these as appropriate. Similarly, you’ll anticipate and identify risks within engagements and share any issues with senior members of the team. In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards and is reviewed by the next-level reviewer. As an influential member of the team, you’ll help to create a positive learning culture, coach and counsel junior team members and help them to develop their future in EY. The opportunity We’re looking for a Senior Security Consultant with expertise in cyber/information security, risk and controls concepts. This is an opportunity to be part of a market-leading, multi-disciplinary consulting firm whilst being instrumental in the growth of the risk, compliance, and resilience sub-competency , in the only integrated global transaction business worldwide. Your key responsibilities
Ensure smooth delivery of third-party risk management engagements, which involve performing security assessments of the client’s third-party service providers/vendors. Activities may include, but are not limited to:
Performing security assessments of new and existing service providers which includes assessing vendor responses and following up with vendor directly for clarifications or additional documentation Conducting a risk analysis and assessment of vendor information and documentation against client IT security and data privacy requirements Defining appropriate risk levels and corrective actions Identifying process gaps, risks to the client’s environment and providing risk remediation recommendations Working with the client’s business units and/or vendors to understand and accept recommended remediation steps Monitoring risk exposures through closure Understanding, reviewing, revising or drafting client security policies, basing on client requirements and industry security standards
Develop and maintain productive working relationships with client personnel Work effectively as an individual contributor and as a team member, consistently demonstrating accountability, providing support, effectively communicating within the unit Execute engagement requirements, along with review of work by junior team members Proactively developing, maintaining and sharing accurate engagement and deliverable status reporting to relevant stakeholders at different levels Build strong internal relationships within EY Consulting Services and with other services across the organization Understand and follow workplace policies and procedures
Contribute to people-related initiatives including recruiting and retaining Cyber Transformation professionals Support skills development of junior/staff level peers Building a quality culture at EY GDS Provide feedback for performance reviews staff/junior level team members, where applicable Manage the performance management for direct reportees, as per the organization policies Foster teamwork and lead by example Participating in the organization-wide people initiatives
Skills and attributes for success
Strong knowledge in key components of cybersecurity including (but not limited to):
Regulations/standards such as ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, NIST 800-53 Third Party Vendor/Supplier Risk Assessments and Risk