Technology Risk Analyst – Third-Party Risk _ Contract
Roles & Responsibilities
Technology Risk Analyst – Third-Party Risk
We are seeking an experienced Technology Risk Analyst to support the security review and assessment of third-party service providers and outsourcing arrangements for a leading financial institution.
This is a 06 -month contract position based in Changi, with employment through NTT Singapore.
Key Responsibilities
- Conduct due diligence and technology-risk assessments of third-party service providers and outsourcing arrangements.
- Assess information security, cybersecurity, cloud, technology, operational and compliance risks.
- Review vendor questionnaires, policies, certifications, audit reports and supporting control evidence.
- Evaluate the design and effectiveness of security and technology controls.
- Identify control gaps, risk exposures and areas of non-compliance.
- Document assessment findings, risk ratings and practical remediation recommendations.
- Engage vendors, business stakeholders, technology teams and control owners to clarify findings and obtain evidence.
- Track identified risks, remediation actions and outstanding documentation through closure.
- Prepare clear assessment reports and management updates.
- Support compliance with internal policies, control frameworks and applicable MAS regulatory expectations.
Requirements
- Diploma or degree in Information Technology, Cybersecurity, Information Systems, Risk Management or a related discipline.
- Relevant experience in third-party risk management, vendor due diligence, technology risk, cybersecurity risk, IT audit or information security reviews.
- Experience reviewing technology controls, supporting evidence and audit documentation.
- Knowledge of IT general controls, access management, change management, vulnerability management, incident management and business continuity.
- Familiarity with cloud security, outsourcing risk and technology-risk controls.
- Understanding of recognised frameworks such as ISO 27001, NIST, COBIT, SOC 1 or SOC 2.
- Familiarity with MAS technology-risk and outsourcing expectations would be advantageous.
- Strong analytical, documentation, report-writing and stakeholder-management skills.
- Ability to work independently and manage multiple assessments within agreed timelines.
- Professional certifications such as CISA, CISSP, CRISC, CISM or ISO 27001 would be advantageous.
Interested candidates are kindly requested to email their CV with their experience to sandeep.sringeripai@global.ntt
We look forward to your application!
Tell employers what skills you have
Security Controls
Information Security Policy
Technology Risk Management
Remediation
Risk Assessment
Regulatory Compliance
Gap Analysis
ISO 27000
Cyber Security
Compliance Management
It General Controls
IT Security Assessments
Risk and Compliance Reporting
Vendor Management
Audit Management
Control Testing
NIST
IT Risk Management
Cybersecurity
It Auditing