Apply Edge Start your job search

Third Party Risk Management

Tata Consultancy Services · Riyadh, Saudi Arabia

Apply & track with Apply Edge
Job Title – Third Party Risk ManagementCompany – TCS (MEA)Location – Riyadh, Saudi ArabiaJob type – Full timeAbout Us:Tata Consultancy Services (TCS) is an IT services, consulting and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 50 years. TCS offers a consulting-led, cognitive powered, integrated portfolio of business, technology and engineering services and solutions. This is delivered through its unique Location Independent Agile™ delivery model, recognized as a benchmark of excellence in software development.A part of the Tata group, India's largest multinational business group, TCS has over 616,171 of the world’s best-trained consultants with 157 nationalities in 53 countries. For more information, visit www.tcs.com and follow TCS news at @TCS_News.Key ResponsibilitiesPrimary SkillsKey Accountabilities:Perform security review of supplier responses within Client’s risk management platform tool (customized Archer)Create internal risk reports following Client’s report template documenting risk severity and identified findingsConsult and partner with Supplier Portfolio Managers to determine risk treatment and enable the business to make informed decisions on third party selectionsConsult and partner with stakeholders to transition identified findings for remediation or mitigationTrack and monitor risk mitigation and remediation of third partiesInterface with Suppliers frequently to ensure compliance to Client’s privacy and security requirementsEducation/Professional Qualifications:Bachelor’s degree or international equivalent or equivalent work experiencePreferred, CTPRP, CISA, CISM, CRISC, CISSP, or ISO27001 Lead AuditorExperience & Skills:· Minimum 5-6 years performing Security Risk Assessments in line with industry standards and ensuring compliance to global laws and regulatory requirements· Strong understanding of ISO 2700 series, SAMA regulation, SOC 1, SOC 2, and SOC 3 · Strong understanding of the COBIT, NIST, and Risk IT frameworks· Knowledge of global regulatory requirements and compliance in Security, Privacy, Healthcare, Finance, etc., (i.e., SAMA, GDPR, CCPA, HIPPA, PCI DSS, NYDFS, SoX, etc.) · Knowledge of Cloud security· IT experience with 3-4 years of security/infrastructure protection and information technology audit experience· Multi-platform knowledge. Experience in UNIX, Windows and IP intranet/Internet security environments including firewalls, intrusion detection, incident response, policy writing, vulnerability testing, operating system hardening, regulatory compliance, and data classification· Solid knowledge of industry standard corporate security and network policies and procedures· Demonstrated competency in project management in a cross-functional environment· Experience linking legal and regulatory statutes with corporate policies· Demonstrated competency in developing effective solutions to diverse and complex business problems· Strong analytical and problem-solving skills· Demonstrated ability to work effectively within a team environment· Demonstrated ability to identify business needs · Demonstrated ability to handle confidential information in an appropriate manner· Demonstrated ability to communicate at multiple levels within the companyRequirements:· Fluent English and strong communication skills (i.e., written, oral proficiency and presentation)Bachelor’s degree or equivalent work experienceProficient in MS Office suite (i.e., Word, Excel and PowerPoint)Cross-Cultural competence, interpersonal communication and teamwork skillsSelf-motivated, ability to prioritize tasks and multi-task, comfortable with change and complexity, and deliver high quality, accurate work within tight deadlinesStrong knowledge of Security Risk Management / Information Security / Data PrivacyMay occasionally require hours to accommodate global time zonesApplication Deadline: 30th -September-2026Privacy Note:https://www.tcs.com/connect-with-tcs/privacy-policy