Third Party Security Assessor

Mumbai, Maharashtra, India

Third Party Security Assessor

  • 202509060
  • Mumbai, Maharashtra, India
查看收藏夹

Description

About the Team:

Information and Cyber Security team aims at protecting WTW, our colleagues and our clients confidential information by assuring its handled securely by security assessing assets and Third parties as well as assuring client legal obligations with control owners globally.

  • Key Responsibilities

    ▪ Leading and coordinating the completion of third-party assessment requests against WTW best practice and global standards and controls.
    ▪ Scheduling periodical re-assessment in line with standards and controls.
    ▪ Agree scheduled checkpoints with the third party and WTW Service Owner on evidencing remediations and maintaining central repository; these are tracked through to closure.
    ▪ Providing comprehensive reporting across operational and security KPIs related to third-party assurance activities and identifying gaps, risks, and therefore mitigating actions, and raising appropriate escalations for decision with Head of ICS Third Party Supplier Assurance.
    ▪ Providing risk-based assurance advice on all information security issues.
    ▪ Provide key information to leadership as input for prioritizing the future strategy for the organization.
    ▪ Coordinate with the CISO Office and the Internal Audit function in order to coordinate the execution of internal and external audits and manage the delivery of the required remediation activities in a timely manner.
    ▪ Assisting and collaborating with internal teams on third-party security incidents investigation and response.
    ▪ Assist in developing and continuously improving third-party risk management frameworks and processes to help ensure that the information security controls outlined in the policies and standards are effectively applied by third-party providers.

  • Required Skills

  • Third-party risk management

  • IT General Controls (ITGC)

  • Security audits and compliance

  • Review of SOC 2 and other security assessment reports

  • Nice to Have

  • Information security certifications (CISM, CISSP, etc.)

  • Knowledge of security and privacy regulations

  • Basic understanding of security operations

  • Soft Skills

  • Strong communication and stakeholder management

  • Ability to work well in teams

  • Adaptable and proactive mindset

Qualifications

  • Degree in Business, Information Technology, or a related field

  • 4+ years of experience in third-party risk, information security, or governance

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidatehelpdesk@wtwco.com.

主动联系

任何未经请求主动通过我们的网站或韦莱韬悦员工的个人电子邮件帐户提交的简历/应聘者资料,均视为韦莱韬悦的财产,且无需支付代理费用。要成为韦莱韬悦的授权招聘机构/猎头公司,此类机构必须持有由韦莱韬悦授权招聘人员签署的正式书面协议,并与公司保持积极的工作关系。简历必须按照我们的应聘者提交流程进行提交,包括积极参与特定职位的搜索工作。同样,对于我们授权的招聘机构/猎头公司,如果未能遵守应聘者提交流程,韦莱韬悦将不支付任何代理费用。韦莱韬悦是提倡机会均等的雇主。如果您希望我们保存您的联系信息以便将来考虑,请发送电子邮件至:Agency.inquiries@willistowerswatson.com

我们的办事处

我们的员工为全球 140 多个国家和市场提供服务。这为我们所做的每一项工作注入了全球视野,同时也能够为您创造许多绝佳的合作机遇与成长空间。探索下面的地图,探索您的职业发展可能。