Cyber Manager – Third Party Risk

Posted 1hrs ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Cyber Security Manager performing assessments and collaborating with stakeholders at Maersk. Managing third-party cyber security risks and promoting a culture of awareness across the company.

Responsibilities:

  • Conduct detailed cyber security assessments on third parties (e.g. suppliers, partners) consistently and timely
  • Report observations and collaborate with business stakeholders and the Cyber Risk team to ensure any identified risks are managed
  • Facilitate the supplier onboarding by performing rapid cyber security assessments and advising on potential risk exposure
  • Act as an SME to ensure appropriate cyber security measures are incorporated in agreements with third parties
  • Facilitate the collation of information required to respond to Maersk customer cyber security questions
  • Create documentation, reports, and dashboards for a variety of audiences to facilitate decision making
  • Build effective relationships with key stakeholders and teams across Maersk
  • Drive a culture of understanding and awareness of third party cyber security risk across Maersk
  • Focus on continuous improvement of processes, solutions and professional practices of the team

Requirements:

  • 8-12 years of experience in IT / Cyber security audit & risk management background
  • Cyber security assurance experience in a global business, preferably in third party assurance / vendor risk management roles
  • Risk-based and pragmatic approach to security
  • Demonstrable understanding of digital native and emerging technologies
  • In depth understanding of cyber security standards (e.g. NIST, ISO27001) and their application and implementation
  • Familiarity with GRC and cyber security monitoring tools (e.g. Archer, OneTrust, BitSight, etc.) and task management tools (e.g. Jira)
  • Cyber Security Certifications (e.g. CISSP, CISM, CISA) (preferable)
  • Proven ability to work and effectively prioritize in a dynamic environment
  • Excellent written and verbal communication skills, able to be understood by both technical and non-technical stakeholders
  • Stakeholder management and interpersonal/influencing skills
  • Excellent organisation, time management, problem-solving skills and attention to detail
  • Resilient, can-do attitude, ability to work as part of a team to meet deadlines

Benefits:

  • Career development opportunities
  • Broad business knowledge of global activities
  • Strong professional network
  • Opportunities to broaden knowledge and strengthen technical and professional foundation
  • Empowerment and ownership in developing new ways of working
  • Emphasis on diversity and inclusion