JOB SUMMARY:
We are seeking a highly skilled and motivated Specialist Analyst, Tech Risk Operations to play a key role on our Technical Risk team. This role will lead key risk operations for a team that’s mission is to support the reduction of business risk through: Managing our organization's interactions with external vendors, suppliers, and other third-party service providers, and will support the identification and mitigation of potential risks associated with thorough the execution of risk assessments, compliance monitoring, and stakeholder engagement throughout the vendor lifecycle. Developing comprehensive business resiliency plans, operationalizing technology failover and recovery methodologies, and enhancing recovery capabilities across critical systems and applications. Additionally, will be responsible for performing risk assessments, training employees on crisis response, supporting recovery exercises, and developing executive briefing material. Identifying, tracking, analyzing, and resolving technical issues within an organization's IT infrastructure, utilizing established processes and tools to ensure timely resolution and minimize disruption to business operations; key duties include triaging incidents, performing root cause analysis, coordinating with relevant teams, and reporting on trends to proactively prevent future issues.
KEY JOB FUNCTIONS:
1. Risk Assessment:
• Identify potential risks and vulnerabilities that could impact business operations, analyzing their likelihood and potential impact
• Identify and ensure adherence to relevant regulations and industry standards
• Support resilience assessments of third-party vendors and suppliers
2. Business Impact Assessment (BIA):
• Evaluate the critical functions and dependencies within the organization to determine the potential consequences of disruptions
• Align critical functions to key systems, applications, and recovery owners to establish a prioritized business impact and recovery visualization
3. Business Continuity Planning (BCP):
• Develop and maintain comprehensive BCPs that document critical capabilities, recovery strategies, resources, and effective communication to stakeholders.
• Educate employees on business resilience procedures, crisis response, and emergency contact information.
• Ensure materials are accurate, concise, and intuitive.
• Develop and maintain standards and procedures for resilience testing and reporting across business functions, applications, and systems.
4. Vendor Due Diligence:
• Conducting risk assessments on new and existing third-party vendors, including operational capabilities, cybersecurity practices, and compliance with relevant regulations.
• Collecting and analyzing information from vendor questionnaires, documentation, and, if applicable, site visits.
5. Risk Identification and Prioritization:
• Identifying potential risks associated with third-party relationships, such as data privacy breaches, regulatory non-compliance, operational disruptions, and reputational damage
• Categorizing risks based on severity and likelihood
6. Risk Mitigation Strategies:
• Developing and implementing risk mitigation plans, including contractual agreements, performance monitoring metrics, and remediation actions.
• Collaborating with stakeholders to ensure third-party vendors are adhering to required compliance standards and security controls.
7. Incident Management:
• Receive and log IT related incidents through ticketing systems.
• Prioritize and triage incidents based on severity and impact.
• Assign incidents to appropriate technical teams for resolution.
• Collaborate with technical teams to identify and implement solutions.
• Monitor incident progress and escalate issues as needed.
• Communicate status updates to stakeholders throughout the incident lifecycle.
8. Reporting and Analysis:
• Generate reports on incident trends, key performance indicators (KPIs), and root cause analysis.
• Analyze data to identify potential areas for improvement in IT processes.
• Present findings and recommendations to IT leadership.
9. Stakeholder Management and Collaboration:
• Communicating with internal departments and external vendors regarding third-party risk management policies and procedures.
• Collaborating with legal, compliance, and procurement teams to manage vendor relationships and mitigate risk.
• Work closely with various IT teams including network, server, application, and helpdesk support.
• Coordinate with business stakeholders to understand impact of IT issues on operations.
EDUCATION and/or EXPERIENCE and QUALIFICATIONS:
Bachelor’s degree in computer science, information systems, cyber-security, or related discipline. 4+ years of experience in consulting, program management, communications, or a related role. Excellent written and verbal communication skills. Proven ability to handle diverse projects simultaneously and meet deadlines. Strong analytical and problem-solving skills.Preferred Qualifications:
Master’s degree in computer science or management of information systems Experience in a corporate or large organizational setting. Familiarity with relevant regulations and compliance requirements, such as data privacy laws, SOX, cybersecurity industry standards, etc. Project Management Experience
PHYSICAL WORK ENVIRONMENT AND REQUIREMENTS:
Flexible working arrangements may be available. Some Travel may be required