Global Vendor Security Assessment Manager

1 month ago


Johannesburg, Gauteng, South Africa Dentons Full time

WHY DENTONS

Dentons stands out in the legal landscape. Our commitment to innovation drives us to redefine the future of law, offering comprehensive business solutions to our clients through fresh and creative approaches. As the largest global law firm, we leverage the diverse insights of our workforce, clients, and communities, blending local expertise with worldwide perspectives.

ROLE OVERVIEW

This position centers on performing security evaluations of third-party vendors and managing risks associated with the supply chain from a cybersecurity standpoint. You will be responsible for assessing, monitoring, quantifying, and reporting on third-party cyber risks throughout the global organization.

KEY RESPONSIBILITIES

  • Oversee the entire third-party cyber risk management process, from initial security evaluations during onboarding to vendor offboarding.
  • Create an annual schedule for re-evaluating third-party cybersecurity risks affecting the organization.
  • Establish and implement necessary third-party security assessments based on the services utilized by the organization, enhancing existing security evaluations.
  • Identify and develop relevant cybersecurity risk management information across the vendor landscape.
  • Propose and execute enhancements to current third-party risk management processes and protocols.
  • Conduct thorough cybersecurity assessments of third-party vendors and pinpoint controls to mitigate associated risks to the organization’s cybersecurity framework.
  • Adhere to established guidelines for third-party cybersecurity risk management during the onboarding of vendors.
  • Work collaboratively with internal teams and various risk and compliance experts to address and mitigate identified cybersecurity risks.
  • Engage with stakeholders to identify and communicate cybersecurity risks stemming from third-party relationships, driving residual risks to acceptable levels.
  • Review information security clauses in third-party contracts to bolster the organization’s legal security framework.
  • Design and deliver training programs for staff on third-party risk management processes as necessary.
  • Execute tasks with minimal oversight, fostering a collaborative and supportive environment.
  • Perform additional cybersecurity risk management duties as required.
  • Lead and mentor members of the third-party cyber risk team.
  • Supervise and guide junior team members.

QUALIFICATIONS

SKILLS & COMPETENCIES

Technical Skills

  • Proficient in Microsoft Office Suite.
  • Fluent in English, both written and spoken.

Personal Attributes

  • Exceptional troubleshooting, reasoning, and problem-solving abilities.
  • Quick learner with the capacity to grasp new concepts and technologies.
  • Strong critical thinking and analytical skills to identify issues and risks related to third-party risk management.
  • Team-oriented with a proven ability to collaborate effectively.
  • Skilled in multitasking, prioritizing, and executing tasks efficiently.
  • Able to work independently while collaborating with teams across different locations.
  • Demonstrates a strong work ethic and a passion for problem-solving.
  • Excellent relationship-building skills with clients.
  • Stays informed about industry trends in third-party and cybersecurity risk.
  • Outstanding written and verbal communication, interpersonal, and intercultural skills.

EDUCATION & EXPERIENCE

  • Bachelor's degree from an accredited institution.
  • 3-5 years of management experience.
  • 5+ years of hands-on experience in third-party or cybersecurity risk management.
  • Expertise in identifying cybersecurity risks in cloud services and implementing mitigating controls.
  • Experience in addressing and remediating cybersecurity vulnerabilities.
  • Strong knowledge of third-party risk strategies and best practices.
  • Relevant industry certifications such as CRISC, CISM, CISA, or ISO/IEC 27001 Lead Auditor.
  • Familiarity with industry standards and best practices, including ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and the NIST Cybersecurity Framework.

LANGUAGE CAPABILITIES

As a truly global law firm, we value candidates with foreign language skills and those with international experience gained across various regions.

BENEFITS

Flexible work-from-home options available.



  • Johannesburg, Gauteng, South Africa Dentons Full time

    WHY DENTONSDentons stands out in the legal landscape. Our commitment is to be the firm of the future, constantly challenging conventional practices and delivering comprehensive business solutions to our clients through innovative approaches. We embody the spark of creativity and bold ideas. As the largest global law firm, we have over 12,000 professionals...


  • Johannesburg, Gauteng, South Africa Dentons Full time

    WHY DENTONSDentons is committed to redefining the legal landscape. We strive to be the firm of the future, consistently challenging conventional norms while delivering comprehensive business solutions to our clients through innovative approaches. We embody creativity and boldness, standing as the world's largest global law firm with over 12,000 professionals...


  • Johannesburg, Gauteng, South Africa Dentons Full time

    Why Dentons?Dentons is a global law firm that values innovation and collaboration. We are driven to provide holistic business solutions to our clients, and our diverse team of professionals is key to achieving this goal.Role OverviewThe Global Third-Party Security Review Lead will be responsible for conducting third-party vendor security assessments and...


  • Johannesburg, Gauteng, South Africa Dentons Full time

    Job Title: Global Third-Party Security Review LeadAbout DentonsDentons is a global law firm that is designed to be different. We are driven to always be the firm of the future, to challenge the status quo, and to provide holistic business solutions to our clients in new and innovative ways. We are the lightbulb moments. The bold ideas. We are a team of...


  • Johannesburg, Gauteng, South Africa Dentons Full time

    {"title": "Cyber Security Risk Management Lead", "subtitle": "Join Dentons", "content": "Dentons is a global law firm that values innovation and collaboration. We are seeking a skilled Cyber Security Risk Management Lead to join our team.The successful candidate will be responsible for conducting third-party vendor security assessments and managing supply...


  • Johannesburg, Gauteng, South Africa Dentons Full time

    Job Title: Global Third-Party Security Review LeadAbout Us:Dentons is a global law firm that values innovation, collaboration, and excellence. We are committed to providing holistic business solutions to our clients and fostering a culture of diversity, equity, and inclusion.Job Summary:We are seeking a highly skilled and experienced Global Third-Party...


  • Johannesburg, Gauteng, South Africa Nedbank Full time

    Job OverviewThis is a critical role in our organization's digital transformation journey. As an IT Cloud Solutions and Vendor Manager, you will be responsible for overseeing our cloud solutions, optimizing vendor partnerships, and ensuring seamless collaboration.Critical ResponsibilitiesEvaluate, select, and implement cloud solutions that align with our...


  • Johannesburg, Gauteng, South Africa NTT DATA Full time

    Job Overview Make a Difference with NTT DATAJoin a pioneering organization that is redefining possibilities. We are recognized for our technological expertise and innovative solutions, committed to making a positive impact on our clients and society. Our workplace fosters diversity and inclusion, providing an environment where you can develop, belong, and...


  • Johannesburg, Gauteng, South Africa E-Merge Full time

    Role OverviewE-Merge is currently seeking an experienced Cloud Solutions and Vendor Manager to play a critical role in our organization's digital transformation journey.Key ResponsibilitiesCloud Solutions Architecture: Evaluate, select, and implement cloud solutions that align with E-Merge's business goals.Vendor Management: Develop and maintain successful...


  • Johannesburg, Gauteng, South Africa NTT DATA Full time

    About the RoleNTT DATA is seeking a highly skilled and experienced Chief Information Security Officer to lead our information security program and drive the implementation of our security strategy. As a key member of our leadership team, you will be responsible for overseeing and leading our information security efforts to ensure the confidentiality,...


  • Johannesburg, Gauteng, South Africa NTT DATA Full time

    About the RoleNTT DATA is seeking a highly skilled and experienced Chief Information Security Officer to lead our information security program and drive the implementation of our security strategy. As a key member of our leadership team, you will be responsible for overseeing and leading our information security efforts to ensure the confidentiality,...


  • Johannesburg, Gauteng, South Africa Cochrane Global Full time

    Job Title: Security Active PatrolAt Cochrane Global, we are seeking a highly skilled and experienced Security Active Patrol to join our team. The successful candidate will be responsible for ensuring a strong security presence within the Site, managing all security-related matters, and maintaining a high level of visibility in the assigned areas of...


  • Johannesburg, Gauteng, South Africa Cochrane Global Full time

    About Cochrane GlobalWe are a leading security services provider, dedicated to delivering exceptional protection solutions to our clients.Job SummaryWe are seeking an experienced Security Threat Mitigator to join our team in Kempton Park, Woodmead and Sandton Area, Gauteng. The successful candidate will be responsible for ensuring a strong security presence...


  • Johannesburg, Gauteng, South Africa Cochrane Global Full time

    Job Title: Security Active PatrolJob Summary:Cochrane Global is seeking a skilled and experienced Security Active Patrol to join our team. The successful candidate will be responsible for ensuring a strong security presence within the site, managing security-related matters, and providing a positive and forceful image for our services.Key...


  • Johannesburg, Gauteng, South Africa NTT DATA Full time

    About the RoleOverviewNTT DATA is seeking a highly skilled and experienced Chief Information Security Officer to lead our information security programme(s). As a senior management role, this position plays a critical role in contributing towards the development of, as well as driving the implementation of NTT's security and governance strategy, frameworks,...


  • Johannesburg, Gauteng, South Africa Cochrane Global Full time

    Job Title: Security Active PatrolAt Cochrane Global, we are seeking a highly skilled and experienced Security Active Patrol to join our team. As a Security Active Patrol, you will be responsible for ensuring a strong security presence within the Site.Key Responsibilities:Adhere to the company's disciplinary 'Code of Conduct'.Project a positive and forceful...


  • Johannesburg, Gauteng, South Africa Cochrane Global Full time

    Job Title: Security Active PatrolAt Cochrane Global, we are seeking a skilled and experienced Security Active Patrol to join our team.Key Responsibilities:• Adhere to the company disciplinary 'Code of Conduct'.• Project a positive and forceful image for Cochrane Global services in the area of operation.• Be visible and proactive against security...


  • Johannesburg, Gauteng, South Africa E-Merge Full time

    Cloud Solutions and Vendor ManagerE-Merge is seeking a skilled Cloud Solutions and Vendor Manager to play a critical role in our digital transformation journey.As a key member of our IT team, you will be responsible for overseeing our cloud solutions, optimizing vendor partnerships, and ensuring seamless collaboration.Key Responsibilities:Oversee the...


  • Johannesburg, Gauteng, South Africa E-Merge Full time

    Are you looking to work for a leading financial institution in South Africa then this role is for you. Currently in search for a Cloud Solutions and Vendor Manager.As an IT Cloud Solutions and Vendor Manager, you will play a critical role in our organization\'s digital transformation journey. You\'ll be responsible for overseeing our cloud solutions,...


  • Johannesburg, Gauteng, South Africa NTT Full time

    About the RoleThe Principal Security Managed Services Engineer is a key technical leader responsible for designing, implementing, and managing highly complex security solutions for clients. This role acts as a consultant in the field, ensuring highly complex contracted Managed Services outcomes are delivered to the client.Key Responsibilities:Creates and...