Aller directement au contenu

Informations générales

Ref #
1000003824
Pays
Inde
Région
Karnataka
Ville
Bangalore
Type de contrat
CDI
Famille de métiers
F06 - INFORMATIQUE

Description

Job Description – Third Party Technology Risk Management Analyst/ Consultant

 

About BNP Paribas Group:

BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialised businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability

 

About BNP Paribas India Solutions:

Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.

 


Commitment to Diversity and Inclusion

At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.




About Business line/Function:

ITTF IRM is a unique community of Transversal, Finance and RISK Projects & Systems along with their related IT teams. ITTF comes under ITG.

 

 

 

 

 

Job Title:

Third Party Technology Risk Management Analyst/ Consultant

Date:

 

 

Department:


Location:

Bangalore

Business Line / Function:

ITG

Reports to:

(Direct)

 NA

Grade: 

(if applicable)

 

(Functional)

 

Number of Direct Reports:

 

Directorship / Registration:

NA

 

Position Purpose

·       The BNP Paribas Fortis Governance, Risk and Compliance team supports IT and Business Units to develop adequate solutions on operational IT and Cyber risk management practices, with specific focus on Information Security. 

·       Their main missions are:

·       Identify operational IT and Cyber risks on assets/applications, projects and 3rd-parties.

·       Advice, consult, monitor and report on risk treatment in order to reduce the overall risk exposure of IT and Business at an optimized cost.

·       Elaborate and manage the implementation of a flexible strategy to reduce IT and Cyber risks in accordance with the IT and Information Security policies of BNP Paribas Group.

Responsibilities

 

Direct Responsibilities

 

·       Instruct the 5 European Bank Authority ICT risks categories and to follow them throughout TPTRM assessments

·       Perform third-party technology risk assessments to help beneficiaries/contract owners identify and evaluate complex business and technology risks related to their third parties, and provide recommendations for managing those risks

·       Provide periodic status updates including potential risks and delays to the project delivery to beneficiary project manager, conduct workshops wherever necessary

·       contribution to the definition and review of contractual clauses. Work with Procurement team in adding or amending any IT related clause in the contract

·       Assist in the selection and tailoring of third-party technology risk management approaches, methods and tools to support delivery of third-party cyber risk assessment services

·       Review thoroughly Asset classifications and pre-existing asset related risks & control responses ensuring sync with TPTRM assessments responses

·       Identify key actors for decision making according to flagged risk families

·       Apply group key procedures, templates, to carry out risk’s activities

·       Demonstrate knowledge in one or more of the following cyber risk domains, including: Security Governance and Management, Security Policies and Procedures, Application Security Controls, Access Controls, Network Security Operations, Security Architectures, Identity Management, Disaster Recovery & Business Continuity, Incident Response, Risk Management, Privacy and Data Protection, Encryption.

 

 

Contributing Responsibilities

 

·       As part of its defined missions, the TPTRM Analyst/Consultant is responsible for executing - or supporting the execution of TPTRM Assessments involving - IT operational risks identification, assessment, documentation, treatment, monitoring and closing

·       Document TPTRM risks, assess inherent and residual risks in the activity

·       Analyze the root cause and the business impact

·       Work towards strong mitigation plan and the execution of the same

·       Provide support to beneficiary/contract owner to implement actions to reduce the residual risk

·       Report to P&P/ Project Manager about key TPTRM risks information, warning, or alert

·       Contribute to various exercises and reviews on controlling and assessing TPTRM risks

·       As a TPTRM Analyst/ Consultant review if all the mandatory prior-assessments are properly completed if not take necessary actions towards compliance

·       Define and document a methodology, use group’s tool to manage and document assessments and outcomes

·       Facilitate the business/sponsor/beneficiary/SME decision-making with deep analysis based on relevant flagged risk families

·       Provide support to provider teams/ contract owners and coordinate/ assist to ensure proper assessments are done

·       Manage TPTRM inventory with follow-up tracker management

·       Monitor the process with specific and group standard indicators to steer the activity

·       As an IRM team member this includes all or part of the following activities:

·       Execute as Second Line of Defense: Oversight of risk management and compliance, providing support and guidelines to operational teams.

·       Contribute to process improvement, upkeep with new policies, regulations, standards & guidelines

·       Contribute to IRM IT risk awareness actions

Technical & Behavioral Competencies

Functional Skills 

· Experience in IT Risk and Cyber Security domains in a financial institution demonstrating a high-level of commitment and self-motivation.

· Experience in the Finance & IT industry with a strong exposure to IT Operations, Application Security, and/or network administration, IPS

· Strong demonstrated knowledge of Risk & Compliance, cybersecurity, cyber risk, cyber threats, Third Party Technology Risk Management/ Vendor assessments

· Risk knowledge and awareness of risks combined with enthusiasm and a genuine interest in the role of Risk Assessment, Third Party Technology Risk Assessment, Risk Analysis in business and providing Risk Opinion as a subject matter expert. 

· Working knowledge of global regulations, frameworks and standards(ISO, NIST, COBIT, PCI-DSS, HIPAA) and conversant in the tactics, techniques and procedures used by Risk adversaries. 

· Demonstrates a calm professional approach, with a good understanding of delivery within time constraints and the need to escalate/inform departmental management as appropriate. 

· IT knowledge

Technical :

 

-          Good understanding of organizations and IT Businesses

-          Good technical understanding of infrastructures and IT Security Productions and Systems

-          Experience in vulnerability management and penetration testing

-           

-          IT risk /Third Party risk analysis and management methods and should have worked on Risk Management Tools like RSA Archer, Metric stream, ServiceNow etc

-          Knowledge of Cyber Resilience, IT continuity and business continuity

-          GRC - Governance, Risk Management and Compliance Management.

-          Firewall and Internet technologies; Cloud Security, Banking Tools & Technologies.

-          Secure access control mechanisms; Encryption and Key management technics

Behavioral :

-          Strong Communication, Analytical and problem-solving skills.

-          Proven organizational skills with excellent multi-tasking, result oriented and prioritization skills

-          Good documentation and reporting skills

-          Ability to work independently

-          Strong communication and interpersonal skills, able to communicate and relate easily with IT, Finance and back-office users

-          Good communication, technical writing/diagramming skills

-          Attention to detail and accuracy

-          Ability for creativity and innovation

-          Self-discipline

Specific Qualifications (if required)

-          One or more Industry-recognized information Security certifications such as CISSP, CISA, GCCC, CISM, CEH, CRISC, OSCP or Security+.

-          IT Security tools like Firewalls, IPS, WAF, Endpoint protection, Network security, etc. 

-          IT Auditing (ISO27001/2, NIST 800 Series, ISO27005, ISO42001)

-          Regulatory Compliance

-          MBA in Finance/Systems/IT, Master’s in Technology, Bachelor of Commerce, Master’s in Commerce, Bachelor in Science, Bachelor in Technology

 

Skills Referential

 

 

Behavioural Skills: (Please select up to 4 skills)

 

 

Communication skills - oral & written

 

 

Attention to detail / rigor

 

 

Ability to deliver / Results driven

 

 

Creativity & Innovation / Problem solving

 

 

Transversal Skills: (Please select up to 5 skills)

 

 

 

Analytical Ability

 

 

Ability to manage a project

 

 

Ability to understand, explain and support change

 

 

Ability to develop and adapt a process 

 

 

Ability to anticipate business / strategic evolution

 

 

Education Level: 

 Bachelor Degree or equivalent

 

 

Experience Level

At least 5 years

 

 

Other/Specific Qualifications (if required)- CISA/CISSP/CISM/CRISC