Jobs and Careers
CA

Third Party Risk Senior Business Analyst

Capco
Belgiumfull_timeVerifiedPosted 4 Jun 2023

About the role

<p><u>WHAT MAKES US DIFFERENT?</u></p> <p>We are a global technology and management consultancy dedicated to the financial <br/>services industry. Our professionals combine innovative thinking with unrivalled industry knowledge to offer our clients consulting expertise, complex technology and package integration, transformation delivery, and managed services, to move their organizations forward.</p> <p><u>WHY WORK FOR CAPCO?</u></p> <p>When you join Capco, you will work on engaging projects with some of the largest banks in the world, projects that will transform the financial services industry. We offer you opportunities for ongoing learning, a culture that’s a true meritocracy and the freedom to be your authentic self at work.</p> <p>As we grow, you will grow, and you can add value and make an impact right away.</p> <p>» A work culture focused on innovation and creating lasting value for our clients.<br/>» Ongoing learning opportunities to help you acquire new skills or broaden and deepen existing expertise.<br/>» Our Capco Schools and leadership development programs are the heart of our global learning experience.<br/>» A flat, non-hierarchical structure that will enable you to work on projects with senior partners and directly with clients.<br/>» Potential opportunities to work in other locations and practice areas.<br/>» An environment where work, leisure, social and professional life are in balance. <br/>» A diverse, inclusive, meritocratic and international culture.</p> <p><u>LET’S GET DOWN TO BUSINESS</u></p> <p>The key role as <strong><u>Third Party Risk Senior Business Analyst</u></strong> is to deliver specific high added value in outsourcing and third party risk management in the financial services industry (banking, market infrastructure, asset management, insurance).</p> <p>The overall role is focused on the design and delivery of complex outsourcing and third party risk management framework and remediation plans.</p> <p>More specifically, the job consists in:</p> <ul> <li>Support the design and implementation of third-party risk operating models, identifying, evaluating, and providing solutions to evaluate complex ICT risks</li> <li>Design policies and procedures that support the successful implementation of TPRM operating models</li> <li>Design technology enhancement requirements to support third-party risk management processes</li> <li>Conduct Third-Party Security Risk Assessment Services</li> <li>Perform cyber risk assessments, incl. review of contracts, SLAs, SOPs, BCM, DRP, exit plans, policies, and materiality levels (substitutability included)</li> <li>Calculate risk score based on: evidence review/ discussion outcomes /additional scores if applicable</li> <li>Agree on the risk mitigation plans with vendors and confirm due dates for remediation closure</li> <li>Follow up on open risks with vendor to confirm completion of mitigation tasks, gather required evidences and perform closure of risks</li> <li>Provide reporting on a regular basis on key risks, mitigation, progress and vendors’ conformance to client’s security policies</li> <li>Assist in the selection and tailoring of approaches, methods and tools to support third party risk management service offering</li> <li>Lead the design, implementation, maintenance, and enforcement of third-party security risk management policies, procedures, and controls</li> <li>Identify key program level metrics, e.g. key performance indicators (KPI) and key risk indicators (KRI) to measure the effectiveness of the program and measure the risk inherited by the organization</li> <li>Partner with other stakeholders (Enterprise Risk Management, Procurement, Information Security, Legal) to effectively coordinate the execution of third-party controls and identify technology integration opportunities and lead proof of concept engagements</li> </ul> <p><u>SHOW US WHAT YOU’VE GOT</u></p> <p><u>Definitely show us:</u></p> <ul> <li>Strong experience of minimum 5 years in all fields of ICT Risks in general and in third party risk management in particular.</li> <li>Demonstrated expertise within the domain of ICT Risk management or Non-Financial Risk (NFR).</li> <li>Being able to work and liaise with various stakeholders, ranging from technical to non-technical.</li> <li>Excellent analytical, reporting and presentation skills.</li> <li>Exceptional interpersonal, team building, mentoring, and leadership skills with a demonstrated ability to gain the confidence and respect of senior level executives.</li> <li>Strong understanding of ICT risk management, integration with enterprise risk management, and the integration with business strategy.</li> <li>Understanding of leading third party risk management platforms and tools including but not limited to ServiceNow, Archer, OneTrust, MetricStream, etc., will be an added advantage.</li> <li>Fluency in Dutch and/or French as well as in English.</li> </ul> <p><u>Good to show us:</u></p> <ul> <li>Knowledge of, experience with

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Capco

View company profile →