*10 openings for Security Consultants!  In MN ! for 1 year contract.*


 *Kindly reply to [email protected] <[email protected]>*



Minneapolis, MN for a 12 month contract

We are looking for a Secruity Consultant that has done risk assessments and
done a lot of security work and probably has their CISSP or their CISA.


 *What is the specific title of the position? *

IT Security Consultant - Supplier / Vendor Risk Assessment


 *What are the top 5-10 responsibilities for this position? (Please be
detailed as to what the candidate is expected to do or complete on a daily
basis) *

• Conduct and manage vendor risk assessments and due-diligence reviews

• Ensure vendor compliance to the business agreement, policies, procedures,
& regulations along with ability to map controls and compliance
requirements

• Review vendor supplied policies & procedures, internal/external
assessment reports, agreements and provide feedback

• Provision assessment reports and executive summaries with recommendations
& direction regarding remediation efforts and disposition of the third
party

• Communicate, escalate, and track vendor progress on assessment
remediation activities

• Act as a liaison & SME for internal departments & vendors to successfully
manage Vendor Risk Assessment

• Understand information security risks that are inherent to a business and
articulate those risks in business terms

• Maintain current knowledge on information security topics and their
applicability program requirements

• Engage VRO regarding any delays/deviations during remediation



*What skills/attributes are a must have? *

• Experience working with senior levels of management

• Good follow-up skills and detail oriented

• Security expertise including knowledge on different security risk
assessment frameworks (NIST/Octave), standards
(ISO27001/HITRUST/ITIL/Cobit), and act such as (HIPAA/GLBA).

• Experience in examining the SSAE 16 Audit report

• Knowledge and understanding of different security products (web/email
filtering, disk encryption, IDS/IPS, antivirus, DLP, firewall etc.)

• Knowledge of software development methodologies, application security,
and OWASP guidelines

• Ability to document assessment work papers and preparing assessment
report

• Ability to manage vendor assessment independently with minimal
supervision


 Regards,
*Sara Wilson* - Staffing Manager
Direct : 646-340-0603
[email protected]

-- 
You received this message because you are subscribed to the Google Groups "GTA 
DBA" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at http://groups.google.com/group/gtadba.
For more options, visit https://groups.google.com/d/optout.

Reply via email to