*10 openings for Security Consultants!  In MN ! for 1 year contract.*


 *Kindly reply to [email protected] <[email protected]>*



Minneapolis, MN for a 12 month contract

We are looking for a Secruity Consultant that has done risk assessments and
done a lot of security work and probably has their CISSP or their CISA.


 *What is the specific title of the position? *

IT Security Consultant - Supplier / Vendor Risk Assessment


 *What are the top 5-10 responsibilities for this position? (Please be
detailed as to what the candidate is expected to do or complete on a daily
basis) *

• Conduct and manage vendor risk assessments and due-diligence reviews

• Ensure vendor compliance to the business agreement, policies, procedures,
& regulations along with ability to map controls and compliance
requirements

• Review vendor supplied policies & procedures, internal/external
assessment reports, agreements and provide feedback

• Provision assessment reports and executive summaries with recommendations
& direction regarding remediation efforts and disposition of the third
party

• Communicate, escalate, and track vendor progress on assessment
remediation activities

• Act as a liaison & SME for internal departments & vendors to successfully
manage Vendor Risk Assessment

• Understand information security risks that are inherent to a business and
articulate those risks in business terms

• Maintain current knowledge on information security topics and their
applicability program requirements

• Engage VRO regarding any delays/deviations during remediation



*What skills/attributes are a must have? *

• Experience working with senior levels of management

• Good follow-up skills and detail oriented

• Security expertise including knowledge on different security risk
assessment frameworks (NIST/Octave), standards
(ISO27001/HITRUST/ITIL/Cobit), and act such as (HIPAA/GLBA).

• Experience in examining the SSAE 16 Audit report

• Knowledge and understanding of different security products (web/email
filtering, disk encryption, IDS/IPS, antivirus, DLP, firewall etc.)

• Knowledge of software development methodologies, application security,
and OWASP guidelines

• Ability to document assessment work papers and preparing assessment
report

• Ability to manage vendor assessment independently with minimal
supervision


 Regards,
*Sara Wilson* - Staffing Manager
Direct : 646-340-0603
[email protected]

-- 
You received this message because you are subscribed to the Google Groups "Open 
Source J2EE frameworks" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to 
[email protected].
Visit this group at http://groups.google.com/group/open-source-j2ee-frameworks.
For more options, visit https://groups.google.com/d/optout.

Reply via email to