Third-Party Cyber Security Risk Analyst

5 days ago


Islamabad, Islamabad, Pakistan PMCL-JAZZ Full time
Job Title: Third-Party Cyber Security Risk Analyst

PMCL-JAZZ is seeking a highly skilled and experienced professional to join its team as a Third-Party Cyber Security Risk Analyst. The successful candidate will be responsible for assessing and monitoring the cybersecurity risks posed by third-party vendors or suppliers, ensuring they comply with regulatory frameworks and international standards.

The role requires building a robust third-party/supplier risk management framework, managing supplier-related incidents, ensuring continuous oversight of supplier security posture, and leveraging supplier monitoring tools to evaluate and monitor supplier risks.

This position plays a crucial role in reducing the cyber risk posed by suppliers and protecting PMCL-JAZZ against possible attacks via backdoors created by partners or suppliers.

Key Responsibilities:
  1. Develop and Implement TPRM/SRM Framework: Design and implement a Third-party/Supplier Risk Management (TPRM/SRM) framework aligned with industry standards and organizational requirements.
  2. Conduct Security Risk Assessments: Perform security risk assessments of suppliers and partners during onboarding and periodically.
  3. Evaluate SOC 2 Reports: Evaluate SOC 2 reports, security certifications, and compliance evidence provided by the partners/suppliers.
  4. Maintain Risk Register: Maintain a risk register for all third-party vendors or suppliers and update it regularly with risk assessment findings.
  5. Collaborate with Stakeholders: Collaborate with internal stakeholders to manage supplier risks effectively.
  6. Implement Security Controls: Act as a liaison between internal teams and suppliers to ensure the implementation of robust security controls.
  7. Incorporate Cybersecurity Clauses: Collaborate with relevant stakeholders to include cybersecurity clauses in supplier contracts.
  8. Analyse Technical Vulnerabilities: Analyse technical vulnerabilities in suppliers' systems and applications to assess potential risks.
  9. Ensure Compliance: Ensure suppliers comply with applicable cybersecurity policies, procedures, and frameworks such as ISO 27001, NIST CSF, PCI DSS, etc.
Requirements:
  • Education: Bachelor's or Master's degree in Information Security, Information Technology, Computer Science, or related field.
  • Experience: 1-3 years of proven experience in third-party or supplier risk management, cybersecurity assessments, cybersecurity consulting, cybersecurity GRC, or related area.
  • Cybersecurity Knowledge: Strong understanding of cybersecurity frameworks like ISO 27001, NIST CSF, PCI DSS, SOC 2, etc.
  • Vendor Risk Management Tools: Strong understanding and knowledge of vendor or supplier risk management tools and methodologies.
  • Technical Skills: Strong technical skills and knowledge to understand and evaluate technical vulnerabilities in suppliers' systems/applications.
  • Certifications: Relevant certifications such as ISC2 CC, ISO 27001 Lead Auditor/Implementer preferred.


  • Islamabad, Islamabad, Pakistan PMCL-JAZZ Full time

    Job Overview:At PMCL-JAZZ, we are committed to maintaining a secure and compliant environment. As a Third-Party Cyber Security Risk Analyst, you will play a vital role in ensuring that our organization meets regulatory requirements and international standards.Your responsibilities will include developing and implementing a robust Third-party/Supplier Risk...


  • Islamabad, Islamabad, Pakistan PMCL-JAZZ Full time

    Job Description:As a Third-Party Cyber Security Risk Analyst at PMCL-JAZZ, you will play a critical role in identifying and mitigating cybersecurity risks associated with third-party vendors or suppliers. Your expertise will help ensure that our organization complies with regulatory frameworks and international standards, safeguarding our data and...


  • Islamabad, Islamabad, Pakistan PMCL-JAZZ Full time

    About the Role:We are seeking a seasoned Third-Party Cyber Security Risk Analyst to join our team at PMCL-JAZZ. As a key member of our risk management team, you will be responsible for assessing and mitigating cybersecurity risks associated with third-party vendors or suppliers.Your primary objectives will be to develop and implement a robust...


  • Islamabad, Islamabad, Pakistan HR Manager Full time

    Job DescriptionAbout the Role:We are seeking a highly skilled Cyber Security Expert to join our team. As an entry-level position, this role requires minimal experience but offers opportunities for growth and development.Main Responsibilities:Cyber Incident Response: Responding to complex security incidents and developing strategies to mitigate risks.Cyber...


  • Islamabad, Islamabad, Pakistan PMCL-JAZZ Full time

    Cyber Security DirectorWe are seeking a highly skilled and experienced Cyber Security Director to lead and manage the cyber security initiatives within the enterprise business unit.The ideal candidate will be responsible for developing and implementing comprehensive cybersecurity strategies, managing audit processes, and ensuring compliance with industry...


  • Islamabad, Islamabad, Pakistan Job Portal - dinCloud Pakistan Full time

    Cyber Security Role OverviewThis critical role involves protecting AT&T, our customers, and our vendors/partners from cyber security threats across products, services, infrastructure, networks, and/or applications.Key responsibilities include:Analysis of complex security issues to develop mitigation strategies and minimize risk.Recommendation of hardware and...


  • Islamabad, Islamabad, Pakistan Job Portal - dinCloud Pakistan Full time

    Cyber Security RoleProtecting our customers and partners from cyber security threats across products, services, infrastructure, networks, and/or applications is a crucial task for this role.Key Responsibilities:Conducting in-depth analysis of complex security issues to develop mitigation strategies and minimize risk.Providing expert recommendations on...


  • Islamabad, Islamabad, Pakistan Job Portal - dinCloud Pakistan Full time

    Cyber Security ExpertProtect AT&T, its customers, and partners from cyber threats across various products, services, infrastructure, networks, and applications.This role requires a technical professional with strong analytical and problem-solving skills to work in a fast-paced environment and adapt to changing priorities.The ideal candidate will have...


  • Islamabad, Islamabad, Pakistan Job Portal - dinCloud Pakistan Full time

    Job Title: Cyber Security ExpertThis role requires individuals with limited-level experience to safeguard our customers and partners from cyber security threats across various platforms.Key Responsibilities:Complex security issue analysis and mitigation strategy development to minimize risk.Hardware and software solution recommendations to enhance cyber...


  • Islamabad, Islamabad, Pakistan Job Portal - dinCloud Pakistan Full time

    Cyber Security RoleJob Summary:This position is responsible for protecting our network, customers, and partners from cyber threats across products, services, infrastructure, networks, and applications.Key Responsibilities:Develop mitigation strategies to minimize risk associated with complex security issues.Recommend hardware and software solutions to...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    About the Position:NADRA Technologies Ltd is looking for a skilled Cyber Security and Governance Lead to join our team.In this role, you will be responsible for leading the development and implementation of our cyber security and governance initiatives.Key Responsibilities:Cyber Security: Develop and implement strategies to enhance the organization's cyber...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    About the Role:The Government of Pakistan, through NADRA Technologies Ltd, is seeking a highly qualified Digital Cyber Security Specialist to support its Digital Economy Enhancement Project. The ideal candidate will have strong skills in legal research and interpretation, experience in framing and amending rules and regulations, and a Master's degree in Laws...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    Job SummaryNADRA Technologies Ltd is looking for an experienced Assistant Director (Cyber Security Compliance Officer) to lead our cybersecurity efforts. The successful candidate will have a strong background in information security, with a minimum 3 years of experience in relevant fields.Key Accountabilities:Develop and maintain information security...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    The Senior Security Analyst - SOC position at NADRA Technologies Ltd requires a highly skilled cybersecurity professional to join its team.The ideal candidate will have a strong background in information security, experience with SIEM tools, and excellent analytical skills to identify and mitigate security threats.Key ResponsibilitiesLead the SOC team in...

  • Cyber Security

    5 days ago


    Islamabad, Islamabad, Pakistan PMCL-JAZZ Full time

    Chief Information Security OfficerWe are looking for a seasoned Cyber Security & Audits Manager to oversee the development and implementation of comprehensive cybersecurity strategies, driving the organization's information security agenda.Main Responsibilities:Information Security Strategy:Establish and enforce effective information security policies,...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    Job Overview:NADRA Technologies Ltd seeks a skilled Cyber Security Legal Expert to provide professional expertise on a project basis. The successful candidate will have a minimum of 5 years of experience in cyber security, with at least 3 years as a cyber security expert/advisor for international projects.Key Responsibilities:Provide expert advice on cyber...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    We are seeking a highly skilled Cyber Security Officer to join our team at NADRA Technologies Ltd. This is a key role in the organization, responsible for protecting our digital assets from cyber threats.The successful candidate will have a minimum of 3 years' experience in a similar role, with a strong understanding of different security frameworks, such as...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    Job RoleNADRA Technologies Ltd invites applications for the position of Assistant Director (Cyber Security Compliance Officer). The ideal candidate will have a strong background in information security, with a minimum 3 years of experience in relevant fields.Responsibilities:Implement security policies, procedures, and guidelines to ensure compliance with...


  • Islamabad, Islamabad, Pakistan aiblux Full time

    The IT Security Risk Manager at aiblux is responsible for identifying and mitigating potential security risks to the company's information systems. This includes monitoring IT infrastructure, identifying vulnerabilities, and implementing corrective measures.Key Responsibilities:Monitoring IT infrastructure for potential threatsIdentifying vulnerabilities and...

  • Cyber Security Specialist

    40 minutes ago


    Islamabad, Islamabad, Pakistan Job Portal - dinCloud Pakistan Full time

    Job Portal - dinCloud Pakistan seeks a skilled Cyber Security Expert to join our team. The ideal candidate will possess strong analytical and problem-solving skills, with a solid understanding of cyber security concepts and principles.The successful candidate will be responsible for developing and maintaining the IC website, including creating an operational...