Website BMO Harris Bank
At BMO, sustaining consumer confidence and trust by ensuring the security, privacy and integrity of our business information is a priority. To manage risk and respond to evolving regulatory requirements, we must carefully evaluate the cyber security controls that our service providers and suppliers have in place. As a leader on the Third Party Risk Cybersecurity team, you’ll play a critical role in maturing the function. You’ll collaborate with team members, senior management, and stakeholders across the company to drive process improvements and ensure consistency. You’ll be part of the Cybersecurity Third Party Risk team, composed of a large team of professionals that cover the entire third party life cycle. The team works closely with counterparts in Procurement, other risk functions, business leaders, and third parties. This is a fantastic opportunity to work with leaders across the bank, and work closely with cybersecurity colleagues to further champion and evangelize third party security. You will have a fundamental role in driving high-visibility improvements to the overall program.
- Work with software development teams to improve, replace, and/or further integrate GRC, monitoring, and other tooling in the TPRM stack.
- Stays abreast of industry, information security and business trends through benchmarking and/or participation in professional associations.
- Coach, mentor and review the assessments of junior third party assessors.
- Acts as the prime subject matter expert for internal/external stakeholders.
- Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
- Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
- Lead initiatives to evangelize third party security.
- Acts as a subject matter expert on relevant regulations and policies.
- Maintaining awareness of the current and emerging threats in the cybersecurity supply chain. Identify threats, model risk, and lead efforts to respond.
- Leads/oversees the management of vendor relationships and provides guidelines for execution; ensures that all agreements are met as per requirements.
- Lead and occasionally perform assessments of high risk third parties.
- Improve the assessment process by updating and strengthening how control assurance is obtained. Collaborate with other internal cybersecurity domains to ensure the third party assessment process aligns with the latest internal policies and standards.
- Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
- Provides strategic input into business decisions as a trusted advisor.
- Presents data and information to all levels within IT and to business units.
- Identifies and recommends opportunities to create/contribute to the tactical and strategic vision of the organization.
- Improve continuous monitoring practices and further integrate OSINT into the program.
- Build relationships and consensus with internal and external stakeholders. Work with stakeholders to understand problems and opportunities, and negotiate outcomes.
- Hands-on experience with information security or technology, for example, through work experiences or training. For example, prefer someone that has actually logged into the AWS Admin Console rather than just watched a video about.
- Demonstrates in depth knowledge of information security concepts, methodology, processes, procedures and controls.
- Verbal & written communication skills – In-depth / Expert.
- Multiple information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).Possesses an expert level of knowledge of information security processes, procedures and controls.
- Min of 5 – 10 years of deep experience in 3rd Party Risk Assessment and governance, likely with substantial experience with using standards like NIST, ISO, and CIS to perform audits. Alternatively, a history of diverse experience across many information security roles could be a replacement for significant risk assessment experience.
- Must have significant history in risk assessment and third party Cyber Risk management.
- Knowledge of business analysis, project delivery practices and standards across the project lifecycle – In-depth/Expert.
- Analytical and problem solving skills – In-depth / Expert.
- Influence skills – In-depth / Expert.
- Mandatory hands-on experience with Cloud risk assessments ( MUST HAVE experience with AWS Admin Console or other Cloud services like Azure or Google Cloud)
- Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or
- Information Systems or a related field of study or an equivalent combination of education and experience.
- Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002 – In-depth/Expert.
- Passion for information security. Should enjoy reading about it in their free time, and would be excited to bring ideas into the office about security.
- Very strong PowerPoint skills
Company: BMO Harris Bank
Vacancy Type: Full Time
Job Location: Indianapolis, IN, US
Application Deadline: N/A