Technology Risk Analyst – Third-Party Risk _ Contract

NTT SINGAPORE PTE. LTD.

Date: 2 weeks ago
City: Singapore, Singapore
Salary: SGD 6,500 - SGD 10,000 / mo
Contract type: Contractor

Technology Risk Analyst – Third-Party Risk

We are seeking an experienced Technology Risk Analyst to support the security review and assessment of third-party service providers and outsourcing arrangements for a leading financial institution.

This is a

06 -month contract position based in Changi,

with employment through NTT Singapore.

Key Responsibilities

  • Conduct due diligence and technology-risk assessments of third-party service providers and outsourcing arrangements.
  • Assess information security, cybersecurity, cloud, technology, operational and compliance risks.
  • Review vendor questionnaires, policies, certifications, audit reports and supporting control evidence.
  • Evaluate the design and effectiveness of security and technology controls.
  • Identify control gaps, risk exposures and areas of non-compliance.
  • Document assessment findings, risk ratings and practical remediation recommendations.
  • Engage vendors, business stakeholders, technology teams and control owners to clarify findings and obtain evidence.
  • Track identified risks, remediation actions and outstanding documentation through closure.
  • Prepare clear assessment reports and management updates.
  • Support compliance with internal policies, control frameworks and applicable MAS regulatory expectations.

Requirements

  • Diploma or degree in Information Technology, Cybersecurity, Information Systems, Risk Management or a related discipline.
  • Relevant experience in third-party risk management, vendor due diligence, technology risk, cybersecurity risk, IT audit or information security reviews.
  • Experience reviewing technology controls, supporting evidence and audit documentation.
  • Knowledge of IT general controls, access management, change management, vulnerability management, incident management and business continuity.
  • Familiarity with cloud security, outsourcing risk and technology-risk controls.
  • Understanding of recognised frameworks such as ISO 27001, NIST, COBIT, SOC 1 or SOC 2.
  • Familiarity with MAS technology-risk and outsourcing expectations would be advantageous.
  • Strong analytical, documentation, report-writing and stakeholder-management skills.
  • Ability to work independently and manage multiple assessments within agreed timelines.
  • Professional certifications such as CISA, CISSP, CRISC, CISM or ISO 27001 would be advantageous.

Interested candidates are kindly requested to email their CV with their experience to

We look forward to your application!

For employers only

Is this your company's job post? Verify ownership to manage this listing and receive applications directly.

Claim this listing

Looking to apply for this job? Use the Apply button above.