सभी पद

थर्ड-पार्टी और सप्लाई-चेन रिस्क एनालिस्ट

Third-Party and Supply-Chain Risk Analyst

उन सप्लायरों और सॉफ़्टवेयर कंपोनेंट्स की सुरक्षा का आकलन कीजिए जिन पर क्लाइंट निर्भर हैं। आप वेंडर आकलन करेंगे, साइबर रेज़िलिएंस एक्ट के दायित्वों पर नज़र रखेंगे और सप्लायर रिस्क रजिस्टर अद्यतन रखेंगे।

अभी आवेदन करेंलगभग 3 मिनट लगेंगे

पूरा विवरण अंग्रेज़ी में है। आप अपनी भाषा में आवेदन कर सकते हैं।

About the role

Most organisations now rely on hundreds of suppliers, and regulation increasingly holds them responsible for the security of that chain. NIS2, DORA and the Cyber Resilience Act all ask for evidence. This role builds and runs supplier risk programmes for our clients. You design questionnaires and tiering models, review supplier evidence and contracts, and follow up on remediation. You work remotely within the EU with our Munich governance team, client procurement and legal staff, and product security colleagues.

What you will do

  • Design supplier tiering, assessment questionnaires and evidence requirements for client programmes
  • Review supplier certifications, audit reports and security documentation and record findings
  • Advise on security clauses, notification duties and exit terms in supplier contracts
  • Track Cyber Resilience Act obligations for manufacturers and importers among the client's suppliers
  • Maintain risk registers and report supplier risk trends to client management

What you bring

  • 3+ years in third-party risk, procurement risk, IT audit or security compliance
  • Working knowledge of ISO 27001, SOC 2 reports and common assurance schemes
  • Familiarity with NIS2 and DORA supply-chain requirements and the Cyber Resilience Act
  • Organised, persistent follow-up across many stakeholders
  • Reliable home workspace within the EU and occasional travel to Munich

Good to have

  • Experience with TPRM platforms such as OneTrust, Archer or Prevalent
  • Understanding of software bills of materials (SBOM)

Languages

English (C1), German (B1) an advantage

Skills

  • Third-party risk
  • Cyber Resilience Act
  • Vendor assessment
  • SOC 2
  • Contract review
  • SBOM
  • Risk registers

यह पेज AI की मदद से अनुवादित किया गया है। कोई बात स्पष्ट न हो, तो अंग्रेज़ी संस्करण मान्य होगा।