LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Join Canary Wharfian
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Third Party Technology Risk Management Analyst/ Consultant

ExperiencedNo visa sponsorship
BNP Paribas logo

at BNP Paribas

Investment Banking

Posted 6 days ago

No clicks

**Third Party Technology Risk Management Analyst/Consultant** (Bangalore, India) - **Key Role**: Identify, assess, and mitigate risks introduced by third-party vendors, suppliers, and partners (TPTs) for BNP Paribas Cardif. - **Responsibilities**: - Instruct EBA ICT risk categories, perform TPT risk assessments, advise on risk treatments, review asset classifications, and monitor TPTs. - Manage risk inventory, coordinate with providers, and contribute to contract negotiations. - Advise beneficiaries/project managers and support SME decision-making. - **Required Skills & Experience**: - Proven IT risk and cybersecurity experience in finance. - Strong knowledge of risk & compliance, cyber threats, and IT operations (IT gov/ops, Apps Sec, network admin). - Industry-recognized certifications (CISSP, CISA, etc.) and global risk/regulatory frameworks. - Proficient in tools like RSA Archer, Metricstream, ServiceNow. - **Education & Location**: Bachelor's degree or equivalent, with at least 5 years of experience. Located in Bangalore. Regression SEO keywords: Third Party Technology Risk Management Analyst Consultant, TPT Risk Assessment, IT Risk Management, Cybersecurity, Vendor Management, IT Operations, IT Governance, Risk Compliance, EBA ICT Risks, TPT Risk Treatment, Security Annex, Contract Negotiation, IT Outsourcing Risks, IT Security, IT Change Management, IT Data Integrity, IT Availability & Continuity, TPT Risk Inventory, TPT Risk Monitoring, Secure Access Controls, Encryption, Cloud Security, Banking Tools.

Compensation
Not specified

Currency: Not specified

City
Bangalore
Country
India

Full Job Description

Job Title: Third Party Technology Risk Management Analyst/ Consultant

Department: Cardif France

About Business line/Function: TG-CDF / TPTRM is an unique community to identify, assess, and mitigate the vulnerabilities and exposures introduced by external vendors, suppliers, and partners.

Position Purpose: The BNP Paribas Cardif Governance, Risk and Compliance team supports IT and Business Units to develop adequate solutions on operational IT and Cyber risk management practices, 

with specific focus on Information Security. 

Their main missions are:  

Identify operational IT and Cyber risks on assets/applications, projects and 3rd-parties.  

Advice, consult, monitor and report on risk treatment in order to reduce the overall risk exposure of IT and Business at an optimized cost.  

Elaborate and manage the implementation of a flexible strategy to reduce IT and Cyber risks in accordance with the IT and Information Security policies of BNP Paribas Group.  

Responsibilities

Direct Responsibilities

         Instruct the 5 European Bank Authority (EBA) ICT risks categories including ICT availability and continuity, ICT security, ICT change, ICT data integrity, and ICT outsourcing risks and to follow them throughout TPTRM assessments

         Perform third-party technology risk assessments to help beneficiaries/contract owners identify and evaluate complex business and technology risks related to their third parties, and provide recommendations for managing those risks 

         Provide periodic status updates including potential risks and delays to the project delivery to beneficiary project manager, conduct workshops wherever necessary.

         Assist in the selection and tailoring of third-party technology risk management approaches, methods and tools to support delivery of third-party cyber risk assessment services.

         Review thoroughly Asset classifications and pre-existing asset related risks & control responses ensuring sync with TPTRM assessments responses; build the Security Annex that allows proper monitoring of the provider in the contract, and if needed contribute to the negotiation.

         Identify key actors for decision making according to flagged risk families 

         Apply group key procedures, templates, to carry out risks activities 

         Ensure to highlight key factors using Risk Assessment Form that will help SMEs in decision making 

         Demonstrate knowledge in one or more of the following cyber risk domains, including: Security Governance and Management, Security Policies and Procedures, Application Security Controls, Access Controls, Network Security Operations, Security Architectures, Identity Management, Disaster Recovery & Business Continuity, Incident Response, Risk Management, Privacy and Data Protection, Encryption and Inventories/data quality management.

Contributing Responsibilities

         As part of its defined missions, the TPTRM Analyst/Consultant is responsible for executing - or supporting the execution of TPTRM Assessments involving - IT operational risks identification, assessment, documentation, treatment, monitoring and closing.

         Document TPTRM risks, assess inherent and residual risks in the activity 

         Analyze the root cause and the business impact 

         Work towards mitigation plan and risk acceptance 

         Provide support to beneficiary/contract owner to implement residual actions 

         Report to P&P/ ITRO/ Project Manager about key TPTRM risks information, warning, or alert 

         Contribute to various exercises and reviews on controlling and assessing TPTRM risks 

         As a TPTRM Analyst/ Consultant review if all the mandatory prior assessments are properly completed if not take necessary actions towards compliance 

         Define and document a methodology, use groups tool to manage and document assessments and outcomes

         Facilitate the business/sponsor/beneficiary/SME decision-making with deep analysis based on relevant flagged risk families

         Provide support to provider teams/ contract owners and coordinate/ assist to ensure proper assessments are made.

         Manage TPTRM inventory with follow-up tracker management and contribute if needed to the negotiation of the requirement mandatory or non-mandatory in the security annex of the contract

         Monitor the process with specific and group standard indicators to steer the activity 

         As an IRM team member this includes all or part of the following activities: 

o    Execute as First Line of Defense: Oversight of risk management and compliance, providing support and guidelines to operational teams. 

o    Contribute to process improvement, upkeep with new policies, regulations, standards & guidelines 

o    Contribute to IRM IT risk awareness actions

Technical & Behavioral Competencies

Functional Skills  

         Experience in IT Risk and Cyber Security domains in a financial institution demonstrating a high level of commitment and self-motivation. 

         Experience in the Finance & IT industry with a strong exposure to IT Operations, Application Security, and/or network administration, IPS 

         Strong demonstrated knowledge of Risk & Compliance, cybersecurity, cyber risk, cyber threats, Third Party Technology Risk Management/ Vendor assessments 

         Risk knowledge and awareness of risks combined with enthusiasm and a genuine interest in the role of Risk Assessment, Third Party Technology Risk Assessment, Risk Analysis in business and providing Risk Opinion as a subject matter expert.  

         Working knowledge of global regulations, frameworks and standards(ISO, NIST, COBIT, PCI-DSS, HIPAA) and conversant in the tactics, techniques and procedures used by Risk adversaries.  

         Demonstrates a calm professional approach, with a good understanding of delivery within time constraints and the need to escalate/inform departmental management as appropriate.  

         IT knowledge

Technical Skills

         Good understanding of organizations and IT Businesses 

         Good technical understanding of infrastructures and IT Security Productions and Systems

         Experience in vulnerability management and penetration testing

         IT risk /Third Party risk analysis and management methods and should have worked on Risk management Tools like RSA Archer, Metric stream, ServiceNow etc 

         Knowledge of Cyber Resilience, IT continuity and business continuity

         GRC - Governance, Risk Management and Compliance Management. 

         Firewall and Internet technologies; Cloud Security, Banking Tools & Technologies.

         Secure access control mechanisms; Encryption and Key management technics

Behavioral Skills

         Strong Communication, Analytical and problem-solving skills.

         Proven organizational skills with excellent multi-tasking, result oriented and prioritization skills

         Good documentation and reporting skills

         Ability to work independently

         Strong communication and interpersonal skills, able to communicate and relate easily with IT, Finance and back-office users

         Good communication, technical writing/diagramming skills

         Attention to detail and accuracy 

         Capacit for crativit and innovation 

         Self-discipline

Specific Qualifications: 

         One or more Industry-recognized information Security certifications such as CISSP, CISA, GCCC, CISM, CEH, CRISC, OSCP or Security+.

         IT Security tools like Firewalls, IPS, WAF, Endpoint protection, Network security, etc. 

         IT Auditing (ISO27001/2, NIST 800 Series, ISO27005, ISO42001)

         Regulatory Compliance

         MBA in Finance/Systems/IT, masters in technology, Bachelor of Commerce, masters in commerce, bachelors in science, bachelors in technology 

Skills Referential (Required knowledge, skills and abilities)

Transversal Skills:

    • Analytical Ability
    • Ability to manage a project
    • Ability to understand, explain and support change
    • Ability to develop and adapt a process 
    • Ability to anticipate business / strategic evolution

Behavioral Skills: 

    • Communication skills - oral & written
    • Attention to detail / rigor
    • Ability to deliver / Results driven
    • Creativity & Innovation / Problem solving

Education Level: Bachelors Degree or Equivalent with at least 5 years of Experience. 

Location: Bangalore

About BNP Paribas Group:

BNP Paribas is the European Unions leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Groups commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.

About BNP Paribas India Solutions:

Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Unions leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.

Commitment to Diversity and Inclusion

At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.

Third Party Technology Risk Management Analyst/ Consultant

Compensation

Not specified

City: Bangalore

Country: India

BNP Paribas logo
Investment Banking

6 days ago

No clicks

at BNP Paribas

ExperiencedNo visa sponsorship

**Third Party Technology Risk Management Analyst/Consultant** (Bangalore, India) - **Key Role**: Identify, assess, and mitigate risks introduced by third-party vendors, suppliers, and partners (TPTs) for BNP Paribas Cardif. - **Responsibilities**: - Instruct EBA ICT risk categories, perform TPT risk assessments, advise on risk treatments, review asset classifications, and monitor TPTs. - Manage risk inventory, coordinate with providers, and contribute to contract negotiations. - Advise beneficiaries/project managers and support SME decision-making. - **Required Skills & Experience**: - Proven IT risk and cybersecurity experience in finance. - Strong knowledge of risk & compliance, cyber threats, and IT operations (IT gov/ops, Apps Sec, network admin). - Industry-recognized certifications (CISSP, CISA, etc.) and global risk/regulatory frameworks. - Proficient in tools like RSA Archer, Metricstream, ServiceNow. - **Education & Location**: Bachelor's degree or equivalent, with at least 5 years of experience. Located in Bangalore. Regression SEO keywords: Third Party Technology Risk Management Analyst Consultant, TPT Risk Assessment, IT Risk Management, Cybersecurity, Vendor Management, IT Operations, IT Governance, Risk Compliance, EBA ICT Risks, TPT Risk Treatment, Security Annex, Contract Negotiation, IT Outsourcing Risks, IT Security, IT Change Management, IT Data Integrity, IT Availability & Continuity, TPT Risk Inventory, TPT Risk Monitoring, Secure Access Controls, Encryption, Cloud Security, Banking Tools.

Full Job Description

Job Title: Third Party Technology Risk Management Analyst/ Consultant

Department: Cardif France

About Business line/Function: TG-CDF / TPTRM is an unique community to identify, assess, and mitigate the vulnerabilities and exposures introduced by external vendors, suppliers, and partners.

Position Purpose: The BNP Paribas Cardif Governance, Risk and Compliance team supports IT and Business Units to develop adequate solutions on operational IT and Cyber risk management practices, 

with specific focus on Information Security. 

Their main missions are:  

Identify operational IT and Cyber risks on assets/applications, projects and 3rd-parties.  

Advice, consult, monitor and report on risk treatment in order to reduce the overall risk exposure of IT and Business at an optimized cost.  

Elaborate and manage the implementation of a flexible strategy to reduce IT and Cyber risks in accordance with the IT and Information Security policies of BNP Paribas Group.  

Responsibilities

Direct Responsibilities

         Instruct the 5 European Bank Authority (EBA) ICT risks categories including ICT availability and continuity, ICT security, ICT change, ICT data integrity, and ICT outsourcing risks and to follow them throughout TPTRM assessments

         Perform third-party technology risk assessments to help beneficiaries/contract owners identify and evaluate complex business and technology risks related to their third parties, and provide recommendations for managing those risks 

         Provide periodic status updates including potential risks and delays to the project delivery to beneficiary project manager, conduct workshops wherever necessary.

         Assist in the selection and tailoring of third-party technology risk management approaches, methods and tools to support delivery of third-party cyber risk assessment services.

         Review thoroughly Asset classifications and pre-existing asset related risks & control responses ensuring sync with TPTRM assessments responses; build the Security Annex that allows proper monitoring of the provider in the contract, and if needed contribute to the negotiation.

         Identify key actors for decision making according to flagged risk families 

         Apply group key procedures, templates, to carry out risks activities 

         Ensure to highlight key factors using Risk Assessment Form that will help SMEs in decision making 

         Demonstrate knowledge in one or more of the following cyber risk domains, including: Security Governance and Management, Security Policies and Procedures, Application Security Controls, Access Controls, Network Security Operations, Security Architectures, Identity Management, Disaster Recovery & Business Continuity, Incident Response, Risk Management, Privacy and Data Protection, Encryption and Inventories/data quality management.

Contributing Responsibilities

         As part of its defined missions, the TPTRM Analyst/Consultant is responsible for executing - or supporting the execution of TPTRM Assessments involving - IT operational risks identification, assessment, documentation, treatment, monitoring and closing.

         Document TPTRM risks, assess inherent and residual risks in the activity 

         Analyze the root cause and the business impact 

         Work towards mitigation plan and risk acceptance 

         Provide support to beneficiary/contract owner to implement residual actions 

         Report to P&P/ ITRO/ Project Manager about key TPTRM risks information, warning, or alert 

         Contribute to various exercises and reviews on controlling and assessing TPTRM risks 

         As a TPTRM Analyst/ Consultant review if all the mandatory prior assessments are properly completed if not take necessary actions towards compliance 

         Define and document a methodology, use groups tool to manage and document assessments and outcomes

         Facilitate the business/sponsor/beneficiary/SME decision-making with deep analysis based on relevant flagged risk families

         Provide support to provider teams/ contract owners and coordinate/ assist to ensure proper assessments are made.

         Manage TPTRM inventory with follow-up tracker management and contribute if needed to the negotiation of the requirement mandatory or non-mandatory in the security annex of the contract

         Monitor the process with specific and group standard indicators to steer the activity 

         As an IRM team member this includes all or part of the following activities: 

o    Execute as First Line of Defense: Oversight of risk management and compliance, providing support and guidelines to operational teams. 

o    Contribute to process improvement, upkeep with new policies, regulations, standards & guidelines 

o    Contribute to IRM IT risk awareness actions

Technical & Behavioral Competencies

Functional Skills  

         Experience in IT Risk and Cyber Security domains in a financial institution demonstrating a high level of commitment and self-motivation. 

         Experience in the Finance & IT industry with a strong exposure to IT Operations, Application Security, and/or network administration, IPS 

         Strong demonstrated knowledge of Risk & Compliance, cybersecurity, cyber risk, cyber threats, Third Party Technology Risk Management/ Vendor assessments 

         Risk knowledge and awareness of risks combined with enthusiasm and a genuine interest in the role of Risk Assessment, Third Party Technology Risk Assessment, Risk Analysis in business and providing Risk Opinion as a subject matter expert.  

         Working knowledge of global regulations, frameworks and standards(ISO, NIST, COBIT, PCI-DSS, HIPAA) and conversant in the tactics, techniques and procedures used by Risk adversaries.  

         Demonstrates a calm professional approach, with a good understanding of delivery within time constraints and the need to escalate/inform departmental management as appropriate.  

         IT knowledge

Technical Skills

         Good understanding of organizations and IT Businesses 

         Good technical understanding of infrastructures and IT Security Productions and Systems

         Experience in vulnerability management and penetration testing

         IT risk /Third Party risk analysis and management methods and should have worked on Risk management Tools like RSA Archer, Metric stream, ServiceNow etc 

         Knowledge of Cyber Resilience, IT continuity and business continuity

         GRC - Governance, Risk Management and Compliance Management. 

         Firewall and Internet technologies; Cloud Security, Banking Tools & Technologies.

         Secure access control mechanisms; Encryption and Key management technics

Behavioral Skills

         Strong Communication, Analytical and problem-solving skills.

         Proven organizational skills with excellent multi-tasking, result oriented and prioritization skills

         Good documentation and reporting skills

         Ability to work independently

         Strong communication and interpersonal skills, able to communicate and relate easily with IT, Finance and back-office users

         Good communication, technical writing/diagramming skills

         Attention to detail and accuracy 

         Capacit for crativit and innovation 

         Self-discipline

Specific Qualifications: 

         One or more Industry-recognized information Security certifications such as CISSP, CISA, GCCC, CISM, CEH, CRISC, OSCP or Security+.

         IT Security tools like Firewalls, IPS, WAF, Endpoint protection, Network security, etc. 

         IT Auditing (ISO27001/2, NIST 800 Series, ISO27005, ISO42001)

         Regulatory Compliance

         MBA in Finance/Systems/IT, masters in technology, Bachelor of Commerce, masters in commerce, bachelors in science, bachelors in technology 

Skills Referential (Required knowledge, skills and abilities)

Transversal Skills:

    • Analytical Ability
    • Ability to manage a project
    • Ability to understand, explain and support change
    • Ability to develop and adapt a process 
    • Ability to anticipate business / strategic evolution

Behavioral Skills: 

    • Communication skills - oral & written
    • Attention to detail / rigor
    • Ability to deliver / Results driven
    • Creativity & Innovation / Problem solving

Education Level: Bachelors Degree or Equivalent with at least 5 years of Experience. 

Location: Bangalore

About BNP Paribas Group:

BNP Paribas is the European Unions leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Groups commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.

About BNP Paribas India Solutions:

Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Unions leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.

Commitment to Diversity and Inclusion

At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.