Conduct IT vendor risk assessments, manage risk findings, provide guidance on security requirements, and prepare reports for management. Lead a team and enhance risk assessment processes.
            Description and Requirements
Position Summary
To perform end to end IT third party cyber risk assessments, which includes Vendor Due Diligence, Risk Identification and Analysis, Archer Management, Reviewing the vendor's questionnaire, Control Mapping, Third party audit report review, Findings and Exceptions Management, Risk Mitigation and Periodic Reviews and various Contracts negotiations; on MetLife's vendor and other third party organizations to ensure adherence to security and compliance requirements.
Job Responsibilities
 Conduct end to end IT third party vendor risk assessments over third party vendors, including but not limited to: determining the scope of the service provided by interacting with MetLife Senior Management and business point of contacts; administering risk assessments directly to vendors using our online GRC tool; examining responses to determine the extent of risk the relationship represents to MetLife; performing gap assessments on the vendor's control environment; reviewing vendor's third party audit reports; offering recommendations to Vendor and MetLife's management on the risk incurred, and on how to respond to any risks; and generating risk findings.   Assess and respond to risk findings, including pursuing action plans to completion and negotiating due dates with vendors;   Provide guidance to the business, Strategic Sourcing and other stakeholders to ensure requirements of VRM are fully understood   Perform security assessments of systems, applications, data centers, infrastructures and service providers using an established framework and tools to evaluate vulnerabilities. Research new and developing technologies and standards to help contribute to the continuous improvement of the risk assessment process   Act as a subject matter expert in understanding why certain risks are a threat to the company and how compensating or mitigating processes affect that risk   Prepare weekly and monthly reports and dashboards, which shall be submitted to higher management and stakeholder;   Provide guidance on IT Security Requirements during Contract negotiation discussions.   Continually reassess the operational risks associated with the function and inherent in the business   Support Vendor selection and contracting on major sourcing efforts and reassess the risks associated with a vendor relationship prior to the renewal of contract agreements   Identify and communicate departmental vendor risk issues and compliance problems that have not been adequately addressed; offer reasonable solutions, and assist them with efforts to come into compliance   
Knowledge, Skills and Abilities
Education
Experience
Knowledge and skills (general and technical)
About MetLife
Recognized on Fortune magazine's list of the "World's Most Admired Companies" and Fortune World's 25 Best Workplaces™, MetLife, through its subsidiaries and affiliates, is one of the world's leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East.
Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by our core values - Win Together, Do the Right Thing, Deliver Impact Over Activity, and Think Ahead - we're inspired to transform the next century in financial services. At MetLife, it's #AllTogetherPossible . Join us!
#BI-Hybrid
    Position Summary
To perform end to end IT third party cyber risk assessments, which includes Vendor Due Diligence, Risk Identification and Analysis, Archer Management, Reviewing the vendor's questionnaire, Control Mapping, Third party audit report review, Findings and Exceptions Management, Risk Mitigation and Periodic Reviews and various Contracts negotiations; on MetLife's vendor and other third party organizations to ensure adherence to security and compliance requirements.
Job Responsibilities
Knowledge, Skills and Abilities
Education
- Master's/Bachelor's degree in Engineering/IT/Information Security or Computer Science from a recognized Indian University
 
Experience
- 4-6 years of experience into IT-Third Party Cyber Risk Management, IT risk & security and IT audit.
 
Knowledge and skills (general and technical)
- Knowledge of information security standards (SSAE16, PCI ROC/AOC, ISO 27001:2022), laws (e.g., NIST, FFIEC, etc.), and regulatory requirements (e.g., GDPR, DPL, HIPAA) and commonly used concepts, practices and procedures within the information security, application security, data center security, and privacy.
 - Proven solid analytical and problem solving skills. Advanced computer skills including Microsoft Office suite and other business related software systems.
 - Skills in influencing business units to assess and monitor vendor risk and follow vendor risk management policy.
 - Ability to manage various complex projects and processes to completion. Sound concepts of Vendor Assessments and to manage existing work and also for providing value addition to existing work.
 - Excellent writing and communication skills; able to translate technical concepts into layperson's terms and interface with upper-level management including Legal Counsel and Corporate Compliance.
 - Excellent ability to work effectively with peers, business units, IT management and staff, and internal/external business partners/clients/vendors.
 - Able to deal with ambiguity - integrate, prioritize and rollout programs without clearly defined guideline.
 - Strong organizational ethics to manage a large volume of competing tasks effectively.
 - Direct experience in developing, implementing, and improving technology controls in a corporate environment.
 - Experience of working in a fast-paced organization that is focused on accountability (must deliver results).
 - Experience working with all levels of an organization and be comfortable in presenting, interacting with, and taking direction from Senior Management
 - Have a team leading and mentoring skill to lead a team of information security professionals and mitigate their IT risk issues.
 
About MetLife
Recognized on Fortune magazine's list of the "World's Most Admired Companies" and Fortune World's 25 Best Workplaces™, MetLife, through its subsidiaries and affiliates, is one of the world's leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East.
Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by our core values - Win Together, Do the Right Thing, Deliver Impact Over Activity, and Think Ahead - we're inspired to transform the next century in financial services. At MetLife, it's #AllTogetherPossible . Join us!
#BI-Hybrid
Top Skills
Grc Tools
Microsoft Office Suite
Similar Jobs at MetLife
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
This role involves developing cloud-native software and AI applications, requiring skills in both front-end and back-end development in a collaborative environment.
Top Skills:
                        Ai-Driven ApplicationsCloud-Native Software
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The role involves finance support, revenue and expense management, financial performance analysis, and reporting. It requires collaboration with various teams to ensure timely and accurate financial deliverables.
Top Skills:
                        ExcelMetlife SystemsPowerPoint
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The role involves managing teams in operations, ensuring SLAs are met, optimizing processes, stakeholder management, and team motivation. A strong background in claims management is essential.
Top Skills:
                        ExcelMicrosoft TeamsMS OfficeOutlookPowerPoint
What you need to know about the Dublin Tech Scene
From Bono and Oscar Wilde to today's tech leaders, Dublin has always attracted trailblazers, with more than 70,000 people working in the city's expanding digital sector. Continuing its legacy of drawing pioneers, the city is advancing rapidly. Ireland is now ranked as one of the top tech clusters in the region and the number one destination for digital companies, with the highest hiring intention of any region across all sectors.

