Ta oferta pracy jest nieaktualna od 15 dni. Sprawdź aktualne oferty pracy dla Ciebie

IT Risk Assurance Analyst

  • Warszawa, mazowieckie pokaż mapę
  • Specjalista
  • 05.04.2019

    Pracodawca ma prawo zakończyć rekrutację we wcześniejszym terminie.

    IT Risk Assurance Analyst
    Workplace: Warszawa
    Ref. no: WAR0010J

    About EY GDS

    EY Global Delivery Services means 29.500 specialists providing globally IT, HR, finance, project management and strategic business services to EY member firms. In addition we deliver support and solutions to clients from all over the world.

    EY Technology team maintains and enhances EY’s IT infrastructure and works for our internal clients across the globe. You will work with EY locations, supporting our service lines and key business processes or be part a dedicated IT team handling cross-organizational initiatives and transformational projects.

    EY Technology supports our technology needs through three business units:

    • Information Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information management systems.
    • Client Technology (CT) - focuses on developing new technology services for our clients. It enables EY to identify new technology-based opportunities faster, and pursue those opportunities more rapidly.
    • Enterprise Workplace Technology (EWT) – EWT supports our Core Business Services functions and will deliver fit-for-purpose technology infrastructure at the cheapest possible cost for quality services. EWT will also support our internal technology needs by focusing on a better user experience.ect, respond, and mitigate cyber risk and to enable the Firm to move at the speed of business.  

    The opportunity

    The Supplier Risk Assurance program evaluates and monitors information security risk associated with the Firm’s use of third party technology suppliers. We measure risk against Firm security controls, industry standards, regulations and laws, and EY business practices. We then advise our engagement and project managers, our procurement team, and our Legal teams in the recommended treatment of the risk assessment conclusions. 

    In a working world where there is an increasing reliance on third party provided products and services the role offers interaction with some of the most interesting and important technology related activities of the Firm across the spectrum of services offered.  

    This role is an important and very visible contributor offering highly valued and critical services within a highly collaborative team environment. A more exciting challenge is difficult to find!

    Your key responsibilities

    The person chosen will conduct inherent risk assessments, vendor research, reporting, data analytics, communications with our stakeholders, and other required tasks associated with the execution of the Supplier Risk Assurance mission.  
    Skills and attributes for success
    • Advanced and creative analytic abilities to synthesize technical data, project related information, interview and survey results, and other information to inform risk decisions.
    • Ability to manage and deliver on multiple and shifting priorities to provide high quality, timely, and effective service to our customers.
    • Advanced interpersonal skills to engage and collaborate with multiple internal and external stakeholders within a matrixed and global organization.
    • Highly developed communications skills, both oral and written in the English language.
    • Must be able to rapidly learn a complex business process that involves acquisition of knowledge and familiarity with related regulations, EY Policies and Standards, and international standards such as ISO 27001:2013.
    To qualify for the role you must have
    • Higher degree in computer science or related discipline.
    • 2+ years’ experience in any of the following: information security, IT risk management, internal audit, or compliance.
    • Knowledge of Information Security controls such as ISO27001:2013, NIST, or SOC. 
    Ideally, you’ll also have
    • Certifications such as the Certified Information Systems Security Professional (CISSP) or Global Security Essentials Certification (GSEC).
    • Good working knowledge of data analytic methods and tools, including but not limited to Spotfire, and Microsoft Excel. Good knowledge and skills with Microsoft Office and Sharepoint.
    • Experience and skills in Information Security technical areas.
    Who we look for?
    The ideal candidate will enjoy the challenge of rapid acquisition of knowledge and have the skills and determination to join a high performing team.  We are looking for someone who is agile, flexible, serious about providing top flight service to our customers, and above all a great team member.    
    What working at EY GDS offers?
    We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer:
    • Support, coaching and feedback from some of the most engaging colleagues around.
    • Opportunities to develop new skills and progress your career.
    • The freedom and flexibility to handle your role in a way that’s right for you.