- Company Name
- Bloomberg
- Job Title
- Vendor Risk Manager (6 Month Contract) - Chief Risk Office
- Job Description
-
**Job Title:** Vendor Risk Manager (6‑Month Contract)
**Role Summary:**
Lead the assessment, monitoring, and remediation of vendor‑related risks for a global enterprise’s business units and subsidiaries. Manage the full vendor lifecycle, ensuring compliance with security, privacy, and regulatory frameworks while collaborating with business, technology, legal, and compliance stakeholders.
**Expectations:**
- Deliver accurate risk profiles and control assessments for all third‑party engagements.
- Drive continuous monitoring and remediation plans, achieving alignment with corporate risk appetite and transformation goals.
- Provide expert guidance to business units on vendor risk management best practices and regulatory compliance.
**Key Responsibilities:**
- Conduct inherent risk assessments of vendor engagements and maintain an up‑to‑date risk inventory.
- Perform due‑diligence control assessments, monitor vendor performance, and report risk status to stakeholders.
- Coordinate risk mitigation activities with vendors and internal teams, ensuring timely resolution of gaps.
- Interpret and enforce the organization’s Vendor Risk Management Policy; train and support business units.
- Build and sustain relationships with CISO, Legal, Compliance, ERM, and other control functions.
- Act as subject‑matter expert in vendor risk, advising on strategic initiatives and regulatory updates.
- Prepare and deliver actionable risk reports; participate in risk committees and working groups.
**Required Skills:**
- 5+ years in risk assurance, internal audit, risk management, or compliance.
- Deep knowledge of cloud risk, data privacy (GDPR, CCPA, HIPAA), and emerging regulations (DORA, EU AI Act).
- Proficiency in industry frameworks: NIST 800‑53, COBIT 5, ISO/IEC 27001/2, HITRUST, PCI DSS, CSA CAIQ/CCM, CIS CSC, NIST 800‑171.
- Technical acumen across application, architecture, system, and network security, identity management.
- Strong analytical, business‑risk trade‑off, and decision‑making skills.
- Excellent written and verbal communication, with proven leadership and influence.
**Required Education & Certifications:**
- Bachelor’s or Master’s degree in Computer Science, Information Security, Business Management, or equivalent experience.
- Relevant certifications: CISSP, CISA, CISM, CTPRP, CIPT/CIPP, GSEC, GIAC, or equivalent.