Third Party Information Security Specialist

4 weeks ago


Malaysia Experian Full time
Third Party Information Security Specialist
  • Full-time
  • Employee Status: Regular
  • Role Type: Hybrid
  • Schedule: Full Time

Experian is the world’s leading global information services company. During life’s big moments – from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers – we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control and access financial services, businesses to make smarter decisions and thrive, lenders to lend more responsibly, and organisations to prevent identity fraud and crime.

We have 21,700 people operating across 30 countries and every day we’re investing in new technologies, talented people, and innovation to help all our clients maximise every opportunity. With corporate headquarters in Dublin, Ireland, we are listed on the London Stock Exchange (EXPN) and are a constituent of the FTSE 100 Index.

Learn more at or visit our global content hub at our global news blog for the latest news and insights from the Group.

This role takes a lead on complex Third-Party Assurance reviews. There are three major aspects to this position -

(1) Conducting reviews of NEW Third-Party entities (Supplier, Reseller, Joint Ventures) - identifying areas of conformance and non-conformance to Experian requirements; driving security contract language and inputs into the Risk Management Process.

(2) Conducting reviews of EXISTING Third-Party entities (Supplier, Reseller, Joint Ventures) - identifying areas of conformance and non-conformance to Experian requirements and inputs into the Risk Management Process.

(3) Supports the Director – Third Party Security UKI and EMAP and VP-Global Head of Third-Party Security to continuously improve the local TPS Management System and ensure that it meets local regulatory, policy and business requirements

• 7+ years of experience in security field specially around security assessments or audit field

• Technical background with prior hands-on experience a plus

• Ability, drive and motivation to research and provide the right guidance and find possible solutions. Ability to push back where the risk outweighs the benefits.

• Curiosity to ask questions and challenge status quo

• Strong leadership skills.

• Excellent verbal and written communication skills.

• Process driven, and has eye for detail, automation and efficiency to improve programs/processes.

• Good collaboration, relationship and interpersonal skills.

Qualifications

• Bachelor’s degree in computer science or relevant field or equivalent demonstrable experience

• CISSP, CISA, CISM, PCI QSA, ISO Lead Auditor or comparable certifications preferable

• 7-10 years experience in Information Security, ideally with some knowledge of performing IT/Information Security Reviews

Dimensions

  • Perform security assessments for new and existing Third Parties using the Third Party Security framework.
  • Provide proactive security support and partnership to other teams within Information Security, Governance and the Business
  • Partner with regional indirect sales and procurement to ensure procedures meet regional requirements / operating practices.
  • Partner with Global TPS colleagues to ensure best practice is shared across all regional teams.
  • Identify information security deficiencies, risks and exceptions to appropriate parties as soon as possible.
  • Ensure 1LoD ownership and ensure non-compliance issues, exception justification, mitigation and risks are appropriately captured.
  • Work with RISOs and other GSOs partners - assist and / or drive remediation activities to mitigate security deficiencies.
  • Validate work / peer review of other in region assessments.
  • Assist in managing the Third-Party Security inventory and programme within the region.
  • Work with 1LoD relationship owners to address BitSIght monitoring alerts.
  • Validate work / peer review of assessments.

Experian Careers - Creating a better tomorrow together

#J-18808-Ljbffr

  • Malaysia PETRONAS Digital Sdn Bhd Full time

    We are looking for an experienced individual who will be responsible to review and assess new and legacy internal Digital projects in both IT and OT space. Ensure all new and legacy applications and systems comply to the Cyber Security standards, requirement and guidelines and to assess the risk classification and impact to PETRONAS environment as well as...


  • Malaysia Nityo Infotech Full time

    •Bachelor's degree in Information Technology, Cybersecurity, or a related field, or equivalent work experience.•1-3 years of experience in cybersecurity, risk management, or vendor management.•Working knowledge of third-party risk assessment methodologies and vendor management practices.•Familiarity with security frameworks such as NIST, ISO 27001,...


  • Malaysia Nityo Infotech Full time

    •Bachelor's degree in Information Technology, Cybersecurity, or a related field, or equivalent work experience.•1-3 years of experience in cybersecurity, risk management, or vendor management.•Working knowledge of third-party risk assessment methodologies and vendor management practices.•Familiarity with security frameworks such as NIST, ISO 27001,...


  • Malaysia DN & Associates Executive Search Pte Ltd | HEADHUNTER Full time

    Regional Information Technology Director I provide bespoke, customised solutions to your Talent Attraction challenges| Headhunter | Top Recruiting Voice | Hustler in the Day and Mum in the… Our client is a trusted provider and supplier of healthcare products with presence in the South East Asia region. They are looking for an experienced IT Director to...


  • Malaysia Ensign InfoSecurity Full time

    Ensign is hiring ! L1 **Responsibilities**: - Perform security monitoring, vulnerability management, data loss / policy violation prevention and threat hunting - Monitor security sensors and review logs to identify network anomalies or intrusions - Provide analysis from monitoring, research and assessment of security log data from a large number of...


  • Malaysia Crypto.com Full time

    The Cybersecurity and Data Privacy team reports directly under the office of the CISO headed by Chief Information Security Officer (CISO) Jason Lau () who has over 23+ years of experience in the cybersecurity space, awarded Global Top 100 CISO, and also serves on the World Economic Forum, International Association of Privacy Professionals and more. The...

  • Security Analyst

    3 weeks ago


    Malaysia Ensign InfoSecurity Full time

    Ensign is hiring ! Evaluates, tests, monitors and maintains information systems (IS) and cyber security policies, procedures and systems I Creates, implements and oversees identity management systems to meet specific security needs and complex compliance standards | Ensures that IS and cyber security plans, controls, processes, standards, policies and...


  • Malaysia Mastercard Full time

    Associate Managing Consultant, Specialized Product Delivery We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and...

  • Director of Security

    3 weeks ago


    Malaysia Destination Hotels Full time

    Summary You will be responsible for the efficient running of the department in line with Hyatt International's Corporate Strategies and brand standards, whilst meeting associate, guest and owner expectations. The Director of Security is responsible to develop, implement, monitor and evaluate the hotel's safety and security procedures, including fire safety,...


  • Malaysia NodeFlair Full time

    **Job Summary**: **Job Type** **Seniority** **Years of Experience** Information not provided **Tech Stacks** play

  • Technical Lead

    1 week ago


    Malaysia Combined Insurance Full time

    To be successful in this role, you will have to be proficient in both front-end and back-end coding languages, development frameworks and third-party libraries. Additionally, being familiar with Agile methodologies, Scrum experience will be a plus and having worked in a Microsoft Azure environment is a must. **Responsibilities**: - Lead the development...

  • Supervisor, Security

    4 weeks ago


    Malaysia Western Digital Capital Full time

    Company Description At Western Digital, our vision is to power global innovation and push the boundaries of technology to make what you thought was once impossible, possible. At our core, Western Digital is a company of problem solvers. People achieve extraordinary things given the right technology. For decades, we’ve been doing just that. Our technology...

  • Head of Pre-Sales

    4 weeks ago


    Malaysia Michael Page Full time

    Kuala Lumpur Permanent MYR20,000 - MYR25,000 per month (MYR240,000 - MYR300,000 per year) Regional exposure for an international MNC Opportunity to be part of a high growth environment About Our Client Our client is a global provider of compliance and payment solutions for the financial services sector. Their experience and expertise help ensure trust...


  • Malaysia Nityo Infotech Corporation Full time

    Degree: Degree holder in Computer Science or majoring in Information Systems, or related discipline. Experience: 5 years+ experience in Security\Risk Assessments with a security focus, gained in another sizable organization Certifications: Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control...

  • Technical Lead

    4 weeks ago


    Malaysia NFT Pangolin Full time

    About NFT Pangolin NFT Pangolin is a global marketplace for regional creators in Asia to issue and sell their unique crypto secured assets to collectors. We aspire to be the leading regional marketplace driving creative, innovative collaborations and boundary pushing campaigns in the NFT space globally for issuers and collectors alike, while making a...

  • Warehouse Executive

    3 days ago


    Malaysia Ogawa World Berhad Full time

    Responsibility - Responsible for organize the warehouse areas, making the best and most efficient use of space, and managing the day to day activities of warehouse staff.Interact with third party transporter for transport arrangement. - Monitoring road show such as location, quality, scheduling, reliability and validity, service, delivery & others. -...


  • Malaysia TIME's group Full time

    Security (Information & Communication Technology) Join SleekFlow, a thriving SaaS startup that is experiencing rapid growth thanks to the support of renowned investors like Alibaba Entrepreneurs Fund and Tiger Global. Our mission is to revolutionize social commerce, and as a member of our team, you will have the opportunity to thrive alongside the company...

  • Construction Director

    4 weeks ago


    Malaysia Balfour Beatty Full time

    To apply for this job please sign in or create an account below. must be different from email address, first name and last name Keep me signed in Marketing Communication We'd love to send you information about Jobs and Services from Evenbreak by email. Yes please. I'd like to receive emails about jobs and services from Evenbreak I'd like...

  • Software Engineer

    3 weeks ago


    Malaysia ZALORA group Full time

    As a FE Engineer for Payments team, you will build high performance, scalable and testable components/integrations in our platform while integrating with different PGs. You will be working in a diverse, international setting with teammates who are experts in various topics. In Payments squad , we work in Scrum/Agile setting and are highly goal driven. You...


  • Malaysia Michael Page Full time

    About Our Client Our client is looking for a Head, IT Security Governance and Architecture to be part of the team. Job Description 1. Provide thought leadership and direction for IT Security team to effectively manage teamwork load, quality deliverable, performance and talent in delivering a systematic, proactive, approach that balances IT risk and...