Cyber Risk Analyst

5 days ago


Kuala Lumpur, Malaysia S&P Global Full time

**About the Role**:
**Grade Level (for internal use)**: 08
S&P Global Corporate

**About the Role**: Cyber Risk Analyst

This role helps reduce the cyber risk posed by third parties and protects S&P Global brands against possible attacks against our information assets by threat actors via backdoor created by our vendors. Primary responsibilities will include assessing Cybersecurity, Business Continuity controls for S&P third parties by conducting control risk assessments, risk recertification's, and continuously monitoring the vendors engaged by S&P.

**The Team**: As part of Vendor Risk Management, the Vendor Cyber Risk Management team manages the Supply Chain Cyber risks by performing risk assessments of third-party engagements to identify and reduce the risks posed by third parties. This is an extremely important role, considering the fact that large number of data breaches happen due to third parties. It involves working with internal stake holders as well as third parties to achieve the results.

**Responsibilities and Impact**: Working in Vendor Risk Management offers the opportunity to continuously enhance processes to meet the evolving requirements of various regulators. This challenging environment provides ample opportunities to expand your knowledge and expertise.
In addition to risk assessments, recertification's, and continuous monitoring, you will participate in various projects, allowing you to showcase and further develop your skills and experience.

Conduct thorough Cybersecurity, Business Continuity, Artificial Intelligence, Cloud Service Prover and Privacy assessments for Vendors, evaluating their information security policies, procedures, and controls.

Effectively collaborate with internal teams to identify critical vendors and assess their potential impact on the organization's cyber risk profile.

Communicate risk assessment findings and recommendations to key stakeholders, including senior management, legal, and compliance teams.

Work closely with vendors to address identified security gaps and ensure they meet the organization's cybersecurity requirements.

Review the vendors on the continuous monitoring program and assisting in driving the periodically review the vendors.

Monitor and stay abreast of evolving cybersecurity threats and industry trends to enhance the effectiveness of the risk assessment process.

Lead and support enhancement projects within Vendor Risk Management to meet various business and regulatory requirements.

Assist the team members in balancing the load and managing Ad-hoc projects.

**What We’re Looking For**:Basic Required Qualifications**:
Bachelor’s degree in computer science or engineering or equivalent

Minimum 3 years of experience in Information Security or Technology Risk Management

Any prior exposure to vendor risk management and/ or privacy laws and regulations is a plus.

Demonstrable understanding of the concepts of technology controls and information security controls.

Exposure to cloud technologies and cloud security is highly desired; the familiarity with pubic cloud technologies such as Amazon Web Services (AWS) or Microsoft Azure or Google Cloud is highly preferred.

Excellent communication skills - a must. The resource should have the ability to communicate with cross-functional teams and vendors, both written and oral communication is critical.

**Additional Preferred Qualifications**:
This position is required to work in UK Shift; flexibility is a must, especially when it comes to vendor and internal meetings held during US business hours.

Strong organizational skills with the ability to multitask and prioritize while maintaining close attention to detail.

Ability to build strategic partnerships with internal stakeholders.

Must be a critical thinker with strong qualitative skills.

Information Security/Risk Management certification would be an advantage.

**Return to Work**: Have you taken time out for caring responsibilities and are now looking to return to work? As part of our Return to Work initiative, Restart, we are encouraging enthusiastic and talented returners to apply, and will actively support your return to the workplace.

What’s In It For You?

**Our Purpose**:
Progress is not a self-starter. It requires a catalyst to be set in motion. Information, imagination, people, technology-the right combination can unlock possibility and change the world.

Our world is in transition and getting more complex by the day. We push past expected observations and seek out new levels of understanding so that we can help companies, governments and individuals make an impact on tomorrow. At S&P Global we transform data into Essential Intelligence®, pinpointing risks and opening possibilities. We Accelerate Progress.

**Our People**:
We're more than 35,000 strong worldwide—so we're able to understand nuances while having a broad perspective. Our team is driven by curiosity and a shared belief that Essential Intelligence can help b



  • Kuala Lumpur, Kuala Lumpur, Malaysia ONESECURE Asia Full time 121,600 - 182,400 per year

    Role DescriptionThis is a full-time on-site role for an Experienced Cyber Security Analyst based in WP. Kuala Lumpur. The role involves conducting security assessments, evaluating security, analyzing and mitigating malware threats, and enhancing network security. The analyst will be responsible for identifying vulnerabilities, developing security strategies,...


  • Kuala Lumpur, Malaysia Affin Bank Full time

    Assistant Manager, Cyber Risk Management **Create your future with Affin! You too can make a difference.** Join us at AFFIN, where the open minds meet and be inspired by a shared commitment to great work. Here, you don't just stay at the forefront of the industry - you can make a difference too. **Job Purpose** Ensure the governance and oversight on the...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Hilti Group Full time 90,000 - 120,000 per year

    WHAT'S THE ROLE?You will be part of the Global Cyber Risk, Control & Assurance team and together with your fellow Cyber Risk and Controls Officers you ensure that IT & cyber risks at Hilti are proactively identified, evaluated and managed.This full-time position is available as soon as possible.WHAT YOU'LL DOYou will support the PO IT & Cyber Risk Management...


  • Kuala Lumpur Centre, Kuala Lumpur, Malaysia Hilti (Malaysia) Sdn Bhd Full time 60,000 - 120,000 per year

    What's the role? You will be part of the Global Cyber Risk, Control & Assurance team and together with your fellow Cyber Risk and Controls Officers you ensure that IT & cyber risks at Hilti are proactively identified, evaluated and managed.This full-time position is available as soon as possible.What You'll do You will support the PO IT & Cyber Risk...


  • Kuala Lumpur, Malaysia Avensys Consulting Sdn Bhd Full time

    **Responsibilities** - Independently assess the effectiveness of SDLC and Change Management controls, determine the impact of control issues, identify corrective action, and track issues to closure. - Perform risk assessments, regulatory and compliance assessments for services and processes. - Work with stakeholders to remediate any identified weakness or...


  • Kuala Lumpur, Malaysia Ekco Full time

    **About Ekco** Founded in 2016 Ekco is now one of the leading cyber security and cloud solution providers in Europe! We specialise in enabling companies to progress along the path of cloud maturity, managing transformation and driving better outcomes from our customers’ existing technology investments. - ️ In a few words, we take businesses to the...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Kris Infotech Sdn Bhd Full time 60,000 - 120,000 per year

    HIRING NOW: Senior Technical Business Analyst (Cyber Security Services) |12 month |On-Site|Kuala Lumpur, MalaysiaWe're hiring for professionals forSeniorTechnical Business Analyst (Cyber Security Services) rolefor a 12-month rolling contract for our client in Kuala Lumpur, Malaysia.Location:Kuala Lumpur, MalaysiaJob Type: 12-Month Contract...

  • Business Analyst

    2 weeks ago


    Kuala Lumpur, Malaysia Skill Quotient Resources Sdn Bhd Full time

    The Cyber Security (CS) Unit under GAP (Governance Assurance and Planning) department is responsible to define, implement and monitor Cybersecurity practices for PDB and subsidiaries. We are looking to recruit an Executive who will be critical for the success of this Unit’s activities and program. Reporting to the CS Unit Head, this role also requires...


  • Kuala Lumpur, Kuala Lumpur, Malaysia KPMG Malaysia Full time 120,000 - 208,000 per year

    Description:The senior incident response manager role will be working in the Cyber Response Services (CRS) Team within our Risk Consulting practice, reporting directly into the head of cyber response. Cyber security is one of the areas which KPMG has identified for tremendous investment and growth. Our clients face a challenging cyber threat and look to us...


  • Kuala Lumpur, Malaysia Munich Re Full time

    Risk and Compliance Analyst Risk and Compliance Analyst (Contract) - Munich Re Retakaful **Company** Munich Re **Location** Kuala Lumpur, Malaysia Reporting to Chief Risk and Compliance Officer of Munich Re Retakaful, you are responsible to provide an effective key second line of defence role for Munich Re Retakaful operations both from a Bank Negara...