TP CIS Assessments & Monitoring Head
Texas, USA · Michigan, USA · India · Tulsa, OK, USA
TP CIS Assessments & Monitoring Head
India
Information Technology (IT)
Group Functions
Your role
The Chief Information Security Office (CISO) team is a first line of defense organization within UBS, whose mission is to ensure cyber and information security control objectives are set, efficiency is measured, and residual risks are handled. As a member of Third Party Cyber and Information Security Oversight leadership team, you are required to have experience in leading a global team, substantial knowledge in the Information Security & Cybersecurity, and Technical Supply Chain Management fields to deliver robust Third Party cyber assurance program and ensure UBS data is appropriately protected, while enabling technology advancements in line with business strategies and to continuously improve the Bank’s 3rd party security risk posture.
The successful candidate will have experience in the quality execution and assurance of Information and Cyber Security 3rd Party risk management including 3rd party audit & regulatory management along with continuous monitoring of third parties. Applicant will work collaboratively across the Bank, and particularly with the CISO team, business division & third party stakeholders, Global & Regional Governance teams, Audit & Control Teams, 2Lod and 3Lod.
Your role :
You will be responsible for leading a global team of 50+ cyber security professionals tasked with evaluating the security posture of third-party vendors that have access to sensitive information or systems of UBS. As the team lead you will ensure delivery of Third Party cyber risk assessments for UBS and identify and evaluate potential security threats posed by our third-party vendors. You will also work closely with internal stakeholders across all business lines to ensure understanding of identified risks and partner with them to agree resolution. We are looking for candidates who have experience in the following areas: • leading a team of cyber security professionals who conduct risk assessments of third-party vendors to identify potential security threats and vulnerabilities;
•Reporting regular updates to relevant committees and management teams on the status of 3rd party Cybersecurity risk and compliance issues based on internal/external & regulatory assessment results
•Ensure that 3rd party Cybersecurity risk assurance approach, plans and execution are aligned with standard operating policies and procedures, risk assurance standards and regulatory requirements
• Train/guide/mentor assessors to analyze and evaluate vendor security controls, policies, and procedures to ensure compliance with regulatory requirements and industry best practices; • Support the team performing continuous monitoring on high CIS inherent risk using tools like Security Scorecard.
Job Reference #
340729BR
City
Pune
Job Type
Full Time
Your team
You’ll be working in the CISO/OCRA (Operational Consolidate Risk assessment) team in India. You'll take a part in supporting colleagues from different areas of the firm, including Risk Taxonomy Owners, Compliance & Operational Risk Controllers and Outsourcing & Supplier Management, in improving the overall risk assessment process and implementing the most effective remediation measures.
Additional assets: • experience with industry recognized standards for IT security controls and best practices like NIST, ISO27001, PCI DSS, COBIT, SOC 2 etc.; • one of the following professional qualifications obtained: CEH, CISSP, CISA, CISM, CRISC or ITIL.
Your expertise
You have:
• Familiar with internal / external and regulator engagements
• Knowledge in regulatory guidelines and requirements: FRBNY, FINMA, MAS, HKMA, RBI, etc.
• Knowledge and specialist in 3rd to Nth party security risk oversight and assessment
• Cyber and Information security or data privacy related certifications (e.g. CISSP, CISM, CISA or CRISC) are an advantage.
• Ability to communicate both written and verbal for business key partners and management audience. Excellent negotiation, influencing and analytical skills are highly desired
• Previous leadership role and experience handling/managing a team in training/mentoring/guiding/managing their performance
• Knowledge in NIST Cybersecurity Framework and NIST 800 series documents and other such related frameworks: COBIT/ITIL/ISO
• Information Security audit or risk assessment experience in complex IT environments, including Cloud technologies would be beneficial.
• Proven ability to work both independently and as part of a team to deliver quality work in a fast-paced environment
• Flexibility and ability to think creatively and to identify new ways to approach old problems
• Phenomenal analytical, decision-making, and problem-solving skills
• Dedication to fostering an inclusive culture and value varied perspectives.
• 10+ years of experience in third-party risk assessment or cybersecurity assessment;
• certifications such as Certified Third-Party Risk Professional (CTPRP) or Certified Information Systems Security Professional (CISSP) are a plus.
You are: • a strong communicator, with good spoken and written English; • good team player with analytical ability to provide practical solutions for minimizing risk; • well organized, detail oriented, with the ability to collect data, coordinate tasks and lead projects; • comfortable leading a team including training, mentoring & guiding, but not hesitant to bring in the expertise of colleagues to help the team; • having risk identification and risk articulation skills; • able to build and maintain strong relations with stakeholders; • able to show initiative, make logical decisions and stay goal oriented at unclear times; • available to work in hybrid model at least 3 days from the office.
•You’re curious to explore how AI can improve how we build, deliver, and optimize workflows. You do this with sound judgment – validating outputs and aligning with policies, risk standards, and ethical use.
About us
UBS is a leading and truly global wealth manager and the leading universal bank in Switzerland. We also provide diversified asset management solutions and focused investment banking capabilities. Headquartered in Zurich, Switzerland, UBS is present in more than 50 markets around the globe.
We know that great work is never done alone. That’s why we place collaboration at the heart of everything we do. Because together, we’re more than ourselves. Want to find out more? Visit ubs.com/careers.
Join us
At UBS, we know that it's our people, with their diverse skills, experiences and backgrounds, who drive our ongoing success. We’re dedicated to our craft and passionate about putting our people first, with new challenges, a supportive team, opportunities to grow and flexible working options when possible. Our inclusive culture brings out the best in our employees, wherever they are on their career journey. And we use artificial intelligence (AI) to work smarter and more efficiently. We also recognize that great work is never done alone. That’s why collaboration is at the heart of everything we do. Because together, we’re more than ourselves.
We’re committed to disability inclusion and if you need reasonable accommodation/adjustments throughout our recruitment process, you can always contact us.
Disclaimer / Policy statements
UBS is an Equal Opportunity Employer. We respect and seek to empower each individual and support the diverse cultures, perspectives, skills and experiences within our workforce.