Current: English
Job Description
Responsibilities
1. Issue Entry & Ownership
- Review the 3PCRM Assessment Letter and accurately enter control exceptions/findings into the designated Issue Management (IM) tool.
- Assume ownership of assigned issues and ensure complete and accurate issue documentation.
- Validate issue details, risk ratings, control gaps, remediation requirements, and due dates.
- Maintain accurate issue records throughout the remediation lifecycle.
2. Remediation Plan Review & Approval
- Review vendor-proposed remediation plans to determine whether they adequately address identified control gaps and risks.
- Challenge remediation plans where actions are incomplete, unclear, or insufficient.
- Coordinate with the Vendor Manager (VM) to obtain clarification or revised remediation plans.
- Collaborate with VM and relevant Technology and Line of Business stakeholders to obtain required approvals.
- Ensure remediation activities are risk-based, actionable, measurable, and aligned with organizational requirements.
3. Risk Treatment & Challenge Management
- Initiate and manage risk treatment challenges using the approved IM Challenge Template.
- Assess proposed risk treatment approaches and challenge vendor responses where appropriate.
- Document rationale, decisions, stakeholder inputs, and required actions within the Issue Management process.
- Ensure risk treatment activities are properly tracked and supported by evidence.
4. Remediation Follow-Up & Escalation
- Monitor remediation milestones, target dates, and upcoming issue deadlines.
- Proactively follow up with Vendor Managers and vendors for remediation progress and supporting evidence.
- Escalate overdue or at-risk remediation activities to the appropriate stakeholders.
- Where evidence has not been received two weeks prior to the due date, escalate to the Vendor Manager, company stakeholders, and Supplier Lead.
- Maintain appropriate escalation records and stakeholder communications.
5. Evidence Validation & Issue Closure
- Review remediation evidence submitted by vendors to determine whether it adequately addresses the identified control gap.
- Validate evidence for completeness, relevance, accuracy, and effectiveness.
- Determine whether the remediation action sufficiently mitigates the identified risk.
- Update the Issue Management record with assessment results and supporting documentation.
- Where remediation is sufficient, seek approval from the 3PCRM IM Lead Consultant for issue closure.
- Ensure closed issues have complete documentation and an appropriate audit trail.
6. Risk Acceptance Management
- Review vendor Risk Acceptance (RA) requests and evaluate the rationale provided for accepting the identified risk.
- Assess proposed compensating controls and determine whether they adequately mitigate the associated risk.
- Coordinate with relevant stakeholders where additional information or challenge is required.
- Where acceptable, initiate/log the appropriate Exception Request.
- Track risk acceptance deadlines and ensure required approvals are obtained.
- Monitor RA expiry dates and initiate extension, remediation, or reassessment activities as appropriate.
7. Control Exception & Gap Management
- Analyze cybersecurity control exceptions identified through third-party assessments.
- Ensure control gaps are clearly documented with associated business and cybersecurity risks.
- Track findings through remediation, risk acceptance, exception, and closure processes.
- Identify recurring control gaps and contribute to trend analysis and risk reporting.
- Support continuous improvement of the 3PCRM control exception and remediation process.
Required Skills & Experience
- 5+ years of experience in Cyber Risk, IT Risk, IT Audit, GRC, Information Security, or Third-Party Risk Management.
- Strong experience in control gap, finding, issue, and remediation management.
- Experience documenting cybersecurity findings, remediation plans, risk treatment activities, and control exceptions.
- Experience reviewing and challenging remediation plans and risk acceptance requests.
- Strong understanding of risk treatment, compensating controls, exception management, and issue lifecycle management.
- Experience validating remediation evidence and determining whether issues can be closed.
- Strong stakeholder management and escalation skills.
- Excellent analytical, documentation, reporting, and communication skills.
Tools & Platforms
Experience with one or more of the following:
- Archer
- Jira
- ServiceNow
- Issue Management / GRC platforms
- Microsoft Excel and reporting tools
Cybersecurity & Risk Knowledge
Working knowledge of:
- Third-Party Risk Management (TPRM/3PCRM)
- Cybersecurity Risk Management
- IT General Controls (ITGC)
- Control Testing & Assessment
- Risk & Control Frameworks
- Issue and Exception Management
- Risk Acceptance
- Compensating Controls
- Remediation & Corrective Action Management
- Audit and regulatory requirements
- NIST, ISO 27001, CIS Controls, SOC 2, or equivalent cybersecurity standards
Preferred Qualifications
- CISA, CRISC, CISSP, CISM, ISO 27001, or equivalent certification.
- Experience working with enterprise GRC/Issue Management platforms.
- Experience in vendor/third-party cybersecurity risk environments.
- Experience working with technology, procurement, business, security, and supplier management teams.
Key Competencies
- 3PCRM Control Exception Management
- Cyber Risk & IT Risk Management
- Control Gap Analysis
- Issue Management
- Remediation Tracking
- Risk Treatment & Challenge
- Risk Acceptance & Exception Management
- Evidence Validation
- Stakeholder & Vendor Management
- Escalation Management
- Audit Readiness
- Strong Analytical & Reporting Skills
- Attention to Detail
- Effective Written & Verbal Communication



