Location: New York,NY, USA
divThe energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy were known for. Its what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldnt do anywhere else. Its up to you to make it happen. /divdivbrVendor Risk Management (VRM) is part of the Chief Risk Office (CRO) and responsible for assisting Bloomberg departments and select subsidiaries of Bloomberg LP in the selection, assessment, mitigation and continuous monitoring of risks introduced by vendors and other third-party service providers. /divdivbrWhats The Role? /divdivbrWe are looking for a Vendor Risk Manager with a strong background in Information Security, Operational Resilience, Technology Audit and/or Risk Management. You will work with Bloomberg departments and subsidiaries to perform the inherent risk assessment of their vendor engagements, create and maintain the risk profile of vendors and vendor products / services, and drive control assessment and risk remediation activities across our vendor population while contributing to strategic initiatives to enhance the overall Vendor Risk program in line with our transformation roadmap. Your work will add value to Bloomberg departments and subsidiaries that use third parties to achieve their goals, by helping them appropriately manage vendor risk throughout the vendor lifecycle. /divdivbrWell Trust You To: /divdivulliLiaise with business and technology teams to understand their use of vendor services and products and appropriately assess the inherent risks related to information security, privacy, resiliency, concentration, regulatory compliance, subcontracting, location / geography, among others. /liliMaintain the vendor and vendor engagement inventory and risk profiles /liliConduct due diligence control assessments, continuously monitor and report on Vendor and vendor engagement risks /liliCoordinate risk mitigation activities with vendors and Bloomberg departments and subsidiaries /liliInterpret, train and enforce compliance with Bloomberg's Vendor Risk Management Policy /liliCultivate and leverage relationships with CISO, Legal, Compliance, Enterprise Risk Management (ERM) and other control functions to accomplish objectives /liliLead key VRM activities and demonstrate understanding of the top and material risks affecting Bloomberg, our supply chains, and our clients /liliAct as subject matter expert on VRM matters supporting Bloomberg departments for which you are responsible /liliProvide advisory support to Bloomberg departments on risk /liliProvide and coordinate input to key compliance, legal and regulatory initiatives /liliDemonstrate existing or develop targeted material to deliver actionable risk reporting to Bloomberg departments as needed /liliParticipate in select risk committees / working groups /li/ul/divdivbrYou'll Need to Have: /divdivulliBachelor's or master's degree in Computer Science, Information Security, Business Management or equivalent industry experience /lili7+ years of experience working in the field of Risk Assurance, Risk Management, Internal Audit or other Compliance-related experience /liliAn understanding of Cloud Computing and how to assess cloud-related risks /liliFamiliarity with international regulations regarding third-party service providers /liliFamiliarity with Industry Frameworks (NIST 800-53, COBIT 5, ISO/IEC 27001/2, HITRUST, PCI DSS, CSA CAIQ and CCM, CIS CSC, NIST 800-171) and Data Privacy regulations/standards/liliFamiliarity with Data Privacy regulations and industry standards (e.g., GDPR, Schrems II, CCPA, HIPAA) /liliFamiliarity with the Digital Operational Resilience Act (DORA) and the European Union Artificial Intelligence (EU AI) Act /liliFamiliarity with Vendor Risk Assessment Frameworks/Tools (e.g., SIG, VSAQ) /liliTechnical knowledge in multiple risk domain areas such as application, architecture, system and network security, identity/access management, etc. /liliKnowledge of current Information Security threats, trends, and mitigations /liliSkilled in risk management, technical risk analysis, and making complex business/risk trade-off recommendations and decisions /liliUnderstanding of impact of financial, technology and privacy regulations on Fintech products and services /liliDemonstrated ability to lead and influence others /liliSenior level written and verbal communication skills /liliDemonstrated leadership, teamwork and collaboration skills /liliIndustry certifications (CISSP, CISA, CISM, CTPRP, CIPT/CIPP, GSEC, GIAC, etc.) /li/ul/divdivbrWe'd Love to See: /divdivbrulliAn understanding of supplier agreements, contractual terms and service level agreements /liliExperience in developing and deploying operational performance metrics to measure IT security effectiveness and operational resilience /liliExperience with Cloud-based IT architectures and security products /li/ul/divdivnbsp;brDoes this sound like you? /divdivbrApply if you think were a good match. Well get in touch to let you know that the next steps are, but in the meantime feel free to have a look at: /divdiv /divdiv /divdiv /divdiv /divdiv /divdiv /divdiv/div
Salary: 130000,180000,USD,Annual
Bloomberg is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law.
Bloomberg is a disability inclusive employer. Please let us know if you require any reasonable adjustments to be made for the recruitment process. If you would prefer to discuss this confidentially, please email ...@bloomberg.net