IT Third Party Risk Specialist
In this role, you will be responsible for assessing, monitoring, and managing IT and cybersecurity risks associated with third-party vendors and service providers. You will work closely with cross-functional stakeholders across Procurement, Legal, Compliance, Cybersecurity, and IT to ensure third-party risks are identified, evaluated, and effectively mitigated throughout the vendor lifecycle.
Responsibilities:
- Lead and perform IT risk assessments on third-party vendors and service providers, including cloud services, SaaS, infrastructure providers, and managed services.
- Define and maintain the third-party risk management (TPRM) framework, processes, and controls in alignment with internal policies, regulatory requirements, and industry best practices.
- Collaborate with procurement and business units during vendor onboarding and renewal to conduct due diligence, risk reviews, and control assessments.
- Evaluate vendor responses to security questionnaires and assess supporting documentation (e.g., SOC reports, ISO certifications, penetration test results).
- Track and monitor identified risks, issues, and remediation plans with third-party vendors to ensure timely resolution.
- Conduct periodic reassessments of critical vendors to ensure ongoing compliance with security and data protection requirements.
- Support regulatory, audit, and internal reporting requirements by maintaining accurate and comprehensive third-party risk records.
- Contribute to the development of risk metrics, dashboards, and reports for senior management and governance forums.
- Stay current on regulatory developments and emerging risks related to third-party risk management and cybersecurity.
Requirements:
- Bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or a related field.
- 3-8 years of experience in IT risk management, third-party/vendor risk assessment, or cybersecurity in a regulated industry
- Strong knowledge of IT controls and security frameworks
- Familiarity with regulatory requirements such as MAS TRM, GDPR, PDPA, or equivalent.
- Experience in reviewing technical documents such as SOC reports, penetration tests, and cloud security
- Excellent stakeholder management, communication, and analytical skills.
To apply:
If you’re interested to apply or find out more, please share across your CV or reach out to Chen Yi at cy@kerryconsulting.com for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060

An organisation operating within a large, complex and mission-critical environment is seeking an experienced leader to head its...
An international financial institution is seeking an experienced leader to head its local Information Security Coordination and...
The Head of Cyber Operations will lead the organisation’s cyber defence capability, overseeing 24×7 Security Operations, Threat Intelligence, Threat Hunting, Detection Engineering and Incident...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are looking for an experienced Lead Data Security Engineer to design, implement, and enhance enterprise data security capabilities across on-premises and cloud environments. This...
We are seeking an experienced Head of IT & Cybersecurity to lead the strategy, operations, and continuous improvement of the organisation’s IT infrastructure and cybersecurity posture. This...
We are seeking a Cybersecurity Architect to join a lean and highly collaborative cybersecurity team. This role will be responsible for defining, designing, and driving the implementation of security...
We are partnering with a leading Singapore-based organization seeking a senior Application Security Architecture leader to drive secure-by-design practices, enterprise security architecture and AI security...
We are looking to hire a Cybersecurity Policy Developer to strengthen the organisation’s cyber governance and policy capabilities. This role sits at the intersection of cybersecurity strategy,...
Our client is looking for a Security Governance Lead to drive the governance, risk and assurance function within its cybersecurity...
Our client is looking for an experienced cybersecurity leader...
Our client is seeking an experienced cybersecurity leader to drive enterprise security governance, technology risk and data protection...
A leading multinational organisation is seeking an experienced Security Architect to drive secure architecture and technology initiatives across a regional environment.
This role will be responsible...
The Head of Cyber Operations will lead the organisation’s cyber defence capability, overseeing 24×7 Security Operations, Threat Intelligence, Threat Hunting, Detection...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are looking for an experienced Lead Data Security Engineer to design, implement, and enhance enterprise data security capabilities across on-premises and cloud...
We are seeking experienced Technology Risk & Controls lead to join the first-line governance and controls function within a highly regulated financial services environment....
Industry: Multiple Sectors (Financial Services, Technology, Critical Infrastructure, Commercial and Others)
We are currently partnering...
A leading multinational organisation is seeking an experienced Security Architect to drive secure architecture and technology initiatives across a regional environment.
A leading global organisation is looking to hire a Technology Risk & Controls professional to support its enterprise technology environment. This role sits within the Technology function and works...
Our client is a leading organisation operating within a regulated environment, and is seeking an experienced Head of Cybersecurity and Technology Risk to lead its enterprise-wide technology risk and...
This is a hands-on cybersecurity role that sits across security engineering, operations, and design. The position focuses on strengthening the organisation’s security posture by embedding controls...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are partnering with a leading Singapore-based organization seeking a senior Security Architecture leader to drive secure-by-design practices, enterprise security architecture...
