BDO Wave - CISO 3rd Party Analyst, Gqeberha (Port Elizabeth)
BDO South Africa · Port Elizabeth, Eastern Cape
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Description
- The Third Party Security Analyst supports the delivery of BDO's third-party security framework. The role is responsible for carrying out supplier information security due diligence activities, analysing evidence provided by third parties, identifying and escalating potential risks, and helping ensure supplier and supply chain information security risks to BDO and BDO client services are assessed, recorded and managed in line with agreed processes and standards. This role reports to the business information risk officer and works closely with procurement, legal, contract management and business stakeholders.
Requirements Principal Accountabilities
- Supports the delivery and continuous improvement of the information security supplier assurance framework across the supplier lifecycle.
- Coordinates supplier information security due diligence activities, including requesting, gathering and reviewing documentation and evidence from internal and external stakeholders.
- Applies agreed assessment criteria and analysis techniques to evaluate supplier security controls and identify potential risks, issues or control gaps.
- Prepares clear and well-structured risk assessment outputs, summaries and recommendations for review by senior colleagues and stakeholders.
- Identifies and escalates non-routine, higher-risk or complex issues to the appropriate technical experts or management.
- Supports supplier risk classification and tiering activities using agreed methodologies, risk indicators and business context.
- Tracks remediation actions, risk treatment activities and follow-up actions, and helps ensure updates are communicated to relevant stakeholders in a timely manner.
- Works with procurement, legal, contract management and business teams to help ensure information security requirements are considered within sourcing, onboarding, contract change and offboarding processes.
- Assesses supplier responses against BDO policies, standards, contractual requirements and relevant regulatory expectations, seeking guidance where needed.
- Maintains accurate records, assessment data, management information and metrics to support reporting, oversight and audit readiness.
- Communicates progress, findings and changes clearly, checking understanding and adapting messages for technical and non-technical audiences.
- Contributes ideas and practical improvements to enhance supplier assurance processes, templates, guidance and ways of working.
Technical competencies
- Experience in supplier assurance, third-party risk management, information security, technology risk, audit, compliance or a related analyst role.
- Working knowledge of supplier due diligence and risk assessment activities across stages of the supplier lifecycle, including onboarding, contract change, ongoing monitoring and offboarding.
- Ability to review and analyse security documentation, control evidence and supplier responses, and draw logical conclusions using agreed criteria and guidance.
- Familiarity with common information security frameworks and good practice, such as ISO 27001, SOC 2, Cyber Essentials Plus, CIS Controls or OWASP.
- Understanding of information security principles relating to access control, encryption, vulnerability management, incident management, business continuity and data protection.
- Able to identify risks, concerns and exceptions, and escalate complex or higher-risk matters appropriately.
- Strong written, verbal and interpersonal communication skills, with the ability to communicate clearly and adapt style for different audiences.
- Good organisational skills, attention to detail and ability to manage own workload using agreed processes, priorities and deadlines.
- Able to work collaboratively with internal stakeholders and external suppliers, building effective working relationships and seeking clarification where required.
- Relevant qualifications, training or progress toward an industry certification such as CISSP, CISM, CRISC, ISO 27001 or equivalent would be advantageous.