Third Party Risk Management Specialist
Dis-Chem Pharmacies · Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Job Description
- Dis-Chem Pharmacies has an opportunity available for a Third-Party Risk Management Specialist responsible for assessing and managing security risks arising from Dis-Chem's external vendors, technology partners, and service providers.
- The role establishes and maintains Dis-Chem's third-party security due-diligence framework, evaluates vendor controls before onboarding, and monitors ongoing compliance across the vendor lifecycle.
- Works closely with CISO, Enterprise Architecture, Procurement, and IT platform teams to ensure third-party risks are identified early, assessed consistently, and addressed through contractual, technical, or operational controls. Strengthens resilience in a landscape heavily reliant on external IT partners.
Requirements
- Degree in Information Security, IT, Risk Management, or related field
- 5+ years' experience in IT security or vendor risk management, preferably in a multi-vendor environment
- Exposure to outsourced service models, SOC/MDR providers, and cloud-hosted solutions.
Responsibilities
Information Security Governance & Compliance
- Develop and maintain the third-party security assessment and onboarding framework for all technology vendors
- Establish security requirements, minimum controls, and contractual clauses for IT suppliers in alignment with enterprise architecture and CISO standards
- Maintain a central third-party risk register and ensure risk ratings, remediation actions, and exceptions are documented and reviewed
- Collaborate with Procurement to embed security reviews into sourcing and renewal
Third-Party Security Risk Management
- Conduct risk assessments for new vendors and high-risk services; evaluate security certifications, architecture, hosting, data flows, access models, and operational processes
- Identify control gaps and recommend mitigation across domains e.g., IAM, data protection, resilience, patching, monitoring
- Partner with IT platform teams to validate integration risks and enforce secure configuration requirements
- Track remediation progress with vendors and escalate overdue or critical issues to CISO
Monitoring, Incident Support & Reporting
- Monitor vendor security posture continuously through attestations, performance metrics, and threat intelligence
- Support incident investigation when a vendor-driven outage or cyber event impacts Dis-Chem noted as a known pain point
- Provide reporting to CISO, Procurement, and Leadership on vendor risk levels, trends, and areas requiring uplift
Competencies
Domain Expertise
- Strong understanding of third-party risk, vendor security controls, and security assessment methods
- Knowledge of risk domains relevant to retail pharmacy hosting, data protection, resilience, availability, integrations
- Familiarity with regulatory and contractual security requirements.
Leadership & Commercial Acumen
- Ability to influence vendors and internal stakeholders toward secure-by-design decisions
- Strong negotiation and communication skills to articulate risks and required mitigations.
Key Performance Indicators
- % of vendors assessed and risk-rated before onboarding
- Remediation closure rate for vendor findings
- Contribution to culture, accountability, engagement, and continuous improvement
- Reduction in vendor-related incidents or outages
- Quality and completeness of vendor risk documentation
- Stakeholder satisfaction with vendor risk process
Special Conditions of Employment
- South African citizen
- MIE, clear criminal and credit
- Driver's license and/or own reliable transport
Remuneration and benefits
- Market related salary
- Medical aid
- Provident fund
- Staff account
Closing Date 02 October 2026