1. Reduce Supply Chain Security Risks: Lower security risks to acceptable levels.
2. Increase Security Assurance: Boost the number of suppliers undergoing security assurance.
3. Reduce Security Incidents: Decrease the number of security incidents reported by suppliers.
4. Compliance: Ensure adherence to regulations like Data Privacy and UNECE Regulation No. 155.
Key Responsibilities
1. Risk Management: Identify and mitigate supply chain risks.
2. Supplier Engagement: Work with suppliers to improve security.
3. Compliance Monitoring: Ensure suppliers comply with security standards.
4. Risk Monitoring: Track and address supply chain security risks.
5. Performance Management: Manage KPIs to ensure positive security outcomes.
6. Support: Provide expertise on supplier assurance and security risks.
Essential Skills and Experience
- Experience: Supply chain security assurance.
- IT Audit/Risk Management:
Managing technology risk and compliance.
- Information Security: Knowledge of security principles and best practices.
- Communication: Solid skills to engage with stakeholders and suppliers.
- Critical Thinking: Detail-oriented and organized.
- Interviewing: Conducting supplier interviews.
- Documentation: Documenting processes and controls.
- Standards: Knowledge of NIST, ISO, Privacy Laws.
- Agile: Experience in an Agile environment.
Desirable Qualifications
- Certifications: CISA, CISM, ISO27001 lead auditor, or CISSP.
- Regulatory Knowledge: UNECE Regulation No. 155.
- Manufacturing Security: Experience in managing security in manufacturing.
- Auditing: Information security auditing techniques.
- Global Experience: Working in a global business environment.