Senior Supplier Chain Security Assessor
JOIN OUR TEAM
At Levi Nine we are passionate about what we do. We love our work and together in a team we are smarter and stronger. We work in a dynamic and challenging environment with talented and forward-thinking people who are part of creative and innovative teams. We are looking for skilled team players who make change happen. Are you one of these players?
OUR PARTNER:
Our partner, ABN AMRO Clearing, is a global leader in the domain of clearing, offering access to a wide range of listed instruments on markets across the globe.
IT is at the heart of their organization with more than 30 different product teams and 10 different platform teams that are trying to build the best products & services for their customers.
Their presence in important financial centers like Amsterdam, Chicago, Sydney, Singapore, Tokyo Hong Kong, London, Sao Paulo, Frankfurt and Iasi, allows them to effectively serve clients worldwide and maintain close proximity to their diverse customer base.
THE ROLE INVOLVES:
The Supply Chain Security Assessor is responsible for managing supplier and third-party cyber security risk throughout the supplier lifecycle. The role ensures that suppliers, ICT service providers, and outsourced service providers comply with our partner's Supply Chain Security requirements, framework, and applicable regulatory obligations including DORA, MAS TRM, and any other global or regional requirements.
The role works closely with Contract Owners, Third Party Risk Management (TPRM), Legal, and Suppliers to perform security due diligence assessments, continuous monitoring activities, deep-dive security reviews, contractual control implementation, and remediation management.
Responsibilities:
Conduct security due diligence assessments for new suppliers, vendors, and third-party service providers during onboarding and contract negotiations.
Perform continuous monitoring of supplier security posture and follow-up with contract owners and suppliers on improving security posture.
Reporting the supplier security assessment status to capability owners, TPRM and relevant stakeholders.
Conduct event-driven reviews following security incident, threat landscape changes, supplier tiering changes, emerging threats, or significant business events.
Conduct deep-dive supplier security assessments, validating the effectiveness of security controls.
Perform supply chain security quality assurance (QA) of peer's assessment.
Work with suppliers to implement contractual security requirements and ensure alignment with security standards and supply chain security control frameworks.
Partner with Procurement, Legal, Contract Owners and Suppliers, to address security requirements during contract negotiations and renewals.
Manage remediation activities and drive closure of identified security gaps with suppliers and contract owners.
TECHNICAL PLAYGROUND:
5+ years in Cyber Security, Third Party Risk Management, Supplier Security or Information Risk
Proven experience performing security assessments of third parties and suppliers
Experience in defining security requirements in suppliers' contracts
Experience working with Procurement, Legal and Contract Management function
Certifications like CISSP, CISM, CRISC, ISO 27001 Lead Auditor or Lead Implementer are strongly preferred
Ability to challenge suppliers and drive accountability
Ability to explain supplier security gap into business impact to stakeholders
NICE TO HAVE:
Familiarity with supplier continuous monitoring tools and external intelligence platforms
Experience with financial services regulatory requirements (DORA, EBA, APRA CPS 230, CPS 234)
Experience with GRC and TPRM platforms
Knowledge of ISO 27001, NIST CSF, CIS Controls or similar security frameworks
Background or understanding of financial services, clearing, and risk management
Relevant university degree in Computer Science, Engineering, or a related field
SOFT SKILLS:
Fluent English, with good written and verbal communication skills
Strong engineering instinct (do the right thing), a deep understanding of computer science
Strong interpersonal and assertive communication skills, great team member
Strong stakeholder management and influencing skills
Problem-solving and troubleshooting skills
Desire to continuously learn and improve in a complex, rapidly evolving environment
Flexible and adaptive working attitude - self-motivated and taking ownership
- Locations
- Iasi
- Remote status
- Hybrid
- Technologies
- NIST, ISO 27001, CIS
- Seniority level
- Senior
Iasi
About Levi9 Romania
Levi9 is a nearshore technology service provider with around 1000 employees and 50+ customers. We specialize in custom made business IT – 95% of our work is on the revenue side of our customers. This is where time to market, high productivity, stable team velocity, and great quality through automation, agility, intensive interaction and understanding matter most.