
Manager- Supply Chain Security
- Mumbai, Maharashtra
- Permanent
- Full-time
- Assess and report the effectiveness of information security general controls throughout the supplier lifecycle with M&G.
- Track, monitor and report on remedial activities, e.g. control improvement actions arising from supplier information security due diligence activity.
- To demonstrate a positive risk and control culture through the active identification, assessment, monitoring and management of risks and controls within the business area.
- Take all reasonable steps to ensure adherence to all external regulatory, legal and industry obligations within the business area.
- Assist with reporting of Technology and information security control effectiveness and policy compliance levels.
- Provide management information to Enterprise Security & Privacy management and colleagues, working with internal and external teams.
- Liaise with the Procurement function and Business Supplier Managers across M&G to ensure appropriate information security oversight activities are completed on our external suppliers.
- Moderate the annual review and update of information security related policies and processes.
- Stay up-to-date on information technology trends and security standards.
- Conduct trainings to educate and develop security awareness in the workforce on information security
- Provide guidance on associated regulations & legislations.
- Research & assess information security vulnerabilities.
- Head of Supply Chain Security
- Enterprise Security & Privacy
- Technology teams
- First line GRC
- Risk & IA
- Business Unit Representatives for all Business Areas
- Procurement & Third Party Risk team
- Privacy team
- External Supplier
- Data Protection and Information Security industry bodies and members and auditors.
- Prefer SSCP, CISA, CISM, ITIL qualified individual.
- Working knowledge of financial services regulatory and legislative frameworks.
- Working knowledge of Information Security regulations and legislation.
- It is desirable to have working knowledge of industry best practice and external bodies in the same field.
- It is desirable to have working knowledge of information security management and governance standards.
- It is desirable to have working knowledge of third-party relationships and the associated information security risks.
- An understanding of key information security risks posed and ability to develop pragmatic options to mitigate these.
- Good analytical multi-tasking skills.
- Able to look at and understand processes and infrastructure.
- Good understanding in information security methodologies, frameworks and tools
- Ability to build relationships at all levels in the business.
- Ability to present reports in meetings.
- Ability to understand organisational culture and use this knowledge to gain commitment and get work done.
- Ability to provide support to and accept direction from colleagues in other areas.
- Remain effective in situations when responsibilities, tasks, priorities and / or work environment change significantly.
- Broad knowledge of business conducted within M&G, including M&G Global Services India.
- Be clear, concise and impactful when communicating with others.
- Ability to assess multiple options (including consequences) in parallel, while working on possible solutions.
- Ability to work with limited supervision, seeking guidance where appropriate.
- Excellent people management skills.
- Confident communicator, able to get the message across clearly and concisely via appropriate channels, whether verbal or written.
- 4+ years’ experience of working or studying in at least one of the following areas: IT / information security / risk management / audit / assurance / business continuity / supplier management.
- Experienced in working with UK stakeholders.
- Graduate in any discipline.