What are the responsibilities and job description for the Third Party Risk Management Consultant position at Abacus Service Corporation?
Job Details
Note: Onsite role it is.
Position : Third Party Risk Management Consultant
Location : Jefferson City ,MO
Client : State of Missouri
Position id : OA-2507-30398-012
The State seeks to establish the first phase of a comprehensive Third-Party Risk Management (TPRM) Program to assess, mitigate, and monitor cybersecurity risks originating from third-party service providers. The project will review existing vendor management processes, identify gaps, create risk management policies and procedures, develop a vendor assessment framework and criticality matrix, and support pilot implementation with training and reporting deliverables
- Testing timeline must not be compressed once the work plan has been approved.
- All services must be provided in the United States. Offshore services shall not be used to perform the services outlined herein.
- Vendor resource(s) may be exchanged under the SOW without modifications of the SOW upon agreement of the SOW Vendor and the State. The State reserves the right to review resumes and accept/reject proposed resource(s).
- Security & Confidentiality All materials (including code, tools, documentation and data) provided pursuant to the SOW shall be deemed confidential. Vendor resource(s) must comply with agency and ITSD security policies, agency and ITSD required trainings, and/or required security specifications that describe: (i) required security capabilities, (ii) required design and development processes, (iii) required test and evaluation procedures, and (iv) required documentation.
- Usage of any recording devices or Generative AI recording is prohibited in any meetings associated with the project and/or this Statement of Work (SOW) by the vendors.
- The SOW Vendor resource(s) must report to the ITSD Project or Resource Manager or designee, who will provide resource(s) with sufficient knowledge to perform the work.
Any specific requirement
All work must be U.S.-based; no offshore services.
Adherence to ITSD security, confidentiality, and training policies.
Use of State-owned ADO/JIRA for tracking issues.
No out-of-state travel required.
No generative AI or recording devices allowed in meetings
Salary : $60 - $70