Jobs on TAL
All jobsOnsiteEngineeringcybersecurity8-12 yearsinformation security
OnsiteSeniorcybersecurity

Third-Party Security Risk Management, Consultant

AIASingaporePosted 20 May 2026

AIA is seeking a consultant to manage third-party security risk, performing due diligence and ensuring regulatory compliance. The role involves assessing security postures of vendors and aligning them with information security standards. The position requires 8-12 years of experience in risk management, ideally within the financial industry. It is a critical role supporting the Senior Manager of Technology Vendor Management.

Matched by TAL

50k new jobs listed every day. Install TAL to find more jobs like this.

Install TAL

Experience

8-12 years

Function

Engineering

Work mode

Onsite, Singapore

Company

Tier 2

What you will work on

AIA is seeking a consultant to manage third-party security risk, performing due diligence and ensuring regulatory compliance. The role involves assessing security postures of vendors and aligning them with information security standards. The position requires 8-12 years of experience in risk management, ideally within the financial industry. It is a critical role supporting the Senior Manager of Technology Vendor Management.

TAL's take

Quality 60/1005/5 clarityTier 2 company

Stable and established insurance domain role with clear, specific responsibilities in security risk management.

The JD provides a very clear breakdown of duties within third-party risk management and governance.

Must haves

  • University degree in Computer Science, Engineering, Information Systems, or Cyber Security
  • 8-12 years of IT experience, audit, or risk management roles
  • Expertise in governance reporting of technology risk and cyber security
  • Strong knowledge of KRIs and metrics development
  • Ability to work independently with high integrity

Tools and skills

information securitytechnology risk managementthird-party risk managementcompliancekrismetrics developmentdue diligence

Nice to have: cissp, cisa, crisc, ccsp, mas trmg, iso27001, nist, soc2, ospar, project management.

About the company

Established insurance MNC, not a pure-play tech company.