US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Supplier Security - Security Risk Analyst

Schneider Electric's purpose is to empower all to make the most of our energy and resources, bridging progress and sustainability for all.

We call this Life Is On.

Our mission is to be your digital partner for Sustainability and Efficiency.

We drive digital transformation by integrating world-leading process and energy technologies, end-point to cloud connecting products, controls, software and services, across the entire lifecycle, enabling integrated company management, for homes, buildings, data centers, infrastructure and industries.

We are the most local of global companies.

We are advocates of open standards and partnership ecosystems that are passionate about our shared Meaningful Purpose, Inclusive and Empowered values.

Job purpose

The Supplier Security Risk Analyst is part of Supplier security (TPRM) team of the Cybersecurity Governance team.

He/she is in charge of governing Schneider Electric's Supplier Security engagement and collaborating with Suppliers , Procurement , Business stakeholders , Legal team , Data Privacy teams , RCISO's.

Duties and responsibilities

Job Scope/Complexity

This role is defining and implementing initiatives to identify, mitigate cybersecurity and data privacy risks stemming from our suppliers in order to build a trust ecosystem.

The role and associated projects will require basic knowledge in security domains Duties will also require building and maintaining strong, trusted relationships across various practices and functions.

Transversal collaboration is key and required.

Capacity to influence and lead is appreciated.

He/she will work with the Supplier Security team to implement the various controls part of the Supplier security framework and contribute in optimizing the framework.

Main requirement of the role will be to conduct both onsite and remote cyber audits of Suppliers cyber posture based on global standards like IS27001 and IEC62443

A good understanding of organization level controls and product level controls is must , review of evidences provided by the supplier , articulating the risk and ensuring right feedback is provided post audit.

Specific Duties & Responsibilities:

1 - Operational Expertise:



* Participate in supplier assessments done for all Critical and high risk suppliers ( approx.

800+ suppliers)


* Review the evidences provided by the suppliers , provide a detailed report while articulating the residual risks appropriately.


* Debrief of assessment results and action plans with Critical / High risk suppliers


* Understanding of the product cyber risks and their controls.


* Optimization of the risk-based Supplier security framework.


* Support in supplier incidents management process

2 - Communication, Training & Awareness:



* Organize awareness sessions and trainings to educate on the Supplier security program and importance of cybersecurity in our ecosystem to supplier facing population.


* Support in grooming interns , new joinees a...




Share Job