Job Summary
Cyber risk management - engagement type full-time;
experience level 2-4 years; function governance, risk, and compliance.
About the role: We are looking for a detail-oriented and proactive Client Assurance Contractor to support our team on an as-needed basis. In this role, you will be part of the first line of response for all client-facing security and compliance requests, ensuring our clients and business stakeholders receive timely, accurate, and professionally presented assurance materials. You will work closely with our legal, case, and client service teams to respond to security questionnaires and review contractual security clauses - playing a critical role in building and maintaining client trust across our consulting engagements.
Responsibilities
- Security Questionnaire Management: Review and respond to client security questionnaires (RFPs, DDQs, vendor assessments) received from clients across all engagement stages. Maintain and continuously update a centralized knowledge base of standard responses, ensuring answers reflect current firm policies and certifications. Coordinate with internal stakeholders (IT, InfoSec, HR, Legal) to gather accurate inputs for complex or bespoke questionnaire items.
Track all incoming questionnaire requests, manage turnaround timelines, and ensure SLAs are consistently met.
- Contract Security Clause Review: Collaborate with the legal and case teams to review, flag, and advise on security-related clauses in client contracts and engagement letters. Identify gaps or risks in proposed contractual language and recommend appropriate redlines or standard firm positions. Maintain a repository of pre-approved security clause positions and standard firm language for common scenarios.
Escalate high-risk or non-standard contractual requirements to senior leadership or the InfoSec team as needed.
- Client Assurance Reporting: Prepare client-facing assurance documentation (e.g., security summaries, data handling statements, certification overviews). Support the team in responding to ad-hoc client queries related to data privacy, information security, and regulatory compliance. Monitor and track the status of pending client assurance requests across multiple simultaneous engagements.
Required Qualifications
- 2-4 years of experience in information security, risk compliance, legal operations, client assurance, or a related field.
- Experience working in a professional services, consulting, or other client-facing services environment is preferred.
- Familiarity with common security frameworks and standards (e.g., ISO 27001, SOC 2, GDPR, NIST).
- Experience handling or contributing to security questionnaires or vendor due diligence responses.
- Strong written communication skills with the ability to translate technical security concepts into clear, client-friendly language.
- High attention to detail and ability to manage multiple concurrent requests with varying deadlines.
- Comfortable working independently in a fast-paced, client-focused setting.
Key Competencies
- Analytical Thinking
- Attention to Detail
- Clear Written Communication
- Stakeholder Collaboration
- Time Priority Management
- Discretion Confidentiality
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Cyber Risk Management (GRC) professional (Bengaluru)
🏢 UST
📍 Bengaluru