Key Responsibilities
Conduct security and risk assessments of third-party vendors throughout the vendor lifecycle.
Review security documentation, including SOC reports, ISO certifications, penetration test reports, and security questionnaires.
Identify security, privacy, compliance, and operational risks, and provide recommendations to address identified gaps.
Partner with business owners, procurement, legal, privacy, and technology teams to support vendor onboarding and risk reviews.
Track remediation activities and monitor risk treatment plans through completion.
Maintain vendor risk assessments, risk ratings, exceptions, and supporting documentation within the TPRM platform.
Perform periodic reassessments of critical and high-risk vendors in accordance with established review cycles.
Support internal and external audits by providing TPRM-related evidence and documentation.
Prepare risk summaries, metrics, and reports for management and key stakeholders.
Contribute to the continuous improvement of the Third-Party Risk Management program, including processes, templates, and standards.
Preferred Qualifications
Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Risk Management, or a related field.
3–6 years of experience in Third-Party Risk Management, Information Security, IT Audit, or Governance, Risk, and Compliance (GRC).
Familiarity with vendor risk assessment methodologies and common security frameworks.
Experience reviewing security documentation such as SOC reports, penetration tests, and compliance certifications.
Robust analytical, documentation, and communication skills.
Experience with TPRM or GRC platforms is an asset.
Relevant certifications such as Security+, CISSP, CISM, CRISC, or CISA are considered a plus.
📌 TPRM Analyst (Bengaluru)
🏢 HGS
📍 Bengaluru