15 Aug
|
FinThrive
|
Gurugram
15 Aug
FinThrive
Gurugram
Overview We are seeking a detail-oriented and collaborative Associate Cybersecurity Risk Analyst to join our growing security team. In this role, you will jointly push forward FinThrive’s Third Party Security Risk Management (TPRM) program and manage responses to customer security inquiries. You will work cross-functionally with IT, Engineering, Product, Sales, Procurement, and Legal to deliver timely, accurate, and defensible diligence on both sides of the security review. Responsibilities • Third Party Security Risk Management ◦ Execute and mature the day-to-day TPRM program, including risk-based vendor tiering aligned to data sensitivity, criticality, and regulatory obligations. ◦ Perform vendor security assessments using questionnaires and evidence (SIG, CAIQ, custom) and review assurance artifacts such as SOC 2 Type II, ISO 27001, HITRUST, PCI, and pen test results. ◦ Document findings, drive remediation to closure, and manage time-bounded risk acceptances and exceptions. ◦ Support continuous monitoring (security ratings, attestation refresh) and secure vendor offboarding. ◦ Partner with Legal and Procurement to embed security requirements in contracts (security addendums, DPAs, breach notification, right to audit). • Customer Security Inquiries ◦ Manage and respond to customer security questionnaires, RFPs, and due diligence requests. ◦ Maintain a repository of standardized responses and supporting documentation to enable cross-functional team independence. ◦ Translate complex security concepts into customer-friendly language and represent FinThrive’s security posture to prospects and customers. • Cross-Functional Collaboration & Tooling ◦ Work closely with IT, Engineering, Product, and Sales to ensure timely, accurate completion of both vendor and customer reviews.
◦ Implement and manage tools (e.g., Whistic, Vanta, security ratings platforms) to streamline and automate inquiry and assessment workflows. ◦ Produce metrics and dashboards covering vendor risk posture, remediation aging, inquiry volume, and SLA performance. • Product, Infrastructure & Compliance Knowledge ◦ Maintain a strong understanding of FinThrive’s products, SaaS architecture, data flows, and security controls. ◦ Support FinThrive’s Audit and Compliance program by aligning activities to HITRUST, HIPAA, SOC 2, NIST, and ISO 27001 requirements. Qualifications • 1-3 years of relevant experience in information security, third party risk management, GRC, or due diligence response. • Experience responding to customer security questionnaires and assessing vendor security posture against frameworks (SOC 2, HIPAA, ISO 27001). • Working knowledge of security control domains: IAM, vulnerability management, encryption, logging/monitoring, incident response, and data handling. • Familiarity with IT infrastructure (servers, firewalls, load balancers, databases), SaaS architecture, and web applications. • Robust written and verbal communication skills, with the ability to explain technical concepts to non-technical audiences. • Customer-centric mindset with experience collaborating with Sales teams and customers. • Proficiency with Microsoft Office (Word, Excel, PowerPoint, Visio). • Bachelor’s degree (IT, Information Security, or Business Administration preferred). Preferred Skills • Security+ or similar certification. • Familiarity with HITRUST, NIST, PCI DSS, and GDPR/CCPA. • Experience with Trust Center, questionnaire management, and continuous monitoring platforms (SafeBase, Whistic, Vanta). • Familiarity with cloud provider assurance models (AWS/Azure/GCP shared responsibility) and SaaS risk patterns.
📌 Associate Cybersecurity Risk Analyst (Gurugram)
🏢 FinThrive
📍 Gurugram