19 Aug
|
Godrej Infotech
|
India
19 Aug
Godrej Infotech
India
Third Party Cyber Risk ManagementAbout the Business & Position OverviewJob ProfileKey Responsibilities
- End-to-end management of Third Party Cyber Risk lifecycle
- Vendor risk assessment and classification based on risk tiers
- Evaluation of vendor security controls and compliance posture
- Integration of data privacy (DPDP) requirements into TPRM
- Risk tracking, remediation, and closure management
- Alignment with regulatory, compliance, and internal security frameworks
- Stakeholder collaboration across business, legal, procurement, and IT
- Continuous improvement of TPRM processes and methodologies
Third Party Cyber Risk Management Responsibilities
- Implement and manage processes for the complete Third Party Cyber Risk Management lifecycle.
- Conduct cyber security risk assessments of vendors, suppliers, partners, and outsourced service providers.
- Classify third parties into risk tiers (Critical, High, Medium, Low) and define assessment scope accordingly.
- Review vendor security certifications and reports (ISO 27001, SOC 2, PCI-DSS) along with internal questionnaires.
- Identify risks related to data privacy, infrastructure access, cloud services, and managed services.
- Incorporate DPDP requirements to ensure vendors handle personal data securely and support user rights.
- Validate vendor capability to protect data and report breaches as per regulatory expectations.
- Track and drive closure of risks, gaps, and remediation actions with vendors.
- Collaborate with internal stakeholders to evaluate residual risks and recommend mitigation or acceptance.
- Ensure vendor controls comply with security standards (ISO 27001, NIST, RBI/SEBI where applicable).
- Support audits, regulatory reviews, and internal assurance activities.
- Maintain dashboards, risk registers, and reporting metrics for leadership.
Stakeholder & Cross-Functional Collaboration
- Partner with Procurement, Legal, Business, Privacy, and Digital teams to embed cyber risk requirements.
- Review and recommend security clauses, SLAs, and audit rights in vendor contracts.
- Provide advisory support during vendor onboarding, selection, and renewal.
Continuous Improvement
- Enhance TPRM processes using automation and risk-based approaches.
- Monitor emerging third-party cyber threats and trends.
- Support incident response activities involving third-party security incidents.
Qualification Details Essential Qualification: Bachelor's degree in Engineering (Information Security, Computer Science, or related field)
Preferred Qualification: Professional certifications such as: CISM / CISSP / CRISC ISO 27001 Lead Implementer / Auditor
Experience Details Essential Experience:
- 6-8 years of experience in Information Security / Cyber Risk / GRC domains
- 3-4 years of hands-on experience in Third Party / Vendor Cyber Risk Management
Preferred Experience: Experience in large enterprises, conglomerates, or regulated industries
Special Skill Essential:
- Strong understanding of cyber security risk management and vendor risk frameworks
- Hands-on experience with TPRM methodologies and assessments
- Knowledge of:
- ISO 27001 / ISO 27002
- NIST Cyber Security Framework (CSF)
- SOC 2
- Data privacy fundamentals
- Familiarity with cloud security and managed service provider risks
- Understanding of DPDP Act and privacy principles (data protection, consent, cross-border considerations)
- Solid analytical, documentation, and reporting skills
- Effective stakeholder management and communication
Preferred:
- Exposure to automation in TPRM tools and processes
- Experience handling regulatory compliance (RBI, SEBI, etc.)
- Incident response exposure involving third-party security events
Location
- Mumbai
📌 GRC Manager (India)
🏢 Godrej Infotech
📍 India