03 Sep
|
Promaynov Advisory Services
|
Bengaluru
03 Sep
Promaynov Advisory Services
Bengaluru
Third Party Risk Analyst will support the organization’s vendor and third-party risk management program by helping identify, assess, monitor, and report risks associated with suppliers, vendors, service providers, and other external business partners. The role will support vendor onboarding, inherent risk assessment, due diligence, questionnaire, and evidence review, issue remediation, ongoing monitoring, and risk reporting across the third-party lifecycle.
This role requires practical experience using ServiceNow , preferably within Third-Party Risk Management, or related workflow modules. The analyst will use ServiceNow to manage assessment workflows, issue and review questionnaires, track tasks and remediation items, maintain accurate third-party records, and support reporting and stakeholder coordination
Key Responsibilities
Vendor Onboarding, Intake, and Risk Tiering
- Support onboarding and renewal reviews for new and existing third-party relationships, including intake validation, business-owner coordination, inherent risk questionnaire review, and routing of assessment requirements to appropriate stakeholders
- Assist in determining vendor risk tiering and assessment scope based on the nature of services, data access, system connectivity, operational criticality, geography, subcontractor reliance, compliance exposure, and other relevant risk factor
- Ensure required intake information, assessment records, supporting documentation, and approval evidence are complete, accurate, and maintained
ServiceNow TPRM Workflow Management
- Use ServiceNow to create, update, monitor, and close third-party risk records, assessments, questionnaires, tasks, issues, and remediation activities
- Issue and review questionnaires through ServiceNow, track vendor and stakeholder responses, monitor workflow status,
and ensure assessment activities progress in accordance with program expectations
- Maintain accurate vendor, engagement, assessment, issue, and reporting data in ServiceNow to support portfolio visibility, audit readiness, management reporting, and operational decision-making
- Support reporting and dashboard activities, including assessment status, open issues, remediation progress, overdue items, risk ratings, and other program metrics
Issue Management and Remediation Tracking
- Create and manage risk issues, findings, remediation tasks, and follow-up actions related to third-party assessments or monitoring activities
- Partner with vendors, business owners, Procurement, Legal, Information Security, Privacy, Compliance, Business Continuity, and other stakeholders to clarify findings, obtain evidence, agree remediation plans, and track items to closure
- Escalate material, overdue, repeat, or high-risk issues in accordance with program procedures and management reporting expectations
- Validate remediation evidence and update ServiceNow records to reflect issue status, risk decisions, risk acceptance, closure rationale, or escalation path
Ongoing Monitoring and Reporting
- Support ongoing monitoring of third-party relationships by reviewing periodic assessment results, performance indicators, control reports, issue trends, incident signals, regulatory changes, and other relevant risk information
- Maintain third-party inventory, assessment schedules, documentation repositories,
and reporting inputs to support program governance and management oversight
- Identify trends, recurring control gaps, process bottlenecks, and opportunities to improve assessment quality, cycle time, reporting, and stakeholder experience
Stakeholder Coordination and Program Support
- Serve as a day-to-day point of contact for third-party risk assessment status, ServiceNow workflow questions, due diligence evidence, issue follow-up, and reporting needs
- Translate technical, security, compliance, and operational risk findings into practical business language for non-technical stakeholders
- Contribute to process documentation, playbooks, training materials, workflow improvements, and ServiceNow enhancement requests that improve the effectiveness of the TPRM program
Knowledge, Skills, And Abilities
- Solid understanding of vendor and third-party risk management concepts, including inherent risk, residual risk, control effectiveness, compensating controls, remediation, risk acceptance, and ongoing monitoring
- Ability to evaluate vendor documentation and convert assessment results into clear risk statements, practical recommendations, and actionable remediation plans
- Practical knowledge of ServiceNow workflows for questionnaires, assessments, tasks, issues, dashboards, reporting, and record maintenance
- Strong stakeholder management skills, including the ability to coordinate across business owners, vendors, Procurement, Information Security, Privacy, Compliance, and other control functions
- Excellent written communication skills, attention to detail, and ability to prepare concise assessment summaries, management updates, and audit-ready documentation
- Ability to prioritize work, manage multiple assessments, follow up on open items, and escalate issues appropriately in a fast-paced environment
📌 Third Party Risk Management (Bengaluru)
🏢 Promaynov Advisory Services
📍 Bengaluru