03 Sep
|
HCLTech
|
Bengaluru
Role & responsibilities
- Driving the third-party risk management program to understand, evaluate and report on the risk exposure HCLTech as an organization has by virtue of using various vendors, their services and/or products to meet our business objectives.
- Contribute towards enhancing the VRM program to address the ever-evolving threat landscape posed by vendor partners including but not limited to the risk domains of Cyber Security, Regulatory Compliance, Data Privacy, ESG, Geo-Political, Financial, etc.
- Self-motivated to hit the ground running with strategic thinking acumen to not only execute the current program but take it to the next level in spirit of continuous improvement.
- Overseeing project management, governance, risk profiling and assessment of vendors at relevant stages of vendor life cycle.
- Acting as a Subject Matter Expert (SME) across key risk domains such as Information Security, Data Privacy, Business Continuity, Regulatory Compliance, etc.
- Identifying applicable risk domains based on vendor service scope, including emerging risk areas.
- Conducting and reviewing vendor risk assessments based on the defined VRM framework.
- Developing risk profiles and periodic assessment plans based on third-party risk categorization.
- Collaborating with vendors to define appropriate remediation and mitigation strategies for identified risks.
- Performing ongoing monitoring, updating risk profiles, and tracking remediation efforts.
- Reviewing and enhancing risk assessment questionnaires and tools.
- Cross collaboration with internal stakeholders and external vendors to ensure program alignment and risk mitigation.
- Generating and presenting reports to leadership and cross-functional teams.
- Supporting queries from clients, business units, and sales / pre-sales teams related to vendor risk posture.
- Present VRM program and its tenets in various audits (internal & external) to provide assurance that third party risk is well managed within the firm.
Preferred candidate profile
- 12-15 years of overall experience in Information Security, Cybersecurity, and Risk Management.
- Minimum 8-10 years of hands-on experience in Vendor Risk Management / Third-Party Risk Management.
- Minimum 5 years of experience in team or people management.
- Ability to analyse the data and create various reports for senior management
- Solid understanding of Data Privacy Regulations (e.g., GDPR, CCPA), Cloud Security, and Business Continuity Planning.
- Proficiency in risk assessment methodologies and frameworks.
- Advanced proficiency in MS Office Suite (Word, Excel, PowerPoint, Outlook).
- Strong analytical, decision-making, and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to mentor and coach junior team members.
- Strong organizational and time management abilities.
- Self-driven, with a proactive and team-oriented mindset.
- Willingness to work in a global, cross-functional environment and adjust to flexible hours when needed.
- Prior experience with tools like Process Unity or Service Now is a plus
📌 Senior Manager - VRM (Bengaluru)
🏢 HCLTech
📍 Bengaluru