03 Sep
|
FinThrive
|
Gurugram
03 Sep
FinThrive
Gurugram
Role & responsibilities
- Third Party Security Risk Management
- Execute and mature the day-to-day TPRM program, including risk-based vendor tiering aligned to data sensitivity, criticality, and regulatory obligations.
- Perform vendor security assessments using questionnaires and evidence (SIG, CAIQ, custom) and review assurance artifacts such as SOC 2 Type II, ISO 27001, HITRUST, PCI, and pen test results.
- Document findings, drive remediation to closure, and manage time-bounded risk acceptances and exceptions.
- Support continuous monitoring (security ratings, attestation refresh) and secure vendor offboarding.
- Partner with Legal and Procurement to embed security requirements in contracts (security addendums, DPAs, breach notification, right to audit).
- Customer Security Inquiries
- Manage and respond to customer security questionnaires, RFPs, and due diligence requests.
- Maintain a repository of standardized responses and supporting documentation to enable cross-functional team independence.
- Translate complex security concepts into customer-friendly language and represent FinThrives security posture to prospects and customers.
- Cross-Functional Collaboration & Tooling
- Work closely with IT, Engineering, Product, and Sales to ensure timely, accurate completion of both vendor and customer reviews.
- Implement and manage tools (e.g., Whistic, Vanta, security ratings platforms) to streamline and automate inquiry and assessment workflows.
- Produce metrics and dashboards covering vendor risk posture, remediation aging, inquiry volume, and SLA performance.
- Product,
Infrastructure & Compliance Knowledge
- Maintain a solid understanding of FinThrives products, SaaS architecture, data flows, and security controls.
- Support FinThrives Audit and Compliance program by aligning activities to HITRUST, HIPAA, SOC 2, NIST, and ISO 27001 requirements.
Preferred candidate profile
- 1-3 years of relevant experience in information security, third party risk management, GRC, or due diligence response.
- Experience responding to customer security questionnaires and assessing vendor security posture against frameworks (SOC 2, HIPAA, ISO 27001).
- Working knowledge of security control domains: IAM, vulnerability management, encryption, logging/monitoring, incident response, and data handling.
- Familiarity with IT infrastructure (servers, firewalls, load balancers, databases), SaaS architecture, and web applications.
- Strong written and verbal communication skills, with the ability to explain technical
- concepts to non-technical audiences.
- Customer-centric mindset with experience collaborating with Sales teams and customers.
- Proficiency with Microsoft Office (Word, Excel, PowerPoint, Visio).
- Bachelors degree (IT, Information Security, or Business Administration preferred).
- Preferred Skills
- Security+ or similar certification.
- Familiarity with HITRUST, NIST, PCI DSS, and GDPR/CCPA.
- Experience with Trust Center, questionnaire management, and continuous monitoring platforms (SafeBase, Whistic, Vanta).
• Familiarity with cloud provider assurance models (AWS/Azure/GCP shared responsibility) and SaaS risk patterns.
📌 Associate Cybersecurity Risk Analyst (Gurugram)
🏢 FinThrive
📍 Gurugram