08 Sep
|
Pinnacle Group
|
Mumbai
08 Sep
Pinnacle Group
Mumbai
Job Description
We're looking for someone who has the background in third-party risk, technology risk, information security, or GRC appears relevant to a Third-Party Risk Analyst chance with Pinnacle Group. The role involves owning vendor risk assessments, evaluating cybersecurity and compliance controls, supporting SOC 2 and ISO 27001 requirements, and addressing emerging risks associated with AI-enabled products. This is a strong opportunity for someone interested in taking broad ownership of a third-party risk program and growing into a future leadership role. Would you be open to a brief conversation to explore the position? Job Title: Third-Party Risk Analyst (Technology/AI Risk) Location: Remote Condensed Job Description: Own third-party risk assessments across the complete vendor lifecycle Evaluate SaaS, cloud,
managed-service, software, and AI-enabled vendors Review SOC 1, SOC 2, ISO 27001, penetration-testing, privacy, and BCP documentation Identify technology risks and communicate practical mitigation recommendations Coordinate with auditors, vendors, Information Security, Legal, Compliance, and business teams Support ISO 27001 certification maintenance and SOC 2 compliance Prepare risk summaries, dashboards, governance reports, and audit-ready documentation Develop AI-risk standards and strengthen business-continuity procedures Use Drata or comparable governance, risk, and compliance platforms
📌 Third-Party Risk Analyst (Mumbai)
🏢 Pinnacle Group
📍 Mumbai