Third Party Risk Management | GRC Analyst (Thane)

Third Party Risk Management | GRC Analyst (Thane)

10 Sep
|
RethinkingWeb
|
Thane

10 Sep

RethinkingWeb

Thane

We are looking for a Third-Party Risk Management (TPRM) Associate to support the assessment, monitoring, and management of risks arising from vendors, suppliers, service providers, technology partners, and other third parties.
The role will involve working with business, procurement, information security, legal, privacy, and compliance teams to evaluate third-party risks and ensure that vendors meet the organization's security, privacy, regulatory, and contractual requirements.
The ideal candidate should have hands-on experience with vendor risk assessments, information security questionnaires, due diligence, risk analysis, compliance frameworks, and remediation tracking.
Key Responsibilities1. Third-Party Due Diligence
Conduct initial and periodic risk assessments of third parties and vendors.
Review vendor security and compliance documentation during onboarding and renewal.
Evaluate vendor responses to security questionnaires such as SIG, CAIQ, VSAQ, and customized information security questionnaires.
Review certifications and independent assurance reports including SOC 1, SOC 2, ISO 27001,



PCI DSS, and relevant regulatory certifications.
Identify gaps, exceptions, and areas requiring additional investigation.
2. Risk Assessment & Analysis
Assess third-party risks across areas such as:
Information security
Data privacy
Business continuity
Cybersecurity
Regulatory compliance
Data handling and access
Subcontractor / fourth-party risk
Operational resilience
Assign risk ratings based on defined organizational methodologies.
Document identified risks, control gaps, and compensating controls.
Recommend appropriate remediation actions and risk treatments.
3. Vendor Monitoring
Support ongoing monitoring of high- and critical-risk vendors.
Track changes in vendor risk profiles, certifications, security incidents, and regulatory compliance.
Monitor remediation plans and ensure closure of identified findings within agreed timelines.
Escalate overdue or significant risks to a

📌 Third Party Risk Management | GRC Analyst (Thane)
🏢 RethinkingWeb
📍 Thane

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: third party risk management | grc analyst (thane) / thane

Subscribe to this job alert:

Get the latest job offers by email for: third party risk management | grc analyst (thane) / thane