Third Party Risk Management | GRC Analyst (Thane)

Third Party Risk Management | GRC Analyst (Thane)

11 Sep
|
RethinkingWeb
|
Thane

11 Sep

RethinkingWeb

Thane

We are looking for a Third-Party Risk Management (TPRM) Associate to support the assessment, monitoring, and management of risks arising from vendors, suppliers, service providers, technology partners, and other third parties.

The role will involve working with business, procurement, information security, legal, privacy, and compliance teams to evaluate third-party risks and ensure that vendors meet the organization's security, privacy, regulatory, and contractual requirements.

The ideal candidate should have hands-on experience with vendor risk assessments, information security questionnaires, due diligence, risk analysis, compliance frameworks, and remediation tracking.

Key Responsibilities1. Third-Party Due Diligence

- Conduct initial and periodic risk assessments of third parties and vendors.
- Review vendor security and compliance documentation during onboarding and renewal.
- Evaluate vendor responses to security questionnaires such as SIG, CAIQ, VSAQ, and customized information security questionnaires.
- Review certifications and independent assurance reports including SOC 1, SOC 2, ISO 27001, PCI DSS, and relevant regulatory certifications.
- Identify gaps, exceptions, and areas requiring additional investigation.

2. Risk Assessment & Analysis
- Assess third-party risks across areas such as:
- Information security
- Data privacy
- Business continuity
- Cybersecurity
- Regulatory compliance
- Data handling and access
- Subcontractor / fourth-party risk
- Operational resilience
- Assign risk ratings based on defined organizational methodologies.
- Document identified risks, control gaps, and compensating controls.
- Recommend appropriate remediation actions and risk treatments.

3. Vendor Monitoring
- Support ongoing monitoring of high- and critical-risk vendors.
- Track changes in vendor risk profiles, certifications, security incidents, and regulatory compliance.
- Monitor remediation plans and ensure closure of identified findings within agreed timelines.
- Escalate overdue or significant risks to appropriate stakeholders.





4. Documentation & Reporting
- Maintain accurate and up-to-date vendor risk records.
- Prepare risk assessment reports and management summaries.
- Maintain evidence supporting vendor assessments and approvals.
- Develop dashboards and periodic reports covering:
- Vendor risk ratings
- Assessment status
- Open findings
- Remediation status
- High-risk / critical vendors
- Exceptions and risk acceptances

5. Stakeholder Management
- Coordinate with Procurement, Legal, IT, Information Security, Privacy, Business Owners, and vendors.
- Communicate assessment requirements and follow up for pending information.
- Participate in vendor onboarding, renewal, and offboarding processes.
- Support risk committees and governance meetings where required.

6. Compliance & Frameworks
- Support TPRM activities aligned with applicable regulatory requirements and industry standards.
- Assist in mapping third-party controls against frameworks such as:
- ISO 27001
- NIST CSF
- NIST 800-53
- SOC 2
- PCI DSS
- CIS Controls
- GDPR
- India's DPDP Act
- Keep track of changes in relevant security, privacy, and regulatory requirements.

7. Incident & Exception Management
- Support assessment of security incidents involving third parties.
- Assist in evaluating vendor notification, response, and remediation processes.
- Track risk exceptions and compensating controls.
- Escalate material third-party risks in accordance with organizational procedures.

Required Skills & Qualifications
- Bachelor's degree in Information Security, Cybersecurity, IT, Risk Management, Computer Science, or a related field.




- 2–4 years of experience in Third-Party Risk Management, GRC, Information Security, IT Risk, Vendor Risk, or Compliance.
- Understanding of information security and cybersecurity principles.
- Experience conducting or supporting vendor risk assessments.
- Ability to interpret SOC 2, ISO 27001, penetration testing reports, security questionnaires, and related evidence.
- Strong analytical and documentation skills.
- Good written and verbal communication skills.
- Ability to work with multiple stakeholders and manage assessment timelines.

Preferred Certifications

One or more of the following would be advantageous:

- CISA
- CRISC
- CISM
- CISSP
- ISO 27001 Lead Auditor / Lead Implementer
- Security+
- Certified Third Party Risk Qualified (CTPRP) or equivalent TPRM certification
- Privacy certifications such as CIPP/E, CIPP/US, CIPM, or equivalent

Tools & Technology

Exposure to GRC / TPRM platforms such as:

- ServiceNow GRC
- OneTrust
- Archer
- RSA Archer
- MetricStream
- LogicGate
- SecurityScorecard
- BitSight
- Whistic
- ProcessUnity

Working knowledge of Excel, PowerPoint, Power BI, and reporting/dashboard tools is desirable.

Key Competencies

- Risk-based thinking
- Analytical and critical thinking
- Attention to detail
- Vendor and stakeholder management
- Strong documentation
- Problem solving
- Communication and negotiation
- Ability to manage multiple assessments simultaneously
- Understanding of confidentiality and sensitive information
- Ability to work independently and as part of a cross-functional team

Key Performance Indicators

Success in this role will be measured through:

- Timely completion of vendor risk assessments
- Quality and accuracy of risk assessments
- Effective identification and classification of third-party risks
- Closure of vendor remediation items
- Compliance with TPRM processes and SLAs
- Quality of risk reporting and documentation
- Stakeholder and vendor responsiveness
- Reduction in overdue high-risk assessments and findings

📌 Third Party Risk Management | GRC Analyst (Thane)
🏢 RethinkingWeb
📍 Thane

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: third party risk management | grc analyst (thane) / thane