28 Sep
|
Allegis Group
|
Bengaluru
28 Sep
Allegis Group
Bengaluru
We are looking for Immediate joiners only or candidates serving notice less than 15 days
Location : Bangalore
Shift : General Shift
Work Mode : Hybrid
Senior Analyst Third Party Cyber Security Evaluations
Role: Assess and monitor information security controls of third-party vendors, ensuring risks are identified, rated, and reported to stakeholders.
What You'll Do
- Assess third-party IT infrastructure, applications, and security programs
- Run remote security assessments (questionnaires, reports, security plans)
- Review SOC2, SIG, PCI DSS, and similar certifications for risk red flags
- Perform gap analysis against control frameworks (ISO 27001/27002, NIST, PCI DSS, etc.) to identify control deficiencies
- Evaluate residual risk after compensating controls and assign risk ratings for identified gaps
- Recommend remediation plans and risk treatment options (accept, mitigate, transfer) based on residual risk levels
- Write clear assessment reports for stakeholders
- Act as lead on third-party assessments, working with global teams
- Spot trends in security findings and present them to leadership
- Keep assessments moving and closed on schedule
Must-Haves
- 5+ years in Information Security GRC
- 4+ years in Third-Party/Cyber Security Assessments
- Hands-on experience conducting gap analysis and residual risk assessments in a TPRM context
- Bachelor's/Master's in Computer Science or Information Systems
- Familiarity with ISO 27001/27002, PCI DSS, COBIT, NIST, GLBA, GDPR
- Solid writing, communication, and analytical skills
- Solid grasp of security domains, IT systems, and operational risk
- Confidence presenting to varied audiences
📌 Information Security Analyst (TPRM & Vendor Risk Management) (Bengaluru)
🏢 Allegis Group
📍 Bengaluru