02 Oct
|
Millennium Consulting
|
Bengaluru
02 Oct
Millennium Consulting
Bengaluru
Information Security Risk Specialist Responsibilities
- Perform security risk assessments of prospective and existing vendors, covering questionnaire review, evidence validation, technical discussions, and identification of fourth-party and subprocessor dependencies
- Assess the materiality and business impact of findings, identify compensating controls, and present recommendations and residual risk for remediation or risk acceptance
- Draft clear, decision-ready risk assessment reports and maintain the third-party risk inventory and assessment records
- Communicate findings and implementation requirements to technical teams, business stakeholders, and senior leaders
- Track and drive remediation of security gaps and implementation requirements identified during assessments
- Partner with vendor management, procurement, legal, and business teams to embed security requirements into vendor contracts and onboarding
- Monitor security incidents and adverse news affecting existing vendors, engaging them directly to assess impact, root cause, and corrective measures
- Strengthen the program through improvements to methodology, questionnaires, monitoring, reporting, quality assurance, and automation
Requirements
- Experience conducting vendor and third-party security risk assessments, including familiarity with common security frameworks, standards, and assessment questionnaires (e.g., NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, CAIQ); 5+ years of hands-on third-party risk management experience preferred
- Ability to analyze penetration-test reports and architecture and data-flow diagrams to assess vulnerability severity, connectivity, trust boundaries, and associated security risks
- Strong critical thinking and risk judgment, with the ability to weigh materiality, business impact, and compensating controls
- Excellent written and verbal communication skills, with the ability to translate technical issues into risk and business impact for deeply technical teams and senior executive stakeholders alike
- Ability to manage multiple assessments and deadlines concurrently, work independently, escalate appropriately, and operate effectively in a fast-paced, high-stakes environment
Qualifications
- Bachelor's degree or higher in Computer Science, Computer Engineering, Cybersecurity/Information Security, or a related field, or commensurate work experience; relevant certifications such as CTPRP, CTPRA, CISA, or CISSP preferred
- Preferred: robust understanding of technology fundamentals across on-premises and cloud infrastructure, with hands-on experience spanning design, deployment, and operations, plus working proficiency across Windows, Linux, and macOS environments
- Preferred: experience with the secure use, deployment, and governance of AI models, tools, and supporting infrastructure such as GPUs and inferencing workloads; familiarity with TPRM platforms and reporting/automation tooling (e.g., Python, Excel/VBA); and experience in financial services, particularly hedge funds or other buy-side firms, or another highly regulated industry
📌 Information Security Risk Specialist (Bengaluru)
🏢 Millennium Consulting
📍 Bengaluru