08 Oct
|
HCLTech
|
Hyderabad
Track Manager (Support & Operations)
Hyderabad, Telangana
Job Summary
Security GRC Analyst - Third Party Risk Management (TPRM) L3 Role Summary The Security GRC TPRM L3 Analyst serves as a senior subject matter expert responsible for leading the Third-Party Risk Management (TPRM) program, overseeing complex vendor risk assessments, driving governance initiatives, and ensuring compliance with organizational, regulatory, and industry security requirements. The role provides strategic guidance, manages high-risk vendor engagements, supports executive-level reporting, and contributes to the maturity and continuous improvement of the organization's third-party risk management framework. Experience Range 6-10 Years Required Skills Security & Technical Expertise • Advanced understanding of Information Security, Cyber Risk, and Enterprise Risk Management. • Robust knowledge of: o Cloud Security (Azure, AWS, GCP) o Identity and Access Management (IAM) o Data Security and Privacy o Network Security o Application Security o Vulnerability and Threat Management o Incident Response and Business Continuity • Ability to review: o SOC 1 / SOC 2 Reports o ISO 27001 Certifications o Penetration Test Reports o Security Architecture Reviews o Data Protection Assessments Vendor Control Matrices
Key Responsibilities
Key Responsibilities Third-Party Risk Governance & Oversight • Lead end-to-end third-party security risk assessments for critical and high-risk vendors. • Establish and maintain TPRM governance processes, standards, and assessment methodologies. • Oversee vendor onboarding, periodic reviews, contract renewals, and offboarding risk activities. • Review and approve risk assessments performed by junior analysts. • Drive continuous improvement initiatives to enhance the effectiveness of the TPRM program. Risk Assessment & Management • Perform in-depth analysis of vendor security, privacy, operational, cloud, and compliance risks. • Evaluate complex security architectures, data flows, and control environments. • Conduct inherent, residual, and emerging risk assessments. • Facilitate risk treatment, risk acceptance, and exception management processes. • Present risk recommendations to senior management and risk governance committees. Regulatory Compliance & Audit Support • Ensure alignment with regulatory and industry requirements, including: o ISO 27001 o NIST CSF o PCI-DSS o SOC 2 o GDPR o HIPAA o CIS Controls o DORA o NIS2 (where applicable) • Support internal, external, and regulatory audits. • Lead vendor compliance reviews and ensure audit readiness.
Skill Requirements
Security GRC Analyst - Third Party Risk Management (TPRM) L3
Other Requirements
Security GRC Analyst - Third Party Risk Management (TPRM) L3
📌 Track Manager (Support & Operations) (Hyderabad)
🏢 HCLTech
📍 Hyderabad