10 Oct
|
V3 Staffing
|
Secunderabad
10 Oct
V3 Staffing
Secunderabad
Manager – Third-Party Risk Management (TPRM)
Location: Hyderabad (Hybrid)
Experience: 10 to 14 years
Employment Type: Full-time
About the Role
We are hiring a Manager for Third-Party Risk Management (TPRM) to lead the vendor risk team at the Hyderabad GCC. You will run vendor security assessments, contract security reviews, continuous monitoring and risk reporting, and work directly with the Director of TPRM to grow the program.
This is a people leadership role with real decision-making ownership. You will be the go-to person for high-risk vendor decisions, audit requests and executive reporting.
What You Will Do
- Lead, coach and grow a team of TPRM analysts. Manage workload, quality and performance.
- Oversee vendor risk assessments, security questionnaires, due diligence and contract security reviews.
- Own risk decisions on high-risk vendors, including risk acceptance, exceptions, compensating controls and remediation plans.
- Track vendor remediation and run continuous monitoring across the third-party portfolio.
- Act as the main contact for internal and external audits on TPRM controls. Keep evidence audit-ready.
- Build and improve TPRM policies, standards, procedures and governance frameworks.
- Define assessment criteria for AI-enabled vendors with Legal, Privacy and Compliance teams.
- Build KPI and KRI dashboards and present vendor risk posture to senior leadership.
- Drive automation and tool improvements across the vendor risk lifecycle.
- Partner with Procurement, Legal, Privacy, Compliance, Internal Audit and Technology teams.
What We Are Looking For
- 10 to 14 years of total experience,
with at least 8 years in cybersecurity risk, IT GRC, information security governance or third-party risk management.
- 2 to 3 years of direct people management experience.
- Hands-on experience running or leading an enterprise TPRM or vendor risk management program.
- Solid knowledge of risk assessment methods and security control frameworks such as NIST CSF, ISO 27001, SOC 2, HIPAA, SIG and HITRUST.
- Experience preparing executive reporting, risk metrics and leadership presentations.
- Experience writing security policies, standards and governance processes.
- Clear communication with both technical teams and senior leadership.
- Bachelor's degree in Cybersecurity, IT, Computer Science or a related field.
Good to Have
- Certifications: CISSP, CISM, CRISC, CISA, CCSP or CCSK
- Experience with TPRM tools such as ServiceNow VRM, OneTrust, Archer, Prevalent, BitSight or SecurityScorecard
- Exposure to healthcare, BFSI or US regulated environments
- Understanding of AI governance and AI vendor risk
Why Join
- Global ownership from a fast-growing GCC in Hyderabad
- Work on healthcare and AI-driven technology at scale
- Health insurance for self, kids and parents, plus accident cover
- Learning and certification reimbursement
Skills
Third-Party Risk Management, Vendor Risk Management, IT Governance Risk and Compliance (GRC), Information Security Governance, Risk Assessment, Cybersecurity, ISO 27001, NIST, SOC 2, HIPAA, Vendor Due Diligence, Team Leadership
#TPRM #ThirdPartyRisk #VendorRiskManagement #CyberSecurityJobs #GRC #InfoSecJobs #HyderabadJobs #GCC #CISA #CRISC
📌 Cyber Security Manager (Secunderabad)
🏢 V3 Staffing
📍 Secunderabad