Job Title: Assistant Manager | Risk Management | Pune | Cyber Strategy & Transformation
Job Description – Cybersecurity Assessment | Third-Party Risk Management (TPRM)
Role Overview
We are looking for cybersecurity professionals to support Third-Party Risk Management (TPRM) activities, with a focus on assessing the cybersecurity posture of third-party suppliers, identifying risks and control gaps, and driving remediation in line with organizational policies and regulatory requirements.
Key Responsibilities
- Perform cybersecurity risk assessments of third-party suppliers across areas such as information security, infrastructure security, application security, data protection, IAM, vulnerability management, incident management, BCP/DR and cloud security.
- Review and evaluate supplier responses to security questionnaires and assessment frameworks against defined control requirements.
- Analyze supporting evidence such as SOC 1/SOC 2 reports, ISO 27001 certificates, penetration testing reports, policies, vulnerability reports, business continuity documentation and security assessments.
- Identify control gaps, cybersecurity risks and potential areas of exposure; assess the inherent and residual risk associated with third parties.
- Validate remediation plans and track open findings/issues through to closure.
- Support risk-based decision making, including identification of compensating controls, risk acceptance and remediation requirements.
- Perform assessments of third parties providing critical, high-risk or technology-enabled services.
- Document assessment results, risk ratings, findings and recommendations in TPRM platforms/tools.
- Engage with third-party stakeholders and internal teams to obtain clarifications, evidence and remediation updates.
- Support escalation and reporting of overdue or high-risk findings to relevant stakeholders.
- Contribute to continuous improvement of TPRM assessment methodologies, processes, control frameworks and assessment templates.
- Support regulatory and audit requirements related to third-party cybersecurity and operational resilience.
Required Skills & Experience
- 5–10 years of experience in Cybersecurity, Information Security, IT Risk, Technology Risk or Third-Party Risk Management.
- Hands-on experience in conducting TPRM / third-party cybersecurity assessments.
- Good understanding of cybersecurity domains including:
- Information Security Governance
- IAM / Privileged Access Management
- Vulnerability & Patch Management
- Network & Infrastructure Security
- Application / SDLC Security
- Data Protection & Privacy
- Cloud Security
- Security Monitoring & Incident Response
- Business Continuity & Disaster Recovery
- Cryptography and Key Management
- Experience assessing third parties against frameworks such as ISO 27001, NIST CSF, CIS Controls, SOC 2, PCI DSS or similar standards.
- Ability to interpret SOC reports, audit reports, penetration testing reports and security certifications.
- Strong understanding of risk assessment methodologies, control testing and risk rating approaches.
- Strong analytical, documentation and stakeholder management skills.
- Ability to independently manage multiple assessments and meet defined SLA / turnaround requirements.
Preferred Qualifications
- Certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer or equivalent.
- Experience working with TPRM/GRC platforms.
-
B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field
- Experience in financial services / banking / insurance environments.
- Knowledge of regulatory expectations around third-party risk and operational resilience.
- Experience with cloud service provider and SaaS vendor assessments.
Key Competencies
- Cybersecurity & Technology Risk
- Third-Party Risk Management
- Risk & Control Assessment
- Evidence Analysis
- Risk Rating & Remediation
- Regulatory & Compliance
- Stakeholder Management
- Strong written and verbal communication
- Analytical and problem-solving skills