Job Title:  Assistant Manager | Risk Management | Pune | Cyber Strategy & Transformation

Job Description – Cybersecurity Assessment | Third-Party Risk Management (TPRM)

 

Role Overview

We are looking for cybersecurity professionals to support Third-Party Risk Management (TPRM) activities, with a focus on assessing the cybersecurity posture of third-party suppliers, identifying risks and control gaps, and driving remediation in line with organizational policies and regulatory requirements.

 

Key Responsibilities

  • Perform cybersecurity risk assessments of third-party suppliers across areas such as information security, infrastructure security, application security, data protection, IAM, vulnerability management, incident management, BCP/DR and cloud security.
  • Review and evaluate supplier responses to security questionnaires and assessment frameworks against defined control requirements.
  • Analyze supporting evidence such as SOC 1/SOC 2 reports, ISO 27001 certificates, penetration testing reports, policies, vulnerability reports, business continuity documentation and security assessments.
  • Identify control gaps, cybersecurity risks and potential areas of exposure; assess the inherent and residual risk associated with third parties.
  • Validate remediation plans and track open findings/issues through to closure.
  • Support risk-based decision making, including identification of compensating controls, risk acceptance and remediation requirements.
  • Perform assessments of third parties providing critical, high-risk or technology-enabled services.
  • Document assessment results, risk ratings, findings and recommendations in TPRM platforms/tools.
  • Engage with third-party stakeholders and internal teams to obtain clarifications, evidence and remediation updates.
  • Support escalation and reporting of overdue or high-risk findings to relevant stakeholders.
  • Contribute to continuous improvement of TPRM assessment methodologies, processes, control frameworks and assessment templates.
  • Support regulatory and audit requirements related to third-party cybersecurity and operational resilience.

 

Required Skills & Experience

  • 5–10 years of experience in Cybersecurity, Information Security, IT Risk, Technology Risk or Third-Party Risk Management.
  • Hands-on experience in conducting TPRM / third-party cybersecurity assessments.
  • Good understanding of cybersecurity domains including:
  • Information Security Governance
  • IAM / Privileged Access Management
  • Vulnerability & Patch Management
  • Network & Infrastructure Security
  • Application / SDLC Security
  • Data Protection & Privacy
  • Cloud Security
  • Security Monitoring & Incident Response
  • Business Continuity & Disaster Recovery
  • Cryptography and Key Management
  • Experience assessing third parties against frameworks such as ISO 27001, NIST CSF, CIS Controls, SOC 2, PCI DSS or similar standards.
  • Ability to interpret SOC reports, audit reports, penetration testing reports and security certifications.
  • Strong understanding of risk assessment methodologies, control testing and risk rating approaches.
  • Strong analytical, documentation and stakeholder management skills.
  • Ability to independently manage multiple assessments and meet defined SLA / turnaround requirements.

Preferred Qualifications

  • Certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer or equivalent.
  • Experience working with TPRM/GRC platforms.
  • B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field

  • Experience in financial services / banking / insurance environments.
  • Knowledge of regulatory expectations around third-party risk and operational resilience.
  • Experience with cloud service provider and SaaS vendor assessments.

Key Competencies

  • Cybersecurity & Technology Risk
  • Third-Party Risk Management
  • Risk & Control Assessment
  • Evidence Analysis
  • Risk Rating & Remediation
  • Regulatory & Compliance
  • Stakeholder Management
  • Strong written and verbal communication
  • Analytical and problem-solving skills