
| Location: | Bengaluru |
| Openings: | 1 |
| Salary Range: |
Description:
Role Purpose
The GRC Specialist is responsible for assessing, managing, and mitigating risks associated with third-party
vendors and service providers. Implement security best practices, policies, and controls through a repeatable
process. This role involves conducting thorough security evaluations of potential and existing vendors,
conducting regular security awareness trainings, and phishing campaigns, design and implementation of KPI’s,
KRI’s, enhancing our internal policies and procedures.
Roles & Responsibilities
➢ Enhance existing security policies, controls and procedures and conduct annual certifications.
➢ Assist to operationalize the GRC tool and identify areas of improvement.
➢ Develop and maintain a vendor risk management framework and supporting documentation.
➢ Conduct detailed risk assessments, identify potential security risks associated with third-party vendors
by reviewing and analyzing security policies, controls, and procedures.
➢ Get to know the business side, meet with owners and vendors, while identifying opportunities to
improve ease of vendor management.
➢ Collaborate with legal, and other departments to ensure that security requirements are included in
contracts and service level agreements (SLAs).
➢ Collaborate and coordinate with other Security groups, IT Operations, and other teams on audits,
assessments and GRC control recommendations.
➢ Monitor and evaluate changes in vendor services or operations that may impact the organization's
security posture.
➢ Provide guidance and recommendations to internal stakeholders regarding security risks and controls.
➢ Publish and collaborate outside vulnerability and threats. Stay current with industry best practices,
regulatory requirements, and emerging threats related to third-party engagements.
➢ Maintain Security Awareness, Compliance programs, Risk register.
➢ Generate KPI’s and KRI’s for the security team.
Skills & Qualifications
➢ Minimum of 10 years of experience in information security, with a focus on third-party/vendor risk
management.
➢ Strong understanding of information security principles, frameworks (e.g., NIST, ISO 27001, SOC 2 Type
2), and regulations (e.g., GDPR, HIPAA).
➢ Experience with risk assessment methodologies and tools.
➢ Excellent analytical and critical thinking skills, with the ability to manage complex projects.
➢ Proficient communication skills, both written and verbal, with the ability to explain technical concepts to non-technical stakeholders.
➢ Detail-oriented with strong organizational skills.
➢ Ability to work independently as well as collaboratively within a team environment.
➢ Bachelor’s degree in information technology, Cybersecurity, or a related field; or equivalent work
experience.
➢ Relevant professional certifications, such as CISM, CRISC, or CISA are preferred.