
| Location: | Bangalore |
| Openings: | 1 |
| Salary Range: |
Description:
• Minimum of 10 years of experience in information security, with a focus on third-party/vendor risk management.
• Strong understanding of information security principles, frameworks (e.g., NIST, ISO 27001, SOC 2 Type 2), and regulations (e.g., GDPR, HIPAA).
• Experience with risk assessment methodologies and tools.
• Excellent analytical and critical thinking skills, with the ability to manage complex projects.
• Proficient communication skills, both written and verbal, with the ability to explain technical concepts to non-technical stakeholders.
• Detail-oriented with strong organizational skills.
• Ability to work independently as well as collaboratively within a team environment.
• Enhance existing security policies, controls and procedures and conduct annual certifications.
• Assist to operationalize the GRC tool and identify areas of improvement.
• Develop and maintain a vendor risk management framework and supporting documentation.
• Conduct detailed risk assessments, identify potential security risks associated with third-party vendors by reviewing and analyzing security policies, controls, and procedures.
• Get to know the business side, meet with owners and vendors, while identifying opportunities to improve ease of vendor management.
• Collaborate with legal, and other departments to ensure that security requirements are included in contracts and service level agreements (SLAs).
• Collaborate and coordinate with other Security groups, IT Operations, and other teams on audits, assessments and GRC control recommendations.
• Monitor and evaluate changes in vendor services or operations that may impact the organization's security posture.
• Provide guidance and recommendations to internal stakeholders regarding security risks and controls.
• Publish and collaborate outside vulnerability and threats.
Stay current with industry best practices, regulatory requirements, and emerging threats related to third-party engagements.
• Maintain Security Awareness, Compliance programs, Risk register.
• Generate KPI’s and KRI’s for the security team.
ØEnhance existing security policies, controls and procedures and conduct annual certifications.
ØAssist to operationalize the GRC tool and identify areas of improvement.
ØDevelop and maintain a vendor risk management framework and supporting documentation.
ØConduct detailed risk assessments, identify potential security risks associated with third-party vendors by reviewing and analyzing security policies, controls, and procedures.
ØGet to know the business side, meet with owners and vendors, while identifying opportunities to improve ease of vendor management.
ØCollaborate with legal, and other departments to ensure that security requirements are included in contracts and service level agreements (SLAs).
ØCollaborate and coordinate with other Security groups, IT Operations, and other teams on audits, assessments and GRC control recommendations.
ØMonitor and evaluate changes in vendor services or operations that may impact the organization's security posture.
ØProvide guidance and recommendations to internal stakeholders regarding security risks and controls.
ØPublish and collaborate outside vulnerability and threats. Stay current with industry best practices, regulatory requirements, and emerging threats related to third-party engagements.
ØMaintain Security Awareness, Compliance programs, Risk register.
ØGenerate KPI’s and KRI’s for the security team.