
Information Security/Vendor Risk Manager
4 days ago
Description :Position : Information Security & Vendor Risk ManagerWork Level : Middle ManagementIndustry Type : IT Services & ConsultingLocation : IndiaJob Summary :The Information Security & Vendor Risk Manager will operate at a middle management level, serving as a key driver of the organization's Third-Party Risk Management (TPRM) program. This self-motivated and results-driven role requires deep technical expertise in cybersecurity frameworks, cloud security, and compliance standards (e.g., PCI-DSS, ISO 27001). The manager will be responsible for developing the TPRM framework, conducting end-to-end technical security assessments of third parties, and leading risk mitigation advisory and reporting to senior management to ensure compliance and security assurance across all vendor engagements.Job Description :TPRM Program Management and Governance :- Develop, implement, and continuously mature the organizations holistic Third-Party Risk Management (TPRM) framework, ensuring alignment with global standards, industry best practices, and internal risk appetite.- Define and maintain technical policies, procedures, and rigorous guidelines governing the lifecycle of third-party engagements, from initial due diligence to secure offboarding.- Drive program initiatives with a results-driven mindset, focusing on quantifiable metrics for risk reduction and operational efficiency across the TPRM function.Risk Assessment and Technical Due Diligence :- Conduct comprehensive, end-to-end technical security assessments and due diligence reviews of vendors throughout the entire lifecycle, evaluating system configurations, security controls, and overall operational effectiveness.- Technically assess and recommend compensating controls across various domains, including Network, Server, and Endpoint Security controls, as well as data protection mechanisms for sensitive information like PII and Cardholder Data.- Expertly evaluate and validate security posture across multi-cloud environments, specifically reviewing configurations and security controls within AWS, Azure, GCP, and OCI.- Review vendor compliance against rigorous digital payments standards, including PCI-DSS, PCI-PIN, and PA-DSS, ensuring technical control validation is performed where applicable.- Conduct technical control verification, including analyzing Vulnerability Assessment and Penetration Testing (VAPT) reports and assessing the effectiveness of Security Information and Event Management (SIEM) capabilities in vendor environments.Continuous Monitoring and Risk Mitigation Advisory :- Establish and operationalize robust processes for continuous monitoring and periodic technical reassessments of third-party security and compliance posture using automated tools and manual deep-dive reviews.- Identify latent and emerging security risks in third-party engagements, translating potential vulnerabilities into actionable, business-focused mitigation strategies for internal stakeholders.- Provide expert advisory and technical guidance on security control implementation, leveraging security-by-design principles for data protection and API security during new third-party integrations.- Act as a technical liaison with business partners to ensure timely and effective implementation of recommended security controls and regulatory assurance in the digital payments ecosystem.Reporting, Compliance, and Stakeholder Engagement :- Lead audit planning and collaborate with assurance teams to analyze control effectiveness, review reports, and present clear, data-driven findings on the overall third-party risk posture to C-level executives and senior management.- Partner with internal teams (Legal, Procurement, IT, CISO) to champion an integrated and streamlined approach to TPRM across the organization.- Ensure all third-party engagements maintain continuous compliance with relevant local and international laws, regulations, and industry standards.- Validate adherence to recognized international security frameworks, including ISO 27001 (ISMS), SOC Reports, and the NIST Cybersecurity Framework.Required Skills & Qualifications :- Experience : Mandatory experience working within Information Security or GRC, with significant focus on Vendor/Third-Party Risk Management.- Framework Expertise : Deep practical knowledge of major Cybersecurity Frameworks (e.g., NIST, ISO 27001) and regulatory compliance standards (PCI-DSS, SOC 2).- Risk Analysis : Proven experience performing quantitative and qualitative Risk Analysis and technical due diligence assessments (e.g., control gap analysis, analyzing VAPT reports).- Cloud Security : Strong technical understanding of security controls and architecture across at least two major cloud platforms (AWS, Azure, GCP, OCI).- Tooling : Practical experience utilizing SIEM solutions and understanding endpoint security technologies to evaluate a vendor's defensive capabilities.- Core Skills : Self-Motivated, result-driven, exceptional problem-solving abilities, and strong written/verbal communication for effective stakeholder engagement.- Education : Mandatory Graduate degree.Preferred Skills :- Digital Payments : Direct experience with regulatory and security requirements within the digital payments ecosystem (e.g., payment gateways, tokenization, mobile wallets).- Certifications : Industry-leading certifications such as CISSP, CISM, CRISC, or CISA are highly advantageous.- Automation : Experience implementing or utilizing GRC/TPRM automation platforms (e.g., OneTrust, ServiceNow GRC) to streamline assessment workflows and continuous monitoring.- API Security : Technical knowledge of best practices for securing APIs (e.g., OAuth 2.0, API Gateway configuration, rate limiting).- Contract Review : Basic familiarity with reviewing security schedules and terms within third-party contracts and Statements of Work (SOWs). (ref:hirist.tech)
-
Information Security/Vendor Risk Manager
3 days ago
Mumbai, Maharashtra, India Workassist Full time ₹ 12,00,000 - ₹ 36,00,000 per yearDescription : Position : Information Security & Vendor Risk Manager Work Level : Middle Management Industry Type : IT Services & Consulting Location : IndiaJob Summary : The Information Security & Vendor Risk Manager will operate at a middle management level, serving as a key driver of the organization's Third-Party Risk Management (TPRM)...
-
IT Security/Privacy Vendor Manager
4 weeks ago
Mumbai, India Talent Leads Full timeDescription :Role : Security and Privacy Vendor ManagerThe Security and Privacy Vendor Manager reports into the Chief Information Security Officer (CISO) and is accountable and responsible, on a global basis, for all Security and Privacy vendors for Company.Your Role :The Security and Privacy Vendor Manager is responsible for managing relationships with...
-
Vendor Risk Operations
4 days ago
Mumbai, Maharashtra, India Paytm Full time**About Us**: Paytm is India's leading mobile payments and financial services distribution company. Pioneer of the mobile QR payments revolution in India, Paytm builds technologies that help small businesses with payments and commerce. Paytm’s mission is to serve half a billion Indians and bring them to the mainstream economy with the help of technology....
-
Vendor Management and Risk
3 weeks ago
Mumbai, India Orcapod Consulting Services Full timeThis role is on contract basis for 1 year extendible and convertible both based on performance. Please apply only if interested. Primary Responsibilities Position Description: Risk/3rd party monitoring and reporting for Investment Management Operations. This position would also require the individual to work closely with functional teams in our international...
-
Vendor Management and Risk
2 weeks ago
Mumbai, Maharashtra, India Orcapod Consulting Services Full time ₹ 20,00,000 - ₹ 25,00,000 per yearThis role is on contract basis for 1 year extendible and convertible both based on performance. Please apply only if interested.Primary ResponsibilitiesPosition Description:Risk/3rd party monitoring and reporting for Investment Management Operations. This position would also require the individual to work closely with functional teams in our international...
-
Navi Mumbai, Maharashtra, India HDB Financial Services Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJOB ROLEEstablish and lead end-to-end baseline governance framework for vendor risk assessment program, identify areas of potential exposure, develop and align vendor risk management strategies with organizations goals and objectives, and execute program-ensuring consistency. Supporting in other areas of Compliance & Governance in-line with the regulatory...
-
GRC Analyst
3 weeks ago
Mumbai, India PINKVILLA Full timePinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring third-party security risks are effectively identified and mitigated.Key ResponsibilitiesGovernance, Risk & Compliance (GRC)Develop, implement, and maintain information...
-
Grc analyst
3 weeks ago
Mumbai, India PINKVILLA Full timePinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring third-party security risks are effectively identified and mitigated. Key Responsibilities Governance, Risk & Compliance (GRC) Develop, implement, and maintain...
-
Information technology: Risk Management
1 week ago
Mumbai, India Skynet Secure Full timeCompany Description SKYNET SECURE is a company founded by Sachin Dedhia. One of its main objective is to promote cyber crime & internet security awareness across all sections of the society. We provide assistance & also help in solving all kinds of cyber crime related cases. Job Description Information technology : Risk Management & compliance 1) We...
-
Information technology: Risk Management
1 week ago
Mumbai, India Skynet Secure Full timeCompany Description SKYNET SECURE is a company founded by Sachin Dedhia. One of its main objective is to promote cyber crime & internet security awareness across all sections of the society. We provide assistance & also help in solving all kinds of cyber crime related cases. Job Description Information technology : Risk Management & compliance 1) We need...