IT Third Party and Client Security Assurance Analyst
4 weeks ago
**Work with Us. Change the World.**
At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world's most complex challenges and build legacies for future generations.
There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.
We're one global team driven by our common purpose to deliver a better world. Join us.
**Job Description**
The use of third parties is an essential element in AECOM's service delivery model and creates the need for management oversight and continuous monitoring of their security capabilities and performance. AECOM works with many third parties (e.g., vendors, partners, suppliers) each of which poses security, compliance and operational risks. AECOM is recruiting Third Party and Client Security Analysts to support the centralized Third Party and Client Risk Management Function.
In this role, the analyst is expected to support the framework, operating model and supervise processes to ensure: (1) third parties are compliant with AECOM's security standards and (2) that AECOM provides the same type of assurance to our clients that its security program is compliant with regulatory requirements, standards and client expectations.
**Responsibilities & Duties**
+ Evaluate requests for third party engagements
+ Conduct initial and periodic third-party risk assessments
+ Collaborate with business requestors, procurement, legal and other teams to ensure questionnaires are completed timely
+ Collaborate with security/IT team members to ensure a full understanding of security controls, technology and architecture
+ Review responses to security questionnaires, SOC 1 and SOC 2 assessment reports received from third parties to identify potential risk to AECOM
+ Identify gaps/issues based on third party and/or client standards relative to security postures
+ Devise remediation plans and monitor to ensure adherence by third parties and AECOM security/IT
+ Manage, enhance and implement the framework, policies, procedures and program governance to ensure alignment of TPRM with industry best practices and regulatory requirements (NIST, ISO27001, FedRamp, etc.)
+ Develop tactical and strategic plans to evolve the third-party risk management program to ensure compliance with new regulations and alignment with industry best practices
+ Triage/complete requests from AECOM clients regarding AECOM's control environment
+ Manage AECOM's response to existing and potential business partners/clients/third parties security due diligence (questionnaires, site visits, etc.)
+ Assistance with RFI/RFP processes and responses to client inquiries, ensuring comprehensive risk management throughout the process
+ Review third party and client contracts to validate appropriate security requirements and commitments
**Qualifications**
+ Bachelor's degree in information technology, Information Security, Risk Management or a related field
+ 2-3 years of career experience related to information security, IT, audit, third party and/or risk
+ Strong understanding of risk management principles and security frameworks (e.g., NIST, ISO 27001, SOC2, PCI-DSS)
+ Extensive experience in evaluating vendor security and compliance in relation to regulatory and industry standards.
+ Familiarity with industry GRC tools such as UpGuard, Audit Board, ServiceNow etc. is a plus/desirable
+ Strong prioritization and organizational skills
+ Ability to develop, document and maintain procedures
+ Strong verbal communication with the ability to advise management regarding third party and client risk management
+ Ability to work independently and collaborate with cross-functional teams
**Additional Information**
+ Ability to effectively communicate and collaborate within a specific group of internal and external customers. (Communication)
+ Ability to maintain good customer relationship with the ability to proactively support customer needs and requirements. (Customer Service)
+ Ability to be thorough and meticulous in completing assigned tasks and identifying errors, duplicates & discrepancies through defined methods. (Attention to Detail)
+ Ability to identify, assess and resolve simple to moderate issues by following defined policies and procedures. (Problem Solving)
**About AECOM**
AECOM is the world's trusted infrastructure consulting firm, delivering professional services throughout the project lifecycle - from advisory, planning, design and engineering to program and construction management. On projects spanning transportation, buildings, water, new energy and the environment, our public- and private-sector clients trust us to solve their most complex challenges. Our teams are driven by a common purpose to deliver a better world through our unrivaled technical and digital expertise, a culture of equity, diversity and inclusion, and a commitment to environmental, social and governance priorities. AECOM is a Fortune 500 firm and its Professional Services business had revenue of $14.4 billion in fiscal year 2023. See how we are delivering sustainable legacies for generations to come at aecom.com and @AECOM.
**Freedom to Grow in a World of Opportunity**
You will have the flexibility you need to do your best work with hybrid work options. Whether you're working from an AECOM office, remote location or at a client site, you will be working in a dynamic environment where your integrity, entrepreneurial spirit and pioneering mindset are championed.
You will help us foster a safe and respectful workplace, where we invite everyone to bring their whole selves to work using their unique talents, backgrounds and expertise to create transformational outcomes for our clients.
AECOM provides a wide array of compensation, benefits and well-being programs to meet the diverse needs of our employees and their families. We're the world's trusted global infrastructure firm, and we're in this together - your growth and success are ours too.
Join us, and you'll get all the benefits of being a part of a global, publicly traded firm - access to industry-leading technology and thinking and transformational work with big impact and work flexibility. As an Equal Opportunity Employer, we believe in each person's potential, and we'll help you reach yours.
All your information will be kept confidential according to EEO guidelines.
**ReqID:** J10125212
**Business Line:** Geography OH
**Business Group:** DCS
**Strategic Business Unit:** GBS
**Career Area:** Information Technology
**Work Location Model:** Hybrid
**Legal Entity:** AECOM India Global Services Private Limited
-
Third-Party Risk Management
4 weeks ago
Bengaluru, Karnataka, India People Prime Worldwide Private Limited Full timeJob DescriptionAbout Client:One of our MNC clients offers technology consulting and digital solutions to global enterprises across industries, enabling transformative scale at unparalleled speed. With 145,000+ professionals across 90+ countries helping 1100+ clients, it provides a full spectrum of services including consulting, information technology,...
-
Cyber Security Analyst
5 days ago
Bengaluru, Karnataka, India ITC Infotech Full timeJob Description – Security Assurance Analyst:The Security Assurance Analyst is responsible for day-to-day operations related to ISMS (Information Security Management System), external audits, internal audits, and user awareness program. He/She is responsible for documenting and updating policies, procedures, and security baselines to meet security...
-
Cyber Security Analyst
4 days ago
Bengaluru, Karnataka, India ITC Infotech Full timeJob Description – Security Assurance Analyst: The Security Assurance Analyst is responsible for day-to-day operations related to the Information Security Management System (ISMS), external audits, internal audits, and user awareness program. This person documents and updates policies, procedures, and security baselines to meet the security requirements of...
-
GRC - Third Party Cyber Risk Management
3 weeks ago
Bengaluru, Karnataka, India Live Connections Full timeExp : 10yrs to 16yrs Location : PAN INDIA Primary skills • Several years of IT Security Consulting Background• Experience in conducting IT security assessments or audits• ISO27001 Consulting experience in several assignments• Experience in Supplier Management, ideally Third-Party Cyber Risk Management• Seniority in communication with business...
-
GRC - Third Party Cyber Risk Management
3 weeks ago
Bengaluru, Karnataka, India Live Connections Full timeExp : 10yrs to 16yrs Location : PAN INDIA Primary skills • Several years of IT Security Consulting Background • Experience in conducting IT security assessments or audits • ISO27001 Consulting experience in several assignments • Experience in Supplier Management, ideally Third-Party Cyber Risk Management • Seniority in communication with...
-
Senior Third-Party Risk Manager
7 days ago
Bengaluru, Karnataka, India MUFG Global Service Full timeJob OverviewMUFG Global Service is a leading financial institution with a global network spanning over 40 markets. As a Senior Third-Party Risk Manager, you will play a critical role in developing and managing the end-to-end TPRM lifecycle, scope, and timelines. This includes collaborating with stakeholders to align the TPRM with business requirements and...
-
Security Operations Center Analyst
1 week ago
Bengaluru, Karnataka, India Novo Full timeWe are seeking a highly skilled SOC analyst to manage EDR, MDM, and ZTN systems and conduct third-party risk assessments while ensuring compliance with leading security frameworks. About the Role: - Lead the implementation, management, and optimization of critical security solutions, including Endpoint Detection and Response (EDR) tools, Mobile Device...
-
Third Party Risk Management
7 days ago
Bengaluru, Karnataka, India myGwork Full timeThis job is with State Street, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. Who we are looking for: State Street Global Advisors (SSGA) Vendor Management (VM) function is seeking to hire a...
-
Security Analyst – Compliance
4 weeks ago
Bengaluru, Karnataka, India Signzy Full timeJob Title: Security Analyst – Compliance & Audit Location: (Bangalore / Remote) Experience: 3-7 years Industry: Banking, Financial Services, Consulting Employment Type: Full-time Job Summary: We are seeking an experienced Security Analyst with a strong background in cybersecurity compliance, audit frameworks, and regulatory requirements for banks...
-
Analyst 5, It Security
4 weeks ago
Bengaluru, Karnataka, India Western Digital Full timeCompany DescriptionAt Western Digital our vision is to power global innovation and push the boundaries of technology to make what you thought was once impossible possible At our core Western Digital is a company of problem solvers People achieve extraordinary things given the right technology For decades we ve been doing just that Our technology...
-
Manager, Third Party Risk Management
3 weeks ago
Bengaluru, Karnataka, India Thomson Reuters Full timeJob DescriptionJob Description SummaryJoin the Thomson Reuters enterprise Third-Party Risk Management function, part of Risk & Compliance to help strengthening the control landscape and support the establishment of new, and delivery of existing core processes designed to evaluate and manage risks associated with external business relationships.About the...
-
Information Assurance Analyst
5 days ago
Bengaluru, Karnataka, India Tata Consultancy Services Full timeJoin Our Team as an Information Assurance Analyst!About the Role:Tata Consultancy Services is seeking a highly skilled Information Assurance Analyst to join our team. In this role, you will be responsible for ensuring the security and integrity of our information systems.Key Responsibilities:Must have a strong background in information technology with a...
-
Bengaluru, Karnataka, India WELLS FARGO BANK Full timeAbout this role:Wells Fargo is seeking a Business Execution Consultant (TPRM/Third Party Risk Management ).In this role, you will:Participate in a variety of assigned and ongoing business operations to ensure success in meeting business goals and objectivesIdentify opportunities for process improvement by conducting root cause testing of all compliance and...
-
Bengaluru, Karnataka, India Western Digital Full timeRole OverviewWe are seeking an experienced IT Governance Risk and Compliance Security Analyst to join our team at Western Digital. In this role, you will play a crucial part in advancing our company's information security posture.Your primary responsibility will be to develop, enhance, and implement enterprise-wide information security risk management...
-
Cyber Security Analyst
4 weeks ago
Bengaluru, Karnataka, India Zone IT Solutions Full timeWe is seeking a talented Cyber Security Analyst based in Bengaluru. As a Cyber Security Analyst, you will play a key role in ensuring the security and integrity of our organization's data and systems.RequirementsResponsibilities:- Monitor, detect, and respond to cyber threats and security incidents,- Conduct vulnerability assessments and penetration testing...
-
Sr Information Security Analyst
4 weeks ago
Bengaluru, Karnataka, India Informatica Full timeWe are currently looking for an energetic Senior Information Security Analyst GRC with proven experience working in information security to support Customer audits Requests and Customer engagements Supplier Risk Management to join our global team The ideal candidate is passionate about audit and compliance and is excited to join our growing team to...
-
TPRM Sr. Risk Analyst
4 weeks ago
Bengaluru, Karnataka, India Nielsen Full timeAt Nielsen, we are passionate about our work to power a better media future for all people by providing powerful insights that drive client decisions and deliver extraordinary results. Our talented, global workforce is dedicated to capturing audience engagement with content - wherever and whenever it's consumed. Together, we are proudly rooted in our deep...
-
Bengaluru, Karnataka, India Western Digital Full timeJob DescriptionWe are seeking a highly skilled IT Governance Risk and Compliance Security Analyst to join our team. As an integral part of our Information Security Governance, Risk Management, and Compliance (GRC) program, you will be responsible for advancing Western Digital's information security posture.You will assist in the development, enhancement, and...
-
Information Security Auditor
7 days ago
Bengaluru, Karnataka, India CSC Full timeCybersecurity Analyst - Audit Role Summary:This highly respected and in-demand role is responsible for supporting the security direction of the business and elevating the company's security posture across multiple jurisdictions.Key Accountabilities:Support the security strategy of the business within new and existing information system capabilitiesOversight...
-
IT Sourcer
3 weeks ago
Bengaluru, Karnataka, India KPMG Assurance and Consulting Services LLP Full timeJob DescriptionWork exp - 2 years - 7 yearsLocation - BangaloreWe have multiple roles at Third party / Full time .Job Role & Responsibilities- IT Sourcer Role - Strong IT hiring skills , with excellent sourcing skills from linkedin , naukri & various other chanels . (Should have experience in hiring for multiple skills like SAP , Java cyber security , )- IT...