Specialist, Vendor Risk Manager, Technology and Operations

1 day ago


Mumbai India DBS Bank Full time

Job Description Business Function Technology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels. Job Description This role is responsible for establishing, implementing, and maintaining a robust third-party risk management program. This role involves overseeing the assessment and continuous monitoring of third-party vendors and partners to identify, evaluate, and mitigate information security, compliance, and operational risks. This role will ensure that third-party relationships adhere to internal policies, industry standards, and regulatory requirements, protecting the organization's assets and reputation. Key Responsibilities Program Management: - Develop, implement, and continuously improve the organization's Third-Party Risk Management (TPRM) framework, policies, procedures, and guidelines. Risk Assessment & Due Diligence: - Perform comprehensive end-to-end and in-depth information security assessments of third parties throughout their lifecycle (onboarding, ongoing, offboarding). - Conduct due diligence reviews of prospective and existing third-party vendors, assessing their security controls, compliance posture, and operational capabilities. - Advise and assess security mitigating controls for Network, Server, Endpoint security, Data protection (PII, Cards), Cloud security (Azure/AWS/GCP/OCI), Encryption, and API security. - Review implementation of standards such as PCI-DSS, PCI-PIN, and PA-DSS as applicable to third parties. - Continuous Monitoring: Establish and manage processes for the periodic assessment and continuous monitoring of third-party and ecosystem partners security posture and compliance. Risk Mitigation & Advisory: - Identify potential risks associated with third-party engagements and projects, advise on effective mitigation strategies. - Provide expert guidance on control implementation for the protection of sensitive data and adherence to security-by-design principles. Reporting & Stakeholder Engagement: - Responsible for audit planning, report review, and reporting on third-party risk posture to senior management and other stakeholders. - Liaise with business units on new third-party requirements, ensuring risk is considered from the outset. - Collaborate with internal teams (e.g., Legal, Procurement, IT, CISO team, Group Security) to ensure a consistent and integrated approach to third-party risk management. - Work with the CISO team on regulatory requirements and submissions pertaining to Digital Payment security for third-party engagements. - Liaise with business and partners on compliance and regulatory assurance related to third parties. Compliance & Standards: - Ensure third-party engagements comply with relevant laws, regulations, and industry standards. - Review and validate third-party adherence to recognized security frameworks and standards such as ISMS (ISO 27001), SOC (Service Organization Control reports), and NIST CSF. Requirements - Strong understanding and practical experience with Third-Party Risk Management (TPRM) principles and best practices. - In-depth knowledge of information security domains, including network, server, endpoint, data protection, cloud security (Azure/AWS/GCP/OCI), encryption, and API security. - Clear understanding of application security assessments, source code review, and VAPT (Vulnerability Assessment and Penetration Testing). - Strong fundamentals of Defense-in-Depth security and SDLC (Software Development Life Cycle) processes. - Excellent understanding of industry standards and frameworks such as PCI-DSS, PCI-PIN, PA-DSS, ISMS (ISO 27001), SOC, and NIST CSF. - Proven ability to conduct security assessments and interpret security reports. - Strong analytical, problem-solving, and communication skills to effectively engage with internal and external stakeholders. - Experience with audit planning and reporting. - Ability to work independently and manage multiple third-party relationships concurrently.



  • Mumbai, Maharashtra, India Paytm Full time

    **About Us**: Paytm is India's leading mobile payments and financial services distribution company. Pioneer of the mobile QR payments revolution in India, Paytm builds technologies that help small businesses with payments and commerce. Paytm’s mission is to serve half a billion Indians and bring them to the mainstream economy with the help of technology....


  • India - Pune Northern Trust Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Technology Risk Specialist About Northern Trust: Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889. Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by...


  • Mumbai, Maharashtra, India Orcapod Consulting Services Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    This role is on contract basis for 1 year extendible and convertible both based on performance. Please apply only if interested.Primary ResponsibilitiesPosition Description:Risk/3rd party monitoring and reporting for Investment Management Operations. This position would also require the individual to work closely with functional teams in our international...


  • Mumbai, India Orcapod Consulting Services Full time

    This role is on contract basis for 1 year extendible and convertible both based on performance. Please apply only if interested. Primary Responsibilities Position Description: Risk/3rd party monitoring and reporting for Investment Management Operations. This position would also require the individual to work closely with functional teams in our international...


  • Noida, Uttar Pradesh, India, Ghaziabad HCLTech Full time

    Position - Deputy General ManagerLocation - NoidaEducation - Graduate or postgraduate degree in Computer Science, Information Technology, Cybersecurity, or a related field.Professional Qualifications - ISO 27001 Lead Auditor, CISA, CISM, CISSP, CRISC, or equivalent.Experience - 12–15 years of overall experience in Information Security, Cybersecurity, and...


  • Mumbai, India Deutsche Bank Full time

    Job Description Operational Risk Senior Specialist, AVP Position Overview In Scope of Position based Promotions (INTERNAL only) Job Title: Operational Risk Senior Specialist, AVP Location: Mumbai, India Role Description The purpose of the Operational Risk Management (ORM) function is to ensure that the bank's Operational Risk (OR) exposure is...

  • Vendor Success

    1 week ago


    Mumbai, India MadeTruly Full time

    As a Vendor Success & Operations Specialist , you'll be working with the Project Manager - Vendor Operations as a vital bridge between internal stakeholders and external manufacturers/factories. You'll manage vendor-related processes—from purchase orders to issue resolution—so the KAM team can focus on client relationships. Key Responsibilities ...


  • Mumbai, India Deutsche Bank Full time

    Job Description NFRM Information Security & Technology Risk Specialist, AVP Position Overview Job Title:NFRM Information Security & Technology Risk Specialist Location: Mumbai, India Corporate Title: AVP Role Description - An Information Technology & Security Risk Specialist to join the 2nd LoD Information Security & Technology Risk Team. The team is...

  • Technology Risk

    1 week ago


    Mumbai, Maharashtra, India TIAA Full time

    Senior Associate - Technology Risk - IN The Technology Risk job oversees the identification and management of potential information security risks to the environment by utilizing control assessments, vendor due diligence and review remediation action plans to mitigate cybersecurity risks. Key Responsibilities and Duties - This job manages projects and...


  • Bengaluru, India Circles Full time

    Job Description About Us Founded in 2014, Circles is a global technology company reimagining the telco industry with its SaaS platform - Circles X, helping telco operators launch and operate successful digital brands through its offerings. Having pioneered a successful blueprint for disrupting the telco space in Singapore, Circles has since launched its...