Specialist, Vendor Risk Manager, Technology and Operations

4 weeks ago


Mumbai India DBS Bank Full time

Job Description Business Function Technology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels. Job Description This role is responsible for establishing, implementing, and maintaining a robust third-party risk management program. This role involves overseeing the assessment and continuous monitoring of third-party vendors and partners to identify, evaluate, and mitigate information security, compliance, and operational risks. This role will ensure that third-party relationships adhere to internal policies, industry standards, and regulatory requirements, protecting the organization's assets and reputation. Key Responsibilities Program Management: - Develop, implement, and continuously improve the organization's Third-Party Risk Management (TPRM) framework, policies, procedures, and guidelines. Risk Assessment & Due Diligence: - Perform comprehensive end-to-end and in-depth information security assessments of third parties throughout their lifecycle (onboarding, ongoing, offboarding). - Conduct due diligence reviews of prospective and existing third-party vendors, assessing their security controls, compliance posture, and operational capabilities. - Advise and assess security mitigating controls for Network, Server, Endpoint security, Data protection (PII, Cards), Cloud security (Azure/AWS/GCP/OCI), Encryption, and API security. - Review implementation of standards such as PCI-DSS, PCI-PIN, and PA-DSS as applicable to third parties. - Continuous Monitoring: Establish and manage processes for the periodic assessment and continuous monitoring of third-party and ecosystem partners security posture and compliance. Risk Mitigation & Advisory: - Identify potential risks associated with third-party engagements and projects, advise on effective mitigation strategies. - Provide expert guidance on control implementation for the protection of sensitive data and adherence to security-by-design principles. Reporting & Stakeholder Engagement: - Responsible for audit planning, report review, and reporting on third-party risk posture to senior management and other stakeholders. - Liaise with business units on new third-party requirements, ensuring risk is considered from the outset. - Collaborate with internal teams (e.g., Legal, Procurement, IT, CISO team, Group Security) to ensure a consistent and integrated approach to third-party risk management. - Work with the CISO team on regulatory requirements and submissions pertaining to Digital Payment security for third-party engagements. - Liaise with business and partners on compliance and regulatory assurance related to third parties. Compliance & Standards: - Ensure third-party engagements comply with relevant laws, regulations, and industry standards. - Review and validate third-party adherence to recognized security frameworks and standards such as ISMS (ISO 27001), SOC (Service Organization Control reports), and NIST CSF. Requirements - Strong understanding and practical experience with Third-Party Risk Management (TPRM) principles and best practices. - In-depth knowledge of information security domains, including network, server, endpoint, data protection, cloud security (Azure/AWS/GCP/OCI), encryption, and API security. - Clear understanding of application security assessments, source code review, and VAPT (Vulnerability Assessment and Penetration Testing). - Strong fundamentals of Defense-in-Depth security and SDLC (Software Development Life Cycle) processes. - Excellent understanding of industry standards and frameworks such as PCI-DSS, PCI-PIN, PA-DSS, ISMS (ISO 27001), SOC, and NIST CSF. - Proven ability to conduct security assessments and interpret security reports. - Strong analytical, problem-solving, and communication skills to effectively engage with internal and external stakeholders. - Experience with audit planning and reporting. - Ability to work independently and manage multiple third-party relationships concurrently.



  • Mumbai, Maharashtra, India Paytm Full time

    **About Us**: Paytm is India's leading mobile payments and financial services distribution company. Pioneer of the mobile QR payments revolution in India, Paytm builds technologies that help small businesses with payments and commerce. Paytm’s mission is to serve half a billion Indians and bring them to the mainstream economy with the help of technology....


  • India Ujjivan Small Finance Bank Full time

    POSITION DESCRIPTION JOB TITLE- Specialist-Operational Risk GRADE SM DEPARTMENT Risk LOCATION HO TYPE OF POSITION -Full-time REPORTS TO Manager – Operational Risk Specialist-Operational Risk - Job Description Internal Process Reports loss incidents for identification of control gaps Responsible for implementing risk and control matrix / Supports for...


  • Bengaluru, India ABB Full time

    Job Description En ABB, ayudamos a las industrias a ser ms eficientes y limpias. Aqu, el progreso es una expectativa - para usted, su equipo y el mundo. Como lder del mercado mundial, le daremos lo que necesita para lograrlo. No siempre ser fcil, crecer requiere agallas. Pero en ABB, nunca corrers solo. Run what runs the world. Este Puesto Reporta a IS...


  • Mumbai-suburbs, India Acura Solution Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Job Description:• Implementing and embedding the Operational risk framework to identify, assess, monitor Vendor risk (Outsourcing & Non-Outsourcing Services) • Ensuring Gatekeeping of all new vendors to ensure onboarding requirements are completed prior to vendor services being consumed. • Co-ordination with Payments Teams to ensure ORM approval is...


  • Noida, India Ameriprise Financial Services, LLC Full time

    Job Description - Partnering with technology, business, compliance, and audit partners to operationalize technology risk framework. - Solid working understanding of Vendor Risk Management process end-to-end, should be able to lead and participate in the vendor risk assessments. - Acting as a liaison between audit owners and technology teams to facilitate...


  • Mumbai, India Cubical Operations LLP Full time

    Job Title: Manager – Third Party Risk Management (TPRM)Location: MumbaiExperience: 6+ YearsDepartment: Information Risk Management / Information SecurityAbout the Role:We are seeking an experienced TPRM Manager to lead and enhance our Third-Party Risk Management framework. The ideal candidate will have a strong background in Information Risk Management...


  • mumbai, India Cubical Operations LLP Full time

    Job Title: Manager – Third Party Risk Management (TPRM)Location: MumbaiExperience: 6+ YearsDepartment: Information Risk Management / Information SecurityAbout the Role:We are seeking an experienced TPRM Manager to lead and enhance our Third-Party Risk Management framework. The ideal candidate will have a strong background in Information Risk Management...


  • Mumbai, India Cubical Operations LLP Full time

    Job Title: Manager – Third Party Risk Management (TPRM)Location: MumbaiExperience: 6+ YearsDepartment: Information Risk Management / Information SecurityAbout the Role:We are seeking an experienced TPRM Manager to lead and enhance our Third-Party Risk Management framework. The ideal candidate will have a strong background in Information Risk Management...


  • Mumbai, India Cubical Operations LLP Full time

    Job Title: Manager – Third Party Risk Management (TPRM)Location: MumbaiExperience: 6+ YearsDepartment: Information Risk Management / Information SecurityAbout the Role:We are seeking an experienced TPRM Manager to lead and enhance our Third-Party Risk Management framework. The ideal candidate will have a strong background in Information Risk...


  • Mumbai, India Cubical Operations LLP Full time

    Job Title: Manager – Third Party Risk Management (TPRM) Location: Mumbai Experience: 6+ Years Department: Information Risk Management / Information Security About the Role: We are seeking an experienced TPRM Manager to lead and enhance our Third-Party Risk Management framework. The ideal candidate will have a strong background in Information Risk...