IT Third Party and Client Security Assurance Analyst

4 weeks ago


Bengaluru, Karnataka, India Aecome Full time
Job Description

Job description

The use of third parties is an essential element in AECOMs service delivery model and creates the need for management oversight and continuous monitoring of their security capabilities and performance. AECOM works with many third parties (e.g., vendors, partners, suppliers) each of which poses security, compliance and operational risks. AECOM is recruiting Third Party and Client Security Analysts to support the centralized Third Party and Client Risk Management Function.

In this role, the analyst is expected to support the framework, operating model and supervise processes to ensure: (1) third parties are compliant with AECOMs security standards and (2) that AECOM provides the same type of assurance to our clients that its security program is compliant with regulatory requirements, standards and client expectations.

Responsibilities & Duties

- Evaluate requests for third party engagements
- Conduct initial and periodic third-party risk assessments
- Collaborate with business requestors, procurement, legal and other teams to ensure questionnaires are completed timely
- Collaborate with security/IT team members to ensure a full understanding of security controls, technology and architecture
- Review responses to security questionnaires, SOC 1 and SOC 2 assessment reports received from third parties to identify potential risk to AECOM
- Identify gaps/issues based on third party and/or client standards relative to security postures
- Devise remediation plans and monitor to ensure adherence by third parties and AECOM security/IT
- Manage, enhance and implement the framework, policies, procedures and program governance to ensure alignment of TPRM with industry best practices and regulatory requirements (NIST, ISO27001, FedRamp, etc.)
- Develop tactical and strategic plans to evolve the third-party risk management program to ensure compliance with new regulations and alignment with industry best practices
- Triage/complete requests from AECOM clients regarding AECOMs control environment
- Manage AECOMs response to existing and potential business partners/clients/third parties security due diligence (questionnaires, site visits, etc.)
- Assistance with RFI/RFP processes and responses to client inquiries, ensuring comprehensive risk management throughout the process
- Review third party and client contracts to validate appropriate security requirements and commitments

Qualifications

- Bachelors degree in information technology, Information Security, Risk Management or a related field
- 2-3 years of career experience related to information security, IT, audit, third party and/or risk
- Strong understanding of risk management principles and security frameworks (e.g., NIST, ISO 27001, SOC2, PCI-DSS)
- Extensive experience in evaluating vendor security and compliance in relation to regulatory and industry standards.
- Familiarity with industry GRC tools such as UpGuard, Audit Board, ServiceNow etc. is a plus/desirable
- Strong prioritization and organizational skills
- Ability to develop, document and maintain procedures
- Strong verbal communication with the ability to advise management regarding third party and client risk management
- Ability to work independently and collaborate with cross-functional teams

Additional Information

- Ability to effectively communicate and collaborate within a specific group of internal and external customers. (Communication)
- Ability to maintain good customer relationship with the ability to proactively support customer needs and requirements. (Customer Service)
- Ability to be thorough and meticulous in completing assigned tasks and identifying errors, duplicates & discrepancies through defined methods. (Attention to Detail)
- Ability to identify, assess and resolve simple to moderate issues by following defined policies and procedures. (Problem Solving)

  • Bengaluru, Karnataka, India Broadridge Full time

    Job DescriptionKey Responsibilities:- Vendor Security Documentation Review- Evaluate third-party security artifacts including SOC 2 Type II reports, ISO/IEC 27001 certificates (with Statement of Applicability), vulnerability assessments and penetration testing (VAPT) results, and security policy documentation. Identify gaps or weaknesses in vendor controls...

  • Cyber Security

    3 hours ago


    Bengaluru, Karnataka, India, Karnataka Computacenter Full time

    Life on the teamOperates the Third-Party Cyber Risk Management framework to ensure cybersecurity risks related to our supply chain are effectively, managed to maintain a resilient and compliant security posture.What you’ll doOperate the Third-Party Cyber Risk Management Framework (~ 90%)• Third-Party Risk Management framework: operate processes and...


  • Bengaluru, Karnataka, India Stripe Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    About StripeStripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead....


  • Bengaluru, Karnataka, India Gainsight Software Private Limited Full time

    About Stripe: - Stripe is a financial infrastructure platform for businesses.- Millions of companies-from the world's largest enterprises to the most ambitious startups-use Stripe to accept payments, grow their revenue, and accelerate new business opportunities.- Our mission is to increase the GDP of the internet, and we have a staggering amount of work...


  • Bengaluru, Karnataka, India NETSACH GLOBAL Full time ₹ 4,00,000 - ₹ 12,00,000 per year

    Greetings from Netsach - A Cybersecurity Company.Job Summary:Our client, a leading bank based in Dubai, is looking for a Junior Third-Party Risk Assessor to join their growing Risk Management function. This entry-level role will support the assessment, monitoring, and governance of third-party service providers, ensuring compliance with internal policies and...


  • Bengaluru, Karnataka, India 42Gears Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Relevant Experience: 5 – 6 yearsAbout The RoleWe're looking for a Senior Security Analyst with a focus on malware analysis, application security, and software validation. You'll be responsible for ensuring third-party applications and patches, particularly those distributed through our MDM platform, are safe, authentic, and compliant. You'll lead efforts...


  • Bengaluru, Karnataka, India State Street Full time

    Third-Party Risk Management Due Diligence - Tech Lead Role Summary State Street uses third parties to support internal processes and in the delivery of certain products and services to clients These third parties are evaluated and risk assessed through our Third-Party Risk Management TPRM Program The Due Diligence Onboarding Senior Associate is...


  • Bengaluru, Karnataka, India Morgan Stanley Asia Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    We are seeking an experienced Director to support our Third-Party Due Diligence Assessment program in Bangalore. This individual will be responsible for leading and managing the delivery of Cybersecurity and Information Security Third Party Risk Assessments. In the Corporate Services division, we empower our businesses by creating collaborative...


  • Bengaluru, Karnataka, India AT&T Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Description:Role: Senior – Third Party Risk Management (TPRM)About the Company:Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold...


  • Bengaluru, Karnataka, India AT&T Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Job Description Role: Senior Third Party Risk Management (TPRM)About the Company: Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold...