Third party risk

4 weeks ago


Hyderabad, Telangana, India MOURI Tech Full time
Job Description

TPRM Analyst 4 to 8 Years

Role Summary: Cyber Risk Analyst to support and strengthen our enterprise cyber risk management program. The ideal candidate will be responsible for conducting risk and criticality assessments, maintaining the risk register, tracking mitigation efforts, and generating actionable risk reports to support leadership decision-making.

Key Responsibilities:

Execute risk-based assessments of third-party vendors to evaluate cybersecurity posture, data protection measures, and compliance with organizational and regulatory standards.

Maintain and update a centralized third-party inventory, including criticality ratings and assessment status.

Collaborate with business owners and procurement teams to understand the nature and scope of third-party engagements.

Issue and analyze security questionnaires (e.g., SIG Lite, CAIQ) and supporting documentation to identify control gaps and risks.

Provide actionable risk mitigation recommendations to business stakeholders and vendors.

Monitor remediation efforts and track open findings to closure; escalate overdue or high-risk issues as needed.

Contribute to the continuous improvement of the TPRM framework, including policies, procedures, assessment methodologies, and risk scoring models.

Generate regular reports and dashboards on third-party risk posture, trends, and compliance metrics for management and stakeholders.

Support annual reviews of third-party security requirements, contractual clauses, and due diligence processes.

Stay informed on emerging risks, regulatory changes, and best practices related to third-party and supply chain risk.

Strong knowledge of TPRM lifecycle, risk frameworks (e.g., NIST, ISO 27001, SIG Lite), and contract/vendor governance.

Strong understanding of risk assessment methodologies, cybersecurity controls, and vendor lifecycle management.

Familiarity with common frameworks (e.g., NIST CSF, ISO 27001, SIG, SOC 2, GDPR, HIPAA).

Proficient in GRC or TPRM platforms (e.g., ProcessUnity, Archer, OneTrust, ServiceNow GRC).

Excellent analytical, communication, and stakeholder management skills.

Ability to interpret technical and non-technical information and communicate risks effectively.

  • Hyderabad, Telangana, India ICE Data Services Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Job Description Job PurposeThe Analyst, Third Party Risk Management will be the first point of contact for any new third-party service request and will coordinate the end-to-end lifecycle process for third party onboarding.ResponsibilitiesConduct Risk assessments in compliance with the ICE TPRM policy.Work with stakeholders across business to ensure that...


  • Hyderabad, Telangana, India New Relic Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    We are a global team of innovators and pioneers dedicated to shaping the future of observability. At New Relic, we build an intelligent platform that empowers companies to thrive in an AI-first world by giving them unparalleled insight into their complex systems. As we continue to expand our global footprint, we're looking for passionate people to join our...


  • Hyderabad, Telangana, India Amgen Inc Full time

    Job DescriptionDescriptionThe Cyber and 3rd Party Risk Manager will be responsible for identifying, assessing, and mitigating cyber risks associated with third-party vendors, ensuring compliance with security policies and regulations.Responsibilities- Identify, assess, and manage cyber risks associated with third-party vendors.- Develop and implement risk...


  • Hyderabad, Telangana, India Talent Worx Full time ₹ 15,00,000 - ₹ 28,00,000 per year

    We are hiring for one of the BIG 4's in India, professionals leverage the global network of firms, providing detailed knowledge of local laws, regulations, markets, and competition.Our client in India offers services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused, and...


  • Hyderabad, Telangana, India Amgen Inc Full time

    Job Description- This is a lead role to support the risk management product team in identifying, analyzing, and mitigating IT-related risks to the organization. This role will involve working closely with various departments to ensure that risk controls are in place, policies are adhered to, and security standards are met. The IT Risk Analyst will assist in...


  • Hyderabad, Telangana, India Sandoz Full time

    Job DescriptionKey Responsibilities:- Support Novartis systems to verify compliance with HSE relevant responsible procurement commitments- Executes risk assessments of selected business critical 3rd party suppliers- Contributes to the overall 3rd party supplier improvement program- Follows the EPRM processes, standards, and ensures tracking of findings to...


  • Hyderabad, Telangana, India S&P Global Market Intelligence Full time

    Job DescriptionThe Team:- As part of Vendor Risk Management, the Vendor Cyber Risk Management team manages the Supply Chain Cyber risks by performing risk assessments of third-party engagements to identify and reduce the risks posed by third parties. This is an extremely important role, considering the fact that large number of data breaches happen due to...

  • Sr. Governance Risk

    4 days ago


    Hyderabad, Telangana, India Providence Global Center Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    About ProvidenceProvidence, one of the US's largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, 'Health for a better world', Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and...


  • Hyderabad, Telangana, India Citratech IT Services Private Limited Full time

    Job DescriptionClient's Digital Assets is seeking an experienced Information Security Risk Analyst to support the implementation and ongoing compliance of ISO27001 and SOC2 frameworks. This role will be responsible for conducting risk assessments, identifying control gaps, and collaborating with cross-functional teams to develop and monitor remediation...


  • Hyderabad, Telangana, India State Street Full time

    Who we areIt is an exciting time to join State Street Corporation SSC in the Enterprise Technology Risk Management ETRM organization ETRM in its capacity as Second Line of Defense SLOD is responsible for leadership oversight monitoring and advisement around the technologies architecture operational processes security and resiliencyWho we are...