▷ [18/09/2025] Senior Manager - Vendor Security Risk

3 weeks ago


Gurugram Gurugram India SBI Card Full time

Job Description

About Us

JOB DESCRIPTION

SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto Make Life Simple inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.

SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, color, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.

Join us to shape the future of digital payment in India and unlock your full potential.

What's In It For YOU

- SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
- Admirable work deserves to be rewarded. We have a well curated bouquet of rewards and recognition program for the employees
- Dynamic, Inclusive and Diverse team culture
- Gender Neutral Policy
- Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
- Commitment to the overall development of an employee through comprehensive learning & development framework

Role Purpose

Responsible for conducting vendor risk assessments from information security perspective based on, ISO27001:2013, PCI-DSS, Cloud security control framework etc. and to ensure identified risks are addressed appropriately in timely manner. The role is also responsible for assessing and identifying risks associated with third parties part of SBI Card extended echo system, analyzing identified risks and ensure timely reporting and remediation of the same and working closely with cross-functional teams within SBI Card and vendor /partner teams to manage security risks associated with third parties and get the same addressed within a agreed timeline.

Role Accountability

- Conduct vendor risk assessments from information security perspective using, ISO27001:2013, PCI-DSS, Cloud security control framework etc.
- Ensure identified risks are addressed appropriately
- Track and report status of open observations, remedial plan and timelines for resolution
- Perform remediation testing once identified observations have been marked as resolved
- Review and establish secure processes and systems at vendor's end for integration with SBI Card
- Prepare and update assessment questionaries basis various applicable standards and industry good practices such as ISO 27001, PCI-DSS etc.
- Monitor vendor compliance, undertake vendor evaluations based on various industry standard and regulatory compliance perspective and suggest feedback / recommendations to the - business / vendor for mitigating identified risk
- Work with appropriate business users to ensure that for any identified risk require mitigating action along with timeline is agreed and tracked the same for successful closure
- Act as a subject matter expert to assist the business in identifying and mitigating risks pertaining to their vendor relationships
- Deliver continuous training and awareness to Business partners on various compliance requirements such as ISO 27001, PCI-DSS etc.
- Perform process documentation and compliance adherence

Measures of Success

- Number of vendor risk assessments conducted successfully
- Timely and accurate identification and reporting of information security risks pertaining to third parties/vendors
- Timely and accurate delivery of updates, presentations, assessment reports etc. to relevant stakeholders
- Tracking of audit findings and driving to closure within defined timelines
- Process Adherence as per MOU

Technical Skills / Experience / Certifications

- Knowledge in multiple information security technologies and their strengths and shortcomings
- Knowledge of common assessment control techniques
- Understanding of security controls from people, process and technology perspective
- Understanding of security architectural principles and standards
- Experience in system security, network security and information security, control objectives part of ISMS, Technology risk and compliance, BCP & DR planning, Security operations and Cloud security
- Knowledge of standard security processes and guidelines
- Experience in implementing or accessing compliance against PCI-DSS, ISO27001 requirements
- Industry-standard certifications such as ISO27001:2013 LA, CISA, CISM, Cloud Security etc.

Competencies critical to the role

- Detail Orientation
- Process Orientation
- Stakeholder Management
- Analytical ability

Qualification

Bachelor's Degree in Computer Science / Information Security or any other relevant discipline

Preferred Industry

FSI



  • Gurugram, Gurugram, India Bain & Company Full time

    Job Description WHAT MAKES US A GREAT PLACE TO WORK We are proud to be consistently recognized as one of the world's best places to work, a champion of diversity and a model of social responsibility. We are currently ranked the #1 consulting firm on Glassdoor's Best Places to Work list, and we have maintained a spot in the top four on Glassdoor's list for...


  • Noida, Uttar Pradesh, India, Ghaziabad HCLTech Full time

    Position - Deputy General ManagerLocation - NoidaEducation - Graduate or postgraduate degree in Computer Science, Information Technology, Cybersecurity, or a related field.Professional Qualifications - ISO 27001 Lead Auditor, CISA, CISM, CISSP, CRISC, or equivalent.Experience - 12–15 years of overall experience in Information Security, Cybersecurity, and...


  • Gurugram, Haryana, India Ameriprise Financial Full time

    Participation in Ameriprise vendor risk and security audit process for all vendors which are under scope for VRA (Vendor Risk Assessment **Responsibilities** Scheduling VRA Calls with the Security Teams (Information Security, Physical Security and Business Continuity), Line of Business and other stakeholders. Ensuring that the calls are scheduled within...


  • Gurugram, India Senior Full time

    Company Description Senior is a UK based MNC and has operations in 12 countries and has 26 operating businesses worldwide serving number of markets. Senior's experienced manpower support, effective use of raw material as well as high technology enable it to deliver optimized components within a short development time and at most competitive prices. Senior...


  • Gurugram, India Sprinklr Full time

    Job Description Role Responsibilities: - Manage the entire vendor lifecycle, from selection to offboarding - Draft, review, negotiate, and manage vendor contracts - Monitor vendor performance and compliance, ensuring alignment with business goals - Identify opportunities for cost optimization and process improvements Key Deliverables: - Efficient vendor...

  • Vendor Management

    1 week ago


    Gurugram, India Sago Full time

    Sago is seeking a detail-oriented and proactive Vendor Management & Compliance Analyst to support our third-party risk management and compliance efforts. The role is responsible for managing the full lifecycle of vendor relationships-from onboarding and due diligence to contract reviews and ongoing compliance monitoring-ensuring all vendors meet internal...

  • Cyber Security

    3 weeks ago


    Gurugram, India BlackRock Full time

    Cyber Security - Data Protection, Tech & Ops, Analyst Location: Gurgaon, Haryana Team: Information Security Job Requisition #: R Date posted: Sep. 09, 2025


  • Gurugram, Gurugram, India Zinnia Full time

    Job Description Who We Are Zinnia is the leading technology platform for accelerating life and annuities growth. With innovative enterprise solutions and data insights, Zinnia simplifies the experience of buying, selling, and administering insurance products. All of which enables more people to protect their financial futures. Our success is driven by a...

  • Risk Manager

    2 weeks ago


    Gurugram, Gurugram, India Cosmofeed Full time

    Job Description Job Title: Risk Manager Location: Gurgaon About the Role: We're looking for a skilled Risk Manager to join our team at SuperProfile. As the leader of our Risk Management function, you'll play a critical role in identifying, assessing, and mitigating risks across our payments and transaction ecosystems. Your expertise will help us ensure...


  • Gurugram, India Google Full time

    Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Bengaluru, Karnataka, India; Gurugram, Haryana, India; Hyderabad, Telangana, India. Minimum qualifications: Bachelor's degree in business, a quantitative field, or equivalent practical experience. 10 years of experience in technical...