▷ [18/09/2025] Senior Manager - Vendor Security Risk

1 day ago


Gurugram Gurugram India SBI Card Full time

Job Description

About Us

JOB DESCRIPTION

SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto Make Life Simple inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.

SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, color, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.

Join us to shape the future of digital payment in India and unlock your full potential.

What's In It For YOU

- SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
- Admirable work deserves to be rewarded. We have a well curated bouquet of rewards and recognition program for the employees
- Dynamic, Inclusive and Diverse team culture
- Gender Neutral Policy
- Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
- Commitment to the overall development of an employee through comprehensive learning & development framework

Role Purpose

Responsible for conducting vendor risk assessments from information security perspective based on, ISO27001:2013, PCI-DSS, Cloud security control framework etc. and to ensure identified risks are addressed appropriately in timely manner. The role is also responsible for assessing and identifying risks associated with third parties part of SBI Card extended echo system, analyzing identified risks and ensure timely reporting and remediation of the same and working closely with cross-functional teams within SBI Card and vendor /partner teams to manage security risks associated with third parties and get the same addressed within a agreed timeline.

Role Accountability

- Conduct vendor risk assessments from information security perspective using, ISO27001:2013, PCI-DSS, Cloud security control framework etc.
- Ensure identified risks are addressed appropriately
- Track and report status of open observations, remedial plan and timelines for resolution
- Perform remediation testing once identified observations have been marked as resolved
- Review and establish secure processes and systems at vendor's end for integration with SBI Card
- Prepare and update assessment questionaries basis various applicable standards and industry good practices such as ISO 27001, PCI-DSS etc.
- Monitor vendor compliance, undertake vendor evaluations based on various industry standard and regulatory compliance perspective and suggest feedback / recommendations to the - business / vendor for mitigating identified risk
- Work with appropriate business users to ensure that for any identified risk require mitigating action along with timeline is agreed and tracked the same for successful closure
- Act as a subject matter expert to assist the business in identifying and mitigating risks pertaining to their vendor relationships
- Deliver continuous training and awareness to Business partners on various compliance requirements such as ISO 27001, PCI-DSS etc.
- Perform process documentation and compliance adherence

Measures of Success

- Number of vendor risk assessments conducted successfully
- Timely and accurate identification and reporting of information security risks pertaining to third parties/vendors
- Timely and accurate delivery of updates, presentations, assessment reports etc. to relevant stakeholders
- Tracking of audit findings and driving to closure within defined timelines
- Process Adherence as per MOU

Technical Skills / Experience / Certifications

- Knowledge in multiple information security technologies and their strengths and shortcomings
- Knowledge of common assessment control techniques
- Understanding of security controls from people, process and technology perspective
- Understanding of security architectural principles and standards
- Experience in system security, network security and information security, control objectives part of ISMS, Technology risk and compliance, BCP & DR planning, Security operations and Cloud security
- Knowledge of standard security processes and guidelines
- Experience in implementing or accessing compliance against PCI-DSS, ISO27001 requirements
- Industry-standard certifications such as ISO27001:2013 LA, CISA, CISM, Cloud Security etc.

Competencies critical to the role

- Detail Orientation
- Process Orientation
- Stakeholder Management
- Analytical ability

Qualification

Bachelor's Degree in Computer Science / Information Security or any other relevant discipline

Preferred Industry

FSI



  • Gurugram, Haryana, India Ameriprise Financial Full time

    Participation in Ameriprise vendor risk and security audit process for all vendors which are under scope for VRA (Vendor Risk Assessment **Responsibilities** Scheduling VRA Calls with the Security Teams (Information Security, Physical Security and Business Continuity), Line of Business and other stakeholders. Ensuring that the calls are scheduled within...


  • Gurugram, India Sprinklr Full time

    Job Description Role Responsibilities: - Manage the entire vendor lifecycle, from selection to offboarding - Draft, review, negotiate, and manage vendor contracts - Monitor vendor performance and compliance, ensuring alignment with business goals - Identify opportunities for cost optimization and process improvements Key Deliverables: - Efficient vendor...


  • India Celestica Electronics (S) Pte Ltd Full time

    Job DescriptionSummaryWe are seeking a highly motivated and experienced Senior Analyst to join our Third Party IT Risk Management team. This role is responsible for identifying, assessing, and mitigating information technology risks associated with our third-party relationships. The ideal candidate will possess a strong understanding of IT risk management...

  • B2B associates

    1 day ago


    Gurugram, India Cars24 Full time

    Job Description To identify and source high-quality second-hand cars for the Australian market (Car Stock/Leads will be made available by our B2B Partners) - Preparation, Bidding and Post approval process for online auctions - Conversations (Written over email/chat) with Wholesale/Dealers to secure inventory that meets company standards. - Utilise Google...

  • [High Salary] 09

    1 day ago


    India Celestica Electronics (S) Pte Ltd Full time

    Job Description Summary We are seeking a highly motivated and experienced Senior Analyst to join our Third Party IT Risk Management team. This role is responsible for identifying, assessing, and mitigating information technology risks associated with our third-party relationships. The ideal candidate will possess a strong understanding of IT risk...


  • Gurugram, India Agilent Technologies Full time

    Job Description Job Description Agilent inspires and supports discoveries that advance the quality of life. We provide life science, diagnostic and applied market laboratories worldwide with instruments, services, consumables, applications and expertise. Agilent enables customers to gain the answers and insights they seek –– so they can do what they do...


  • Gurugram, Gurugram, India Moody's Corporation Full time

    Job Description At Moody&aposs, we unite the brightest minds to turn todays risks into tomorrows opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they arewith the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. If you are excited about...


  • India Strobes Security, Inc. Full time

    The Role Are you the kind of person who can turn complex, technical topics into content that makes people stop scrolling? We’re on the hunt for a Social Media Executive who knows how to build a strong digital presence, spark conversations, and translate cybersecurity speak into compelling, creative content. You’ll be the digital voice of the Strobes...


  • Gurugram, India V2 Retail Full time

    Job Description Responsibilities: - Buying Merchandising: - Lead the buying strategy to ensure alignment with market trends, customer preferences, and company goals. - Develop and manage the seasonal product assortment, considering customer demands, market insights, and financial targets. - Ensure a balanced and profitable product range by working closely...


  • Gurugram, Gurugram, India Best for Him Full time

    Job Description Company Description Best for Him is dedicated to changing the long-held perception of men&aposs health and wellness by providing support and resources. Our mission is to help men embrace their vulnerabilities and improve their well-being with the best possible care. At Best for Him, we aim to enhance the quality of life for men, one...