
Associate, Grc
2 days ago
**Description**
Alvarez & Marsal (A&M) is seeking a TPVRM GRC Analyst who will play a critical role in managing and enhancing our third-party risk management program. This position will align to the team responsibilities of assessing, monitoring, and mitigating risks associated with third-party vendors, ensuring compliance with regulatory requirements and internal security policies.
Key Responsibilities:
Third-Party Risk Management:
- Laise with business and external stakeholders to perform comprehensive due diligence risk assessments of third-party vendors and identify risk, whilst maintaining monitoring activities of existing vendors.
- Contribute to process improvements and development of vendor risk assessment frameworks and questionnaires
Vendor Assessment & Monitoring:
- Perform due diligence on new and existing vendors, including reviewing SOC reports, certifications, and security controls.
- Monitor vendor performance and compliance through periodic assessments and audits.
- Maintain vendor risk register and track remediation efforts.
Client Security Questionnaires:
- Manage and complete client security questionnaires and assessments to demonstrate the organization’s security posture.
- Collaborate with internal teams (Privacy, Legal, IT) to gather accurate and comprehensive responses.
- Ensure timely delivery of client responses with service level agreements
- Support and contribute to continuous maintenance of question and response database (Responsive)
Governance & Compliance:
- Ensure third-party vendor activities comply with internal security policies and regulatory requirements.
- Support adherence to A&M Global Security Office policies, procedures, and standards.
- Provide guidance and support to internal stakeholders on third-party risk-related issues.
Client and Vendor Contract Reviews:
- Evaluate security terms in contracts with third parties, suppliers, and business teams to mitigate risks associated with client and vendor engagements.
- Work with legal, privacy and business teams to ensure that contractual obligations align with the organisation’s security policies and compliance requirements.
Risk Reporting & Communication:
- Communicate identified risks and remediation strategies to both technical and non-technical stakeholders.
- Participate and execute governance activities including metrics gathering and reporting, and the performance of recurring internal assessment activities
Qualifications:
Education & Experience:
- Bachelor’s degree in information security, Risk Management, Business, or related field.
- Industry recognized certification in security (e.g., CRISC (Certified in Risk and Information Systems Control), CTPRP (Certified Third-Party Risk Professional), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager)
- 3+ years of experience in GRC, third-party risk management, or information security.
- Experience in conducting vendor risk assessments and audits.
- Experience in managing and completing client security questionnaires.
Technical Skills:
- Good understanding of security frameworks such as ISO 27001, NIST, etc.
- Familiarity with third-party risk management tools and platforms (OneTrust, OnSpring, Responsive, BitSight etc.)
- Knowledge of regulatory requirements
Soft Skills:
- Excellent analytical, problem-solving, and decision-making skills.
- Strong communication and interpersonal skills.
- Ability to work collaboratively with cross-functional teams.
- Detail-oriented with the ability to manage multiple tasks simultaneously.
-
SAP Security/GRC Consultant
2 weeks ago
Remote, India Bridgesoft solutions pvt Ltd Full time ₹ 20,11,000 - ₹ 32,00,000 per yearJob Title: SAP Security ConsultantExperience Level: 5-11YearsJob Type: permanentAbout Us:Bridgesoft Solutions is a technology-driven company dedicated to providing innovative solutions and services. We are looking for a passionate and skilled SAP Security Consultant to join our dynamic team.Role Overview:The SAP Security Consultant will be responsible for...
-
SAP Security/GRC Consultant
2 weeks ago
Remote, India Bridgesoft solutions pvt Ltd Full time ₹ 1,11,098 per yearJob Title: SAP Security ConsultantExperience Level: 5+Job Type: permanent About Us: Bridgesoft Solutions is a technology-driven company dedicated to providing innovative solutions and services. We are looking for a passionate and skilled SAP Security Consultant to join our dynamic team. Role Overview: The SAP Security Consultant will be responsible for...
-
SAP Security
5 days ago
Remote, India Bridgesoft solutions pvt Ltd Full time**Job Title**: SAP Security Consultant **Experience Level**: 10+ **Job Type**: permanent **About Us**: Bridgesoft Solutions is a technology-driven company dedicated to providing innovative solutions and services. We are looking for a passionate and skilled SAP Security Consultant to join our dynamic team. **Role Overview**: **Key Responsibilities**: -...
-
Associate Principal Engineer, ServiceNow
2 weeks ago
Remote, India Nagarro Full time US$ 1,25,000 - US$ 1,75,000 per yearREQUIREMENTS:Total Experience 11+ years Strong working experience with ServiceNow architecture, application development and implementation experience. Strong working experience in service now module GRC and Legal. Strong command of ServiceNow platform components such as Business Rules, Client Scripts, UI Policies, UI Actions, ACLs, Flow Designer, etc. ...
-
SOC 2 Associate Manager
2 weeks ago
India (Remote) Insight Assurance Full time US$ 80,000 - US$ 1,20,000 per yearInsight Assurance is a security and compliance firm trusted by over 1200 organizations for their SOC 2, PCI DSS, ISO 27001, and HIPAA audit needs. Insight Assurance is a licensed CPA firm, PCI Qualified Security Assessor (QSA), and ISO 27001 Certification Body founded by former Big-4 professionals (Former EY) looking to simplify the world of IT compliance. ...