
Tpr Assessment and Information Security
3 days ago
**TPR Assessment and information security**
***
Summary
Experience Required:
**4 - 9 Years**
**Location**:
**Kolkata,Kerela**
Category:
**Finance and Accounts**
EY GDS Consulting - Third-Party Risk Management as a Service (TPRaaS) - Senior
As part of our EY- TPRaaS team, you will help clients enhance their business performance by translating their strategies into realities. Working with EY-high performing teams, you will help clients to grow, innovate, protect, and optimize their business performance.
The opportunity
We’re looking for Seniors with expertise in Third-Party Risk Management to join the leadership group of our EY- TPRaaS team. It is a fantastic opportunity to be part of a leading firm while being instrumental in the growth of a new service offering.
Your key responsibilities
- Lead and work closely with the manager in the delivery of TPRaaS engagements.
- Lead the design and implementation of TPRM operating models, identifying, evaluating, and providing solutions to evaluate complex business and technology risks.
- Follow policies and procedures that support the successful implementation of TPRaaS operating models.
- Facilitate process walkthrough discussions to document end-to-end business processes and functional requirements.
- Lead/Participate in technology enhancement requirements such as Automation, Data Analytics, AI to support TPRaaS processes.
- Assist in the selection and tailoring of approaches, methods, and tools to support service offering or industry projects.
- Demonstrate a general knowledge of market trends, competitor activities, EY products, and service lines.
- Build and nurture positive working relationships with clients to achieve exceptional client service.
- Contribute to Identifying opportunities to improve engagement profitability.
- Assist leadership in driving business development initiatives and account management.
- Participate in building strong internal relationships within EY Consulting Services and with other services across the organization.
Skills and attributes for success
- Maintain an educational program to develop personal skills continually.
- Constantly upskilling as per market trends.
- Understand and follow workplace policies and procedures.
- Attend L&D programs and exhibit a thorough knowledge of consulting methodology and consulting attributes.
- Exhibit initiative and participate in corporate social and team events.
To qualify for the role, you must have
- 4 to 8 years of demonstrated experience with Risk Management across the Third-Party engagement lifecycle (pre-contracting, contracting, and post contracting) and an understanding of the associated organizational infrastructure (e.g., relevant internal controls, business processes, governance structures).
- Strong understanding of the TPRM framework, Risk Management, Information Security practices.
- Demonstrate a good understanding of the Contract Risk Review management process.
- Hands-on exposure to TPRM tools and technology solutions (e.g., GRC enablement solutions, such as Process Unity, Prevalent, Archer, ServiceNow, etc.).
- Demonstrated knowledge of standards such as ISO 27001/2, ISO 22301, ISO 27018, PCI - DSS, HITRUST, etc.
- Good knowledge of privacy regulations such as GDPR, CCPA, etc.
- Good knowledge of regulations such as FISMA, HIPAA, Reg SCI, MAS, etc.
- Good knowledge of TCP/IP, concepts of OSI layer and protocols, networking and security concepts, Physical & Environmental Security, Asset Security and Identity & Access Management.
- Good knowledge of OS (Windows / Linux) security, Database security, IT infrastructure (switches, routers, firewalls, IDS, IPS, etc.), Security architecture design, and review.
- Good familiarity with OWASP, and Secure SDLC standards/frameworks, anti-virus solutions (e.g., Symantec, McAfee, etc.).
- Good experience in LAN/WAN architectures and reviews.
- Good knowledge of incident management, disaster recovery, and business continuity management, cryptography.
- Good to have prior Big-4 experience.
- Good to have certifications - CISSP, CISA, CISM, CTPRP, CIPP, ISO 27001 Lead Auditor or Lead Implementer
Ideally, you’ll also have
- Project Management skills.
- Exposure to tools like ProcessUnity, ServiceNow, Archer.
What we look for
- A Team of people with enthusiasm to develop new skills and knowledge and experience to succeed and inquisitiveness to learn new things in this fast-moving environment.
- Actively tracks and communicates engagement performance and planning to EY engagement management, ensuring project milestones remain on track and are completed timely.
- Actively mentors and trains team members on TPRaaS processes, governance, and frameworks.
- Works cross-functionally with team members to support and drive a collaborative team environment.
- Creates and design effective presentations as a means for communicating project and deliverable progress to clients.
- Performs sophisticated data analyses to understand client’s bu
-
Chief Information Security Strategist
2 weeks ago
Kolkata, West Bengal, India beBeeSecurity Full time ₹ 1,50,00,000 - ₹ 2,50,00,000Information Security Leader RoleAs a seasoned Information Security Engineer Lead, you will develop and implement comprehensive security strategies that safeguard our organization's assets. Your expertise in industry best practices and regulatory standards will ensure compliance and mitigate risks.The ideal candidate will possess in-depth knowledge of...
-
Head of Information Security
2 weeks ago
Kolkata, West Bengal, India Pixis Full timeAbout us: Pixis is a global AI technology company transforming how brands plan, create, and optimize marketing. Our flagship marketing operating system, Prism, sits at the core of the Pixis platform, using AI to turn fragmented performance data into clear, actionable insights and directly into execution. With native integrations across major ad platforms,...
-
Information Security Analyst
3 weeks ago
Delhi, Kolkata, Mumbai, India Ion Full timeJob DescriptionJob Summary- Monitor security alerts and incidents and respond promptly to potential threats.- Conduct threat hunting, vulnerability assessments and penetration testing to identify security weaknesses.- Conduct regular security audits and risk assessments.- Analyse security breaches to determine root cause and implement corrective actions....
-
Information Security Professional
2 weeks ago
Kolkata, Delhi, Mumbai, India beBeeSecurity Full time ₹ 5,00,000 - ₹ 15,00,000Job Title: Security Analyst Role">We are seeking an experienced Security Analyst to join our team. This is a key role that will be responsible for monitoring, analyzing and responding to security incidents.">The successful candidate will have a strong background in security protocols, systems and methodologies, and will have proven experience in conducting...
-
Chief Information Security Specialist
2 weeks ago
Kolkata, West Bengal, India beBeeCybersecurity Full time ₹ 7,50,000 - ₹ 12,50,000As a Cybersecurity Professional, you will be responsible for ensuring the security and integrity of systems and applications. This includes conducting thorough security assessments, identifying vulnerabilities, and working closely with development teams to implement fixes.Key Responsibilities:Perform application security testing and penetration testing to...
-
25199715-analyst Ii Information Security
24 hours ago
Kolkata, West Bengal, India DXC Technology Full time**Essential Job Functions**: - Support security assessments, audits, and vulnerability scans, assisting in generating reports and recommendations. - Monitor security events and incidents, escalating issues as required and contributing to containment efforts. - Assist with the implementation of security policies and standards. - Collaborate with the security...
-
Chief Information Security Officer
2 weeks ago
Delhi, Mumbai, Kolkata, India beBeeSecurity Full time ₹ 9,00,000 - ₹ 12,00,000Job Description:">Analyse security breaches to determine root cause and implement corrective actions.Monitor security alerts and incidents and respond promptly to potential threats.Identify, review, prioritize, plan, coordinate, and follow-up on the remediation of vulnerabilities.Conduct threat hunting, vulnerability assessments and penetration testing to...
-
Chief Information Security Officer
2 weeks ago
Kolkata, West Bengal, India beBeeNetworkSecurity Full time ₹ 1,50,00,000 - ₹ 2,00,00,000Job TitleWe are seeking a highly capable Network Security Operations Manager to lead, manage, and enhance the organization's network security infrastructure and operations.This role will be responsible for managing key security technologies such as firewalls, proxies, VPNs, NAC, DNS security, WAF, and EDR & Data Security, ensuring operational governance...
-
Application Security Engineer
7 days ago
Kolkata, India Cloudkaptan Full timeINTRODUCTION: As an Application Security Engineer, you will play a critical role in driving secure application development and vulnerability remediation across our AWS and Azure cloud environments. You'll collaborate with cross-functional teams to embed security into systems, tools, and workflows, ensuring the security and integrity of our digital assets....
-
Senior Cyber Security Expert
2 weeks ago
Kolkata, West Bengal, India beBeeCybersecurity Full time ₹ 15,00,000 - ₹ 20,00,000Job Title: Cyber Security SpecialistRole Overview:We are seeking a cyber security expert with strong expertise in ISMS audits and assessments. The role involves conducting thorough evaluations of an organization's cyber risk controls to ensure compliance with security frameworks.Key Responsibilities:Conducting regular ISMS audits aligned with ISO 27001...