Information Security Third-party Risk Management

3 days ago


Bengaluru, Karnataka, India Grant Thornton Full time

Years

1 Opening

Bengaluru

Role description

The Senior Associate, Information Security Third-party Risk Management position will be an integral member of the Information Security and Risk Management team.

The Senior Associate will support the Information Security & Risk Management team in executing Grant Thornton's Third-Party Risk Management (TPRM) Framework. This role focuses on performing vendor risk assessments, maintaining risk records, and assisting with remediation oversight under the guidance of senior team members.

This role will be in Chief Information Security Officer (CISO) office under Associate Director, Information Security Governance, Risk and Compliance.

The successful candidate will have a good mix of technical knowledge of Information technology, Networking, Applications, and understanding of industry security best practices, and some experience in information security risk management program.

The ideal candidate:

is a self-starter, with the ability to drive tasks to and learn new skills on the job.

possesses analytical thinking, is comfortable managing multiple tasks within a fast-paced environment and has worked collaboratively in a third-party risk mgmt. team environment.

possesses good verbal and written communication skills, pragmatic, and team collaborator.

Key Responsibilities:

Conduct basic security risk assessments for third-party vendors using OneTrust.

Maintain and update the risk register for supplier risks.

Support remediation tracking for supplier security findings.

Prepare summary reports for review.

Ensure compliance with firm security policies and procedures.

Collaborate with internal teams and vendors to collect required evidence documentation.

Help execute the information security third-party risk management framework.

Prepare risk registers in OneTrust to monitor and track risks.

Help development of CUECs to document shared responsibility model.

Skills

Required Experience

Experience with information security risk management framework, assessment, audit, and controls based on industry standard frameworks (i.e., NIST; ISO)

Some experience of using GRC tools and technologies in support of the assessment/audit process preferred (OneTrust, Security Scorecard, BitSight, etc.)

Experience gathering information from a range of different sources to help identify weaknesses in security controls.

Demonstrates good understanding across multiple information security domains preferred.

Qualifications

Bachelor's degree in computer science, Engineering or related field or equivalent work experience

CISA, CRISC, CISM, CISSP, or Lead Auditor ISO 27000 certifications (at least one) preferred or working towards it.

Demonstrates good verbal and written communication skills.

Excellent organization skills and be a self-motivated learner.

Very good experience in execution of Information Security third-party risk management program

About Grant Thornton INDUS

'Grant Thornton INDUS' comprises GT U.S. Shared Services Center India Pvt Ltd and Grant Thornton U.S. Knowledge and Capability Center India Pvt Ltd. Grant Thornton INDUS is the shared services center supporting the operations of Grant Thornton LLP, the U.S. member firm of Grant Thornton International Ltd. Established in 2012, Grant Thornton INDUS employs professionals across a wide range of disciplines including Tax, Audit, Advisory, and other operational functions. What sets us apart isn't just what we do – it's how we do it. We support and enable the firm's purpose of making business more personal and building trust into every result. We're collaborators – obsessed with quality and ready for anything – who understand the value of strong relationships. Our professionals are well integrated to seamlessly support the U.S. engagement teams, help increase Grant Thornton's access to a wide talent pool, and improve operational efficiencies. Empowered people, bold leadership, and distinctive client service are imbibed in the culture at Grant Thornton INDUS. We are a transparent, competitive, and excellence-driven firm that offers an opportunity to be part of something significant. In addition, professionals at Grant Thornton INDUS serve communities in India through inspirational and generous services to give back to the communities they work in. Grant Thornton INDUS has its offices in two locations in India – Bengaluru and Kolkata



  • Bengaluru, Karnataka, India Grant Thornton Full time

    5 - 8 Years1 OpeningBengaluruRole descriptionThe Senior Associate, Information Security Third-party Risk Management position will be an integral member of the Information Security and Risk Management team.The Senior Associate will support the Information Security & Risk Management team in executing Grant Thornton's Third-Party Risk Management (TPRM)...


  • Bengaluru, Karnataka, India Cubical Operations LLP Full time

    Job Title:Manager – Third Party Risk Management (TPRM)Location:BangaloreExperience:6+ YearsDepartment:Information Risk Management / Information SecurityAbout the Role:We are seeking an experiencedTPRM Managerto lead and enhance our Third-Party Risk Management framework. The ideal candidate will have a strong background inInformation Risk Management...


  • Bengaluru, Karnataka, India Wisdom Square Technologies Full time US$ 6,00,000 - US$ 18,00,000 per year

    Third-Party Risk Management (TPRM) Analyst / Senior Analyst- IMMEDIATE JOINERS ONLYExperience Level: 3–5 YearsLocation: Bengaluru, Hybrid, RemoteJob Type: Full-TimeJob SummaryWe are seeking a proactive and analytical Third-Party Risk Management (TPRM) Analyst to join our risk and compliance team. The ideal candidate will have 3-5 years of direct experience...


  • Bengaluru, Karnataka, India Wisdom Square Technologies Full time

    Role & ResponsibilitiesRisk Assessments & Due Diligence: Conduct end-to-end third-party risk assessments during onboarding and periodic reviews, including inherent risk scoring and detailed due diligence.Compliance & Frameworks: Evaluate vendor compliance with internal policies and industry standards including regulatory frameworks such as ISO 27001, NIST,...


  • Bengaluru, Karnataka, India Live Connections Full time

    Job DescriptionPosition:Infosec Third Party Risk – Senior ManagerDesignation:Senior ManagerExperience:15–20 YearsLocation:Remote (India)Role OverviewWe are seeking a highly experiencedInformation Security – Third Party Risk Senior Managerto lead and oversee third-party risk management (TPRM) and supply chain security initiatives.The ideal candidate...


  • Bengaluru, Karnataka, India ETT CareerMove Full time

    Our client a UK based MNC is seeking Third-Party Cyber Risk Analyst for their office in Bengaluru.Experience:5–10 yearsLocation:Bengaluru (Hybrid – 3 days WFO)Qualification:Any full-time graduationRole SummaryResponsible for operating the Third-Party Cyber Risk Management (TPCRM) framework to identify, assess, monitor, and mitigate cybersecurity risks...


  • Bengaluru, Karnataka, India Empower Full time

    Our vision for the future is based on the idea that transforming financial lives starts by giving our people the freedom to transform their own. We have a flexible work environment, and fluid career paths. We not only encourage but celebrate internal mobility. We also recognize the importance of purpose, well-being, and work-life balance. Within Empower and...


  • Bengaluru, Karnataka, India Finastra Full time

    Who are we?At Finastra, we are a dynamic global provider of open finance software solutions, dedicated to expanding access to financial services. Our innovative applications span Lending, Payments, Treasury and Capital Markets, and Universal Banking. Proudly serving over 8,000 customers, including 45 of the world's top 50 banks, we aim to boost financial...


  • Bengaluru, Karnataka, India, Karnataka Cubical Operations - We Hire Full time

    Job TitleThird Party Risk Management (TPRM) – Manager / Senior ManagerLocation BangaloreExperience6+ years (Relevant experience in TPRM, ISMS, and Information Security)Notice PeriodImmediate joiners preferredRole OverviewThe TPRM Manager / Senior Manager will be responsible for leading and overseeing third-party risk assessments across information...


  • Bengaluru, Karnataka, India Regeneron Full time

    Regeneron is founded on the belief that the right idea, combined with the right team, can lead to significant transformations. Our growing global network is dedicated to inventing, developing, and commercializing medicines that change lives for those with serious diseases. In doing so, we are pioneering innovative approaches to science, manufacturing, and...