Sr. Manager, Information Security Third-party Risk Management

2 days ago


Bengaluru, Karnataka, India Grant Thornton Full time ₹ 15,00,000 - ₹ 25,00,000 per year

Role Description

The Senior Manager, Information Security Third-party Risk Management position will be an integral member of the Information Security and Risk Management team. This role will be responsible for design, development, implementation and monitoring of risk management program. Work in Chief Information Security Officer (CISO) office under Associate Director, Information Security Governance, Risk and Compliance, this role serves as an information security technology professional for Grant Thornton to support the design, implementation, and maintenance of a cohesive information security governance, risk and compliance program. The successful candidate will have a good mix of deep technical knowledge, understanding of industry best practice, frameworks and regulations, and a demonstrated background in information security risk management program.

An experienced and motivated risk and compliance individual contributor is needed to work across a matrixed team in place today and growing in the future. The successful candidate has a track record of developing strong relationships, collaborating across teams, coordinating multiple timelines, and managing complex, cross discipline projects

Skills

The ideal candidate:

is a self-starter, with the ability to drive tasks to completion independently and learn new skills on the job as program requirements evolve.

possesses strong business judgment, deep analytical thinking, is comfortable managing multiple responsibilities within a fast-paced environment, and has worked collaboratively with others to develop, implement, and communicate business improvement and innovative strategies.

possesses strong verbal and written communication skills, a solution-oriented approach, and relationship-building skills are important attributes to succeed in this role.

global view of their business and think in terms of immediate problem solving but also automating, expanding, and scaling solutions broadly.

thinks strategically at a global level and effectively develop key processes, procedures and communications that facilitate cross-functional implementation of risk management processes and risk reporting.

Responsibilities:

  • Advance the information security third-party risk management framework and develop risk appetite
  • Develop effective strategies for addressing high-risk suppliers.
  • Oversee and perform security risk assessments, business impact analyses, and security control evaluations across third-party vendors in OneTrust.

Prepare risk register in OneTrust to monitor and track risks.

  • Provide supply chain security assessment remediation oversight and facilitate development of CUECs to document shared responsibility model.
  • Perform client MSA security terms and conditions review and provide feedback to legal team.
  • Ensure compliance with relevant firm security policies.
  • Support iterative review of assessment results, working with appropriate stakeholders across the lines of defense
  • Establish risk reporting and escalation processes
  • Remain up to date with emerging threats, best practices and relevant legislation
  • Work and communicate hand-in-hand with both external and internal stakeholders on critical issues that are directly impacting the business.
  • Contribute to the development of scalable models and tools that speed up both decision making and accuracy for the organization.
  • Meet with stakeholders to gather and integrate feedback and evangelize the program
  • Perform and facilitate the collection, review, and assimilation of risk assessment data and reporting into concise and meaningful reports/dashboards for leadership. Take leading role in drafting and presenting deep-dive documents, including responses to senior executives.


  • Bengaluru, Karnataka, India beBeeRisk Full time ₹ 8,00,000 - ₹ 13,00,000

    Senior Risk ConsultantWe are seeking an experienced Senior Risk Consultant to join our Third Party Risk Management team. The successful candidate will perform risk assessments and monitor third-party vendors for compliance with cybersecurity and regulatory standards.Main Responsibilities:Conduct thorough risk assessments of third-party vendors focusing on...


  • Bengaluru, Karnataka, India beBeeSecurity Full time US$ 90,000 - US$ 1,20,000

    Job DescriptionEvaluate third-party engagement requests and conduct initial assessments to ensure alignment with industry best practices.Collaborate with business requestors, procurement, legal, and security teams to complete questionnaires timely and ensure understanding of security controls.Review responses to security questionnaires and assessment reports...


  • Bengaluru, Karnataka, India Broadridge Full time

    Job DescriptionKey Responsibilities:- Vendor Security Documentation Review- Evaluate third-party security artifacts including SOC 2 Type II reports, ISO/IEC 27001 certificates (with Statement of Applicability), vulnerability assessments and penetration testing (VAPT) results, and security policy documentation. Identify gaps or weaknesses in vendor controls...


  • Bengaluru, Karnataka, India State Street Full time

    Third-Party Risk Management Due Diligence - Tech Lead Role Summary State Street uses third parties to support internal processes and in the delivery of certain products and services to clients These third parties are evaluated and risk assessed through our Third-Party Risk Management TPRM Program The Due Diligence Onboarding Senior Associate is...


  • Bengaluru, Karnataka, India beBeeRiskManagement Full time ₹ 15,00,000 - ₹ 28,00,000

    We are seeking a seasoned professional to join our team as a Third Party Risk Management Specialist. As a key member of our organization, you will be responsible for identifying and mitigating risks associated with third-party vendors.This role requires a deep understanding of risk management principles and practices. You should have excellent analytical and...


  • Bengaluru, Karnataka, India Morgan Stanley Asia Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    We are seeking an experienced Director to support our Third-Party Due Diligence Assessment program in Bangalore. This individual will be responsible for leading and managing the delivery of Cybersecurity and Information Security Third Party Risk Assessments. In the Corporate Services division, we empower our businesses by creating collaborative...


  • Bengaluru, Karnataka, India beBeeRisk Full time ₹ 1,50,00,000 - ₹ 2,50,00,000

    Discover a fulfilling career opportunity as a Third Party Risk Management Specialist.Job DescriptionYou will be responsible for designing and implementing a robust framework to deliver services in scope, meeting customer expectations on time and within budget.Our ideal candidate will have hands-on involvement in operations within the service area, creating...


  • Bengaluru, Karnataka, India Aecome Full time

    Job DescriptionJob descriptionThe use of third parties is an essential element in AECOMs service delivery model and creates the need for management oversight and continuous monitoring of their security capabilities and performance. AECOM works with many third parties (e.g., vendors, partners, suppliers) each of which poses security, compliance and...


  • Bengaluru, Karnataka, India beBeeRiskManagement Full time ₹ 2,00,00,000 - ₹ 2,50,00,000

    Job Title: Third-Party Risk Management LeadWe are seeking an experienced professional to lead our third-party risk management initiatives and develop customized solutions for large and mid-sized organizations.Key Responsibilities:Lead the development of comprehensive third-party risk management frameworks in accordance with client objectives and regulatory...


  • Bengaluru, Karnataka, India Morgan Stanley Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    We are seeking an experienced Director to support our Third-Party Due Diligence Assessment program in Bangalore. This individual will be responsible for leading and managing the delivery of Cybersecurity and Information Security Third Party Risk Assessments.In the Corporate Services division, we empower our businesses by creating collaborative workplace...