Manager - Vendor Security Risk Specialist
4 days ago
About Us
SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto 'Make Life Simple' inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.
SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, colour, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.
Join us to shape the future of digital payment in India and unlock your full potential.
What's in it for YOU
- SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
- Admirable work deserves to be rewarded. We have a well curated bouquet of rewards and recognition program for the employees
- Dynamic, Inclusive and Diverse team culture
- Gender Neutral Policy
- Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
- Commitment to the overall development of an employee through comprehensive learning & development framework
Role Purpose
Responsible for conducting vendor risk assessments from information security perspective based on, ISO27001:2013, PCI-DSS, Cloud security control framework etc. and to ensure identified risks are addressed appropriately in timely manner. The role is also responsible for assessing and identifying risks associated with third parties part of SBI Card extended echo system, analyzing identified risks and ensure timely reporting and remediation of the same and working closely with cross-functional teams within SBI Card and vendor /partner teams to manage security risks associated with third parties and get the same addressed within a agreed timeline.
Role Accountability
- Conduct vendor risk assessments from information security perspective using, ISO27001:2013, PCI-DSS, Cloud security control framework etc.
- Ensure identified risks are addressed appropriately
- Track and report status of open observations, remedial plan and timelines for resolution
- Perform remediation testing once identified observations have been marked as resolved
- Review and establish secure processes and systems at vendor's end for integration with SBI Card
- Prepare and update assessment questionaries basis various applicable standards and industry good practices such as ISO 27001, PCI-DSS etc.
- Monitor vendor compliance, undertake vendor evaluations based on various industry standard and regulatory compliance perspective and suggest feedback / recommendations to the - business / vendor for mitigating identified risk
- Work with appropriate business users to ensure that for any identified risk require mitigating action along with timeline is agreed and tracked the same for successful closure
- Act as a subject matter expert to assist the business in identifying and mitigating risks pertaining to their vendor relationships
- Deliver continuous training and awareness to Business partners on various compliance requirements such as ISO 27001, PCI-DSS etc.
- Perform process documentation and compliance adherence
Measures of Success
- Number of vendor risk assessments conducted successfully
- Timely and accurate identification and reporting of information security risks pertaining to third parties/vendors
- Timely and accurate delivery of updates, presentations, assessment reports etc. to relevant stakeholders
- Tracking of audit findings and driving to closure within defined timelines
- Process Adherence as per MOU
Technical Skills / Experience / Certifications
- Knowledge in multiple information security technologies and their strengths and shortcomings
- Knowledge of common assessment control techniques
- Understanding of security controls from people, process and technology perspective
- Understanding of security architectural principles and standards
- Experience in system security, network security and information security, control objectives part of ISMS, Technology risk and compliance, BCP & DR planning, Security operations and Cloud security
- Knowledge of standard security processes and guidelines
- Experience in implementing or accessing compliance against PCI-DSS, ISO27001 requirements
- Industry-standard certifications such as ISO27001:2013 LA, CISA, CISM, Cloud Security etc.
Competencies critical to the role
- Detail Orientation
- Process Orientation
- Stakeholder Management
- Analytical ability
Qualification
Bachelor's Degree in Computer Science / Information Security or any other relevant discipline
Preferred Industry
FSI
-
Vendor Management
2 weeks ago
Gurgaon, Haryana, India KKR Full time US$ 12,00,000 - US$ 30,00,000 per yearCompany OverviewKKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR...
-
Vendor Management Analyst
1 week ago
Gurgaon, Haryana, India Sago Full timeThe IT Vendor Management Analyst is responsible for supporting the full lifecycle of third-party IT vendors, including procurement, onboarding, contract administration, performance monitoring, SLA reporting, issue management, and coordination between internal teams and suppliers. The role requires strong documentation, communication, and analytical skills,...
-
Compliance Specialist
2 days ago
Gurgaon, Haryana, India PINKERTON | Comprehensive Risk Management Full timeOverview170+ Years Strong. Industry Leader. Global Impact.At Pinkerton, the mission is to protect our clients. To do this, we provide enterprise risk management services and programs specifically designed for each client. Pinkerton employees are one of our most important assets and critical to the delivery of world-class solutions. Bonded together, we share...
-
Information Security Manager
9 hours ago
Gurgaon, Haryana, India questW Full timeThis is a full time role with our global client for their captive finance arm in Gurgaon.Key objective-The position will be responsible for ensuring regulatory compliance under RBI guidelines for NBFCs, managing internal policies, and driving the information security framework (data protection, IT audits, and cyber risk governance). The role ensures that...
-
Risk Manager
2 weeks ago
Gurgaon, Haryana, India BT Group Full time ₹ 60,000 - ₹ 1,80,000 per yearWhy this job matters The Risk Manager manages a team to implement the Group's Risk Management framework, including enabling enhanced identification, mitigation / controls, governance, and oversight and reporting. What you'll be doing 1. Manages a team in executing the review of the Group's risk framework refining risk management and oversight processes,...
-
Network Security Specialist
4 days ago
Gurgaon, Haryana, India Maruti Suzuki Full timeRole Objective:Seeking a skilled Network Security Specialist with 5–8 years of experience in managing enterprise security infrastructure, including firewalls, VPNs, NAC, and ZTNA. The role involves designing and maintaining secure access controls and perimeter defenses across hybrid environments. Strong analytical skills, hands-on expertise, and a...
-
IT Security Governance, Risk, and Compliance
2 days ago
Gurgaon, Haryana, India Crocs, Inc. Full timeOverview Reporting into Information Security, the Governance, Risk, and Compliance (GRC) Engineer plays an instrumental role in guiding GRC strategies and processes. As the primary GRC authority in India and supporting the global GRC team, this engineer works directly with other partners such as Legal, Risk, Internal Audit, etc. to ensure the alignment of...
-
IT Security Governance, Risk, and Compliance
2 days ago
Gurgaon, Haryana, India Crocs Vietnam Full timeRequisition ID: 9911Job Location(s):Gurugram, HR, IN, 122022Time in Office: HybridOverviewReporting into Information Security, the Governance, Risk, and Compliance (GRC) Engineer plays an instrumental role in guiding GRC strategies and processes. As the primary GRC authority in India and supporting the global GRC team, this engineer works directly with other...
-
Information Security Manager
1 week ago
Gurgaon, Haryana, India Simpplr Full timeWho We AreSimpplr is the AI-powered platform that unifies the digital workplace – bringing together engagement, enablement, and services to transform the employee experience. It streamlines communication, simplifies interactions, automates workflows, and elevates the everyday experience of work. The platform is intuitive, highly extensible, and built to...
-
Cyber Security Ops. Specialist
2 weeks ago
Gurgaon, Haryana, India BT Group Full time US$ 1,20,000 - US$ 2,40,000 per yearAt BT International, our purpose is to keep the world connected. As part of BT, we build on almost 180 years of innovation and expertise to deliver secure connectivity and digital services to some of the world's leading multinational businesses and organisations. Our customers trust us to safeguard their data, drive their digital transformation and keep...