Live opening · Posted 11 hours ago

TPRM Analyst

RethinkingWeb · Thane, Maharashtra, India (On-site)
Linkedin No
You are 11 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 11 hours ago
CompanyRethinkingWeb
LocationThane, Maharashtra, India (On-site)
Work modeNo
SourceLinkedin
Listed11 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
13 min from Linkedin publishing this role to us finding it
1 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
16,718 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

We are looking for a Third-Party Risk Management (TPRM) Associate to support the assessment, monitoring, and management of risks arising from vendors, suppliers, service providers, technology partners, and other third parties.
The role will involve working with business, procurement, information security, legal, privacy, and compliance teams to evaluate third-party risks and ensure that vendors meet the organization's security, privacy, regulatory, and contractual requirements.
The ideal candidate should have hands-on experience with vendor risk assessments, information security questionnaires, due diligence, risk analysis, compliance frameworks, and remediation tracking.
Key Responsibilities1. Third-Party Due Diligence
Conduct initial and periodic risk assessments of third parties and vendors.
Review vendor security and compliance documentation during onboarding and renewal.
Evaluate vendor responses to security questionnaires such as SIG, CAIQ, VSAQ, and customized information security questionnaires.
Review certifications and independent assurance reports including SOC 1, SOC 2, ISO 27001, PCI DSS, and relevant regulatory certifications.
Identify gaps, exceptions, and areas requiring additional investigation.
2. Risk Assessment & Analysis
Assess third-party risks across areas such as:
Information security
Data privacy
Business continuity
Cybersecurity
Regulatory compliance
Data handling and access
Subcontractor / fourth-party risk
Operational resilience
Assign risk ratings based on defined organizational methodologies.
Document identified risks, control gaps, and compensating controls.
Recommend appropriate remediation actions and risk treatments.
3. Vendor Monitoring
Support ongoing monitoring of high- and critical-risk vendors.
Track changes in vendor risk profiles, certifications, security incidents, and regulatory compliance.
Monitor remediation plans and ensure closure of identified findings within agreed timelines.
Escalate overdue or significant risks to appropriate stakeholders.
4. Documentation & Reporting
Maintain accurate and up-to-date vendor risk records.
Prepare risk assessment reports and management summaries.
Maintain evidence supporting vendor assessments and approvals.
Develop dashboards and periodic reports covering:
Vendor risk ratings
Assessment status
Open findings
Remediation status
High-risk / critical vendors
Exceptions and risk acceptances
5. Stakeholder Management
Coordinate with Procurement, Legal, IT, Information Security, Privacy, Business Owners, and vendors.
Communicate assessment requirements and follow up for pending information.
Participate in vendor onboarding, renewal, and offboarding processes.
Support risk committees and governance meetings where required.
6. Compliance & Frameworks
Support TPRM activities aligned with applicable regulatory requirements and industry standards.
Assist in mapping third-party controls against frameworks such as:
ISO 27001
NIST CSF
NIST 800-53
SOC 2
PCI DSS
CIS Controls
GDPR
India's DPDP Act
Keep track of changes in relevant security, privacy, and regulatory requirements.
7. Incident & Exception Management
Support assessment of security incidents involving third parties.
Assist in evaluating vendor notification, response, and remediation processes.
Track risk exceptions and compensating controls.
Escalate material third-party risks in accordance with organizational procedures.
Required Skills & Qualifications
Bachelor's degree in Information Security, Cybersecurity, IT, Risk Management, Computer Science, or a related field.
2–4 years of experience in Third-Party Risk Management, GRC, Information Security, IT Risk, Vendor Risk, or Compliance.
Understanding of information security and cybersecurity principles.
Experience conducting or supporting vendor risk assessments.
Ability to interpret SOC 2, ISO 27001, penetration testing reports, security questionnaires, and related evidence.
Strong analytical and documentation skills.
Good written and verbal communication skills.
Ability to work with multiple stakeholders and manage assessment timelines.
Preferred Certifications
One or more of the following would be advantageous:
CISA
CRISC
CISM
CISSP
ISO 27001 Lead Auditor / Lead Implementer
Security+
Certified Third Party Risk Professional (CTPRP) or equivalent TPRM certification
Privacy certifications such as CIPP/E, CIPP/US, CIPM, or equivalent
Tools & Technology
Exposure to GRC / TPRM platforms such as:
ServiceNow GRC
OneTrust
Archer
RSA Archer
MetricStream
LogicGate
SecurityScorecard
BitSight
Whistic
ProcessUnity
Working knowledge of Excel, PowerPoint, Power BI, and reporting/dashboard tools is desirable.
Key Competencies
Risk-based thinking
Analytical and critical thinking
Attention to detail
Vendor and stakeholder management
Strong documentation
Problem solving
Communication and negotiation
Ability to manage multiple assessments simultaneously
Understanding of confidentiality and sensitive information
Ability to work independently and as part of a cross-functional team
Key Performance Indicators
Success in this role will be measured through:
Timely completion of vendor risk assessments
Quality and accuracy of risk assessments
Effective identification and classification of third-party risks
Closure of vendor remediation items
Compliance with TPRM processes and SLAs
Quality of risk reporting and documentation
Stakeholder and vendor responsiveness
Reduction in overdue high-risk assessments and findings

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App