Live opening · Posted 11 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
We are looking for a Third-Party Risk Management (TPRM) Associate to support the assessment, monitoring, and management of risks arising from vendors, suppliers, service providers, technology partners, and other third parties.
The role will involve working with business, procurement, information security, legal, privacy, and compliance teams to evaluate third-party risks and ensure that vendors meet the organization's security, privacy, regulatory, and contractual requirements.
The ideal candidate should have hands-on experience with vendor risk assessments, information security questionnaires, due diligence, risk analysis, compliance frameworks, and remediation tracking.
Key Responsibilities1. Third-Party Due Diligence
Conduct initial and periodic risk assessments of third parties and vendors.
Review vendor security and compliance documentation during onboarding and renewal.
Evaluate vendor responses to security questionnaires such as SIG, CAIQ, VSAQ, and customized information security questionnaires.
Review certifications and independent assurance reports including SOC 1, SOC 2, ISO 27001, PCI DSS, and relevant regulatory certifications.
Identify gaps, exceptions, and areas requiring additional investigation.
2. Risk Assessment & Analysis
Assess third-party risks across areas such as:
Information security
Data privacy
Business continuity
Cybersecurity
Regulatory compliance
Data handling and access
Subcontractor / fourth-party risk
Operational resilience
Assign risk ratings based on defined organizational methodologies.
Document identified risks, control gaps, and compensating controls.
Recommend appropriate remediation actions and risk treatments.
3. Vendor Monitoring
Support ongoing monitoring of high- and critical-risk vendors.
Track changes in vendor risk profiles, certifications, security incidents, and regulatory compliance.
Monitor remediation plans and ensure closure of identified findings within agreed timelines.
Escalate overdue or significant risks to appropriate stakeholders.
4. Documentation & Reporting
Maintain accurate and up-to-date vendor risk records.
Prepare risk assessment reports and management summaries.
Maintain evidence supporting vendor assessments and approvals.
Develop dashboards and periodic reports covering:
Vendor risk ratings
Assessment status
Open findings
Remediation status
High-risk / critical vendors
Exceptions and risk acceptances
5. Stakeholder Management
Coordinate with Procurement, Legal, IT, Information Security, Privacy, Business Owners, and vendors.
Communicate assessment requirements and follow up for pending information.
Participate in vendor onboarding, renewal, and offboarding processes.
Support risk committees and governance meetings where required.
6. Compliance & Frameworks
Support TPRM activities aligned with applicable regulatory requirements and industry standards.
Assist in mapping third-party controls against frameworks such as:
ISO 27001
NIST CSF
NIST 800-53
SOC 2
PCI DSS
CIS Controls
GDPR
India's DPDP Act
Keep track of changes in relevant security, privacy, and regulatory requirements.
7. Incident & Exception Management
Support assessment of security incidents involving third parties.
Assist in evaluating vendor notification, response, and remediation processes.
Track risk exceptions and compensating controls.
Escalate material third-party risks in accordance with organizational procedures.
Required Skills & Qualifications
Bachelor's degree in Information Security, Cybersecurity, IT, Risk Management, Computer Science, or a related field.
2–4 years of experience in Third-Party Risk Management, GRC, Information Security, IT Risk, Vendor Risk, or Compliance.
Understanding of information security and cybersecurity principles.
Experience conducting or supporting vendor risk assessments.
Ability to interpret SOC 2, ISO 27001, penetration testing reports, security questionnaires, and related evidence.
Strong analytical and documentation skills.
Good written and verbal communication skills.
Ability to work with multiple stakeholders and manage assessment timelines.
Preferred Certifications
One or more of the following would be advantageous:
CISA
CRISC
CISM
CISSP
ISO 27001 Lead Auditor / Lead Implementer
Security+
Certified Third Party Risk Professional (CTPRP) or equivalent TPRM certification
Privacy certifications such as CIPP/E, CIPP/US, CIPM, or equivalent
Tools & Technology
Exposure to GRC / TPRM platforms such as:
ServiceNow GRC
OneTrust
Archer
RSA Archer
MetricStream
LogicGate
SecurityScorecard
BitSight
Whistic
ProcessUnity
Working knowledge of Excel, PowerPoint, Power BI, and reporting/dashboard tools is desirable.
Key Competencies
Risk-based thinking
Analytical and critical thinking
Attention to detail
Vendor and stakeholder management
Strong documentation
Problem solving
Communication and negotiation
Ability to manage multiple assessments simultaneously
Understanding of confidentiality and sensitive information
Ability to work independently and as part of a cross-functional team
Key Performance Indicators
Success in this role will be measured through:
Timely completion of vendor risk assessments
Quality and accuracy of risk assessments
Effective identification and classification of third-party risks
Closure of vendor remediation items
Compliance with TPRM processes and SLAs
Quality of risk reporting and documentation
Stakeholder and vendor responsiveness
Reduction in overdue high-risk assessments and findings
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.