Associate Cybersecurity Risk Analyst

Finthrive

Gurugram District

Hybrid

INR 900,000 - 1,300,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Finthrive is seeking a security-focused professional to manage third-party risk and vendor assessments in a fast-paced SaaS environment. You will evaluate security postures, review evidence such as SOC 2 Type II and ISO 27001, and drive remediation with cross-functional teams.

You will partner with Legal, Procurement, IT, and Engineering to ensure security requirements are embedded in contracts, respond to security inquiries, and maintain standardized responses for cross-functional teams.

Qualifications

  • 1-3 years of relevant experience in information security, third party risk management, GRC, or due diligence response.
  • Experience responding to customer security questionnaires and assessing vendor security posture against frameworks (SOC 2, HIPAA, ISO 27001).
  • Working knowledge of security control domains: IAM, vulnerability management, encryption, logging/monitoring, incident response, and data handling.

Responsibilities

  • Execute and mature the day-to-day TPRM program, including risk-based vendor tiering aligned to data sensitivity, criticality, and regulatory obligations.
  • Perform vendor security assessments using questionnaires and evidence (SIG, CAIQ, custom) and review assurance artifacts such as SOC 2 Type II, ISO 27001, HITRUST, PCI, and pen test results.
  • Document findings, drive remediation to closure, and manage time-bounded risk acceptances and exceptions.
  • Support continuous monitoring (security ratings, attestation refresh) and secure vendor offboarding.
  • Partner with Legal and Procurement to embed security requirements in contracts (security addendums, DPAs, breach notification, right to audit).
  • Translate complex security concepts into customer-friendly language and represent FinThrives security posture to prospects and customers.

Skills

Security risk management
Vendor risk assessments
Information security
Communication skills

Education

Bachelor's degree in IT/Information Security

Tools

Whistic
Vanta
SafeBase

Job description

Role & responsibilities



  • Third Party Security Risk Management

  • Execute and mature the day-to-day TPRM program, including risk-based vendor tiering aligned to data sensitivity, criticality, and regulatory obligations.

  • Perform vendor security assessments using questionnaires and evidence (SIG, CAIQ, custom) and review assurance artifacts such as SOC 2 Type II, ISO 27001, HITRUST, PCI, and pen test results.

  • Document findings, drive remediation to closure, and manage time-bounded risk acceptances and exceptions.

  • Support continuous monitoring (security ratings, attestation refresh) and secure vendor offboarding.

  • Partner with Legal and Procurement to embed security requirements in contracts (security addendums, DPAs, breach notification, right to audit).

  • Customer Security Inquiries

  • Manage and respond to customer security questionnaires, RFPs, and due diligence requests.

  • Maintain a repository of standardized responses and supporting documentation to enable cross-functional team independence.

  • Translate complex security concepts into customer-friendly language and represent FinThrives security posture to prospects and customers.

  • Cross-Functional Collaboration & Tooling

  • Work closely with IT, Engineering, Product, and Sales to ensure timely, accurate completion of both vendor and customer reviews.

  • Implement and manage tools (e.g., Whistic, Vanta, security ratings platforms) to streamline and automate inquiry and assessment workflows.

  • Produce metrics and dashboards covering vendor risk posture, remediation aging, inquiry volume, and SLA performance.

  • Product, Infrastructure & Compliance Knowledge

  • Maintain a strong understanding of FinThrives products, SaaS architecture, data flows, and security controls.

  • Support FinThrives Audit and Compliance program by aligning activities to HITRUST, HIPAA, SOC 2, NIST, and ISO 27001 requirements.


Preferred candidate profile



  • 1-3 years of relevant experience in information security, third party risk management, GRC, or due diligence response. \\

  • Experience responding to customer security questionnaires and assessing vendor security posture against frameworks (SOC 2, HIPAA, ISO 27001).

  • Working knowledge of security control domains: IAM, vulnerability management, encryption, logging/monitoring, incident response, and data handling.

  • Familiarity with IT infrastructure (servers, firewalls, load balancers, databases), SaaS architecture, and web applications.

  • Strong written and verbal communication skills, with the ability to explain technical

  • concepts to non-technical audiences.

  • Customer-centric mindset with experience collaborating with Sales teams and customers.

  • Proficiency with Microsoft Office (Word, Excel, PowerPoint, Visio).

  • Bachelors degree (IT, Information Security, or Business Administration preferred).

  • Preferred Skills

    • Security+ or similar certification.

    • Familiarity with HITRUST, NIST, PCI DSS, and GDPR/CCPA.

    • Experience with Trust Center, questionnaire management, and continuous monitoring platforms (SafeBase, Whistic, Vanta).

    • Familiarity with cloud provider assurance models (AWS/Azure/GCP shared responsibility) and SaaS risk patterns.


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Cybersecurity Risk Analyst
Associate Cybersecurity Risk Analyst

FinThrive, Inc. • Pune District

On-site
INR 900,000 - 1,300,000
Term life, Accidental & Medical | Ins
Meal and Transport arrangements
Senior Third-Party Risk Consultant
Senior Third-Party Risk Consultant

EY • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Manager Risk Management
Manager Risk Management

Moder • Bengaluru

On-site
INR 1,200,000 - 2,200,000
Security Consultant (TVA)
Security Consultant (TVA)

NTT DATA BUSINESS SOLUTIONS • Mumbai

Hybrid
INR 1,800,000 - 2,800,000
Security Trust Analyst
Security Trust Analyst

RingCentral • Bengaluru Urban

Hybrid
INR 150,000 - 210,000
GRC /SOC Analyst
GRC /SOC Analyst

fulcrumdigital • Pune District

Hybrid
INR 600,000 - 900,000
Audit & Compliance Analyst
Audit & Compliance Analyst

Codincity Digital Technologies • Chennai District

On-site
INR 1,200,000 - 1,800,000
Third Party RIsk management consultant
Third Party RIsk management consultant

Visionet Systems Inc. • Bengaluru

On-site
INR 3,500,000 - 5,500,000