An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Alvarez & Marsal is seeking an Associate in Security Governance, Risk & Compliance in Delhi, India. The role focuses on executing and improving the information security third-party risk program, assessing vendor risk across 100+ vendors annually, and coordinating with Privacy, Legal, IT, procurement, and business teams to produce timely responses.
Candidates should have 3–5 years of dedicated third-party risk management experience, familiarity with ISO 27001 and NIST, and the ability to
3-5 years of relelavant exp inclusing dedicated third-party risk management experience
Alvarez & Marsal (A&M) is a global consulting firm with more than 10,000 entrepreneurial, action- and results-oriented professionals across over 40 countries. A&M takes a hands-on approach to solving client problems and helping organizations reach their potential. Its culture values independent thinking, collaboration, and measurable impact, guided by Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity. Established in India in 2023, A&M Global Capability Center Private Limited partners with leadership across business units and geographies to enable efficient service delivery, specialized talent, competitive pricing, faster delivery, automation, and digital and analytics capabilities. The GCC supports end-to-end case delivery and thought leadership rather than traditional back-office work. It serves the Americas, EMEA, and APAC across industries including Consumer and Retail, Healthcare, Software and Technology, Automotive and Industrials, Hospitality and Leisure, Energy and Natural Resources, and Financial Services. The rapidly growing center already has more than 500 team members.
The Security GRC Associate will own execution and improvement of the Information Security third-party risk management program. Through GRC platforms, assessment workflows, risk registers, reporting routines, and documented controls, the role will identify, evaluate, monitor, and help remediate vendor risks. The associate will complete client security questionnaires, review information security contract terms, and coordinate with Privacy, Legal, IT, procurement, and business stakeholders to produce accurate, timely responses. Success requires dedicated third-party risk management experience, including assessing at least 100 vendors annually, managing remediation within defined SLAs, and translating technical security requirements into practical business language. The role will strengthen governance visibility, support regulatory and policy compliance, and improve the firm's ability to make risk-based decisions across vendor and client engagements.
You will bring 4-8 years of total relevant experience, including 3-5 years dedicated to third-party risk management, governance, risk, compliance, or information security. Your background should demonstrate ownership of vendor security assessments and audits, with experience managing risk reviews for at least 100 vendors in a year. You will be comfortable using GRC and third-party risk management platforms to document findings, assign treatments, monitor remediation, and produce management reporting. You can complete client security questionnaires within agreed SLAs, maintain reliable evidence and response libraries, and collaborate with Privacy, Legal, IT, procurement, and business teams. You will understand security frameworks such as ISO 27001 and NIST, relevant regulatory expectations, security controls, and information security contract clauses. A bachelor's degree in Information Security, Risk Management, Business, or a related field is required. CRISC, CTPRP, CISSP, or CISM certification is advantageous. You are analytical, detail-oriented, organized, and able to prioritize multiple deadlines without losing accuracy. Most importantly, you communicate risk clearly, apply sound judgment, and connect control decisions to business impact.