GRC – Information Security Third‑Party Risk Assessment Specialist

Soffit Infrastructure Services (P) Ltd

Gurugram District

On-site

INR 1,200,000 - 2,100,000

Full time

4 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Soffit Infrastructure Services (P) Ltd is seeking a senior information security GRC professional to lead third‑party risk assessments. You will evaluate vendors, service providers, and partners against regulatory, industry, and organizational requirements, and coordinate risk treatments with IT, procurement, and business units.

You will document risk findings, support ongoing risk management, and help strengthen the organization’s risk framework with internal stakeholders.

Qualifications

  • Role requires governance, risk and compliance (GRC) with focus on third‑party risk assessments.
  • Experience evaluating vendor risk and regulatory compliance in BFSI sectors.
  • Ability to map controls, assess inherent and residual risk, and document findings.

Responsibilities

  • Conduct end‑to‑end information security risk assessments of third parties, vendors, and partners.
  • Profile inherent and residual risk during onboarding, renewals, and reassessments.
  • Review vendor information, security questionnaires, and evidence to determine risk.
  • Coordinate with IT, security, procurement, and business units on risk findings and remediation.
  • Track remediation actions and provide status updates to stakeholders.

Skills

Information security controls
Third-party risk
BFSI compliance
Vendor security assessments
Risk rating methodologies
Compliance reporting
Analytical skills
Documentation
Stakeholder communication

Job description

Role Summary

The role involves managing Information Security Governance, Risk, and Compliance (GRC) with a strong focus on Third‑Party / Vendor Risk Assessments. The incumbent will ensure that vendors, service providers, and partners comply with applicable regulatory, industry, and organizational information security requirements.

Key Responsibilities
Third‑Party Risk Management (TPRM)
  • Conduct end‑to‑end information security risk assessments of third parties, vendors, partners, service providers.
  • Perform inherent risk profiling and residual risk evaluation while vendors onboarding, renewals and periodic reassessments
  • Assist in updating Master Vendor Inventory as per service details and classification
  • Review vendor‑provided information, security questionnaires, and supporting evidence
  • Assess inherent security risks based on:
  • Nature of services provided
  • Type and sensitivity of data accessed, processed, or stored
  • Degree of system and network access
  • Regulatory and compliance impact
  • Assign inherent risk ratings (e.g., High / Medium / Low) to new vendors as per the organization’s security risk framework
  • Identify key risk drivers and control gaps at the inherent risk stage
  • Document assessment results and rationale in the designated risk assessment template or system
  • Perform detailed security risk assessments of third parties based on profiling criteria defined in the organization’s Security Risk Assessment Framework, including evaluation of service criticality, data sensitivity, access levels, regulatory impact, and inherent risk factors, to determine overall risk classification and required risk treatment actions.
  • Coordinate with internal business stakeholders and vendor service owners to
  • Collect and validate details related to vendor services and engagement scope
  • Clarify data access, system integration, and service dependencies
  • Identify, escalation, and report any issues, gaps, or support requirements impacting the risk assessment
  • Provide periodic status updates on assessment progress, risks, and timelines to relevant stakeholders
  • Assist in review and update of security risk framework for third parties
  • Support to business units in updating vendor and its services related information
  • Build and maintain relationships with internal stakeholders
  • Track progress and closure of open observations as per defined remediation plan for each assessment
  • Support in performing process related security assessments for the organization
  • Identify gaps, document risk findings, recommend corrective actions, and track remediation closures.
Stakeholder Management
  • Work closely with:
  • IT & Security teams
  • Procurement & Legal
  • Business units
  • Vendors and external assessors
  • Provide awareness and guidance on third‑party security and regulatory expectations.
Required Skills & Competencies
Technical & Domain Skills
  • Strong understanding of:
  • Information security controls
  • Third‑party risk frameworks
  • Regulatory compliance in BFSI
  • Hands‑on experience with:
  • Vendor security assessments
  • Risk rating methodologies
  • Compliance reporting
Soft Skills
  • Strong analytical and risk assessment skills
  • Excellent documentation and report‑writing abilities
  • Good stakeholder communication and negotiation skills
  • Ability to work independently and manage multiple assessments
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC - TPRM Specialist
GRC - TPRM Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Third Party Risk Management (TPRM)
Third Party Risk Management (TPRM)

UST • Chennai District

On-site
INR 1,200,000 - 2,000,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
Third Party Risk Management (TPRM) Professional
Third Party Risk Management (TPRM) Professional

UST • Chennai District

On-site
INR 900,000 - 1,500,000
Business Controls
Business Controls

Airtel Payments Bank • Gurugram District

On-site
INR 2,500,000 - 4,500,000
Jr. GRC Engineer
Jr. GRC Engineer

GAVS Technologies N.A., Inc • Chennai District

On-site
INR 900,000 - 1,500,000
GRC Specialist – Third-Party Risk Management
GRC Specialist – Third-Party Risk Management

LogicHive® • Bengaluru

On-site
INR 600,000 - 800,000
TPRM Analyst
TPRM Analyst

IDFC FIRST Bank • Mumbai

On-site
INR 1,200,000 - 1,800,000
Vendor Risk Analyst
Vendor Risk Analyst

Kaufman Rossin • Bengaluru

On-site
INR 800,000 - 1,200,000
Work-life balance
Hybrid work policy
People-first company culture