GRC - TPRM Specialist

Soffit Infrastructure Services (P) Ltd

Gurugram District

On-site

INR 700,000 - 1,500,000

Full time

23 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health insurance
Professional development

Job summary

Soffit Infrastructure Services (P) Ltd is seeking an Information Security professional to drive governance, risk and compliance with a focus on third-party risk assessments. You will assess inherent and residual risks, review vendor responses, and coordinate with stakeholders to ensure regulatory and internal security requirements are met.

The role involves managing multiple assessments, documenting findings, and guiding remediation with internal teams and external vendors.

Qualifications

  • End-to-end information security risk assessments of third parties, vendors, partners and service providers.
  • Inherent and residual risk profiling during onboarding, renewals and reassessments.
  • Review vendor information, security questionnaires and evidence provided.
  • Identify risk drivers, gaps, and remediation actions within a formal framework.
  • Coordinate with stakeholders to validate services, data access, and dependencies.
  • Maintain risk assessment documentation and status updates.

Responsibilities

  • Lead third-party risk management activities across onboarding and ongoing assessments.
  • Capture, evaluate and report inherent risk based on data sensitivity and services.
  • Coordinate with IT/security teams and business units for data access and scope.
  • Identify issues, gaps, and remediation needs and track closures.
  • Support updates to the security risk framework for third parties.

Skills

GRC knowledge
Third-Party risk
Vendor risk management
Regulatory compliance
Risk assessment
Stakeholder management
Documentation & reporting
Information security controls
Security risk framework
Communication skills

Tools

Security questionnaires
Risk assessment templates

Job description

The role involves managing Information Security Governance, Risk, and Compliance (GRC) with a strong focus on Third-Party / Vendor Risk Assessments. The incumbent will ensure that vendors, service providers, and partners comply with applicable regulatory, industry, and organizational information security requirements.

Key Responsibilities
Third-Party Risk Management (TPRM)
  • Conduct end-to-end information security risk assessments of third parties, vendors, partners, service providers.
  • Perform inherent risk profiling and residual risk evaluation while vendors onboarding, renewals and periodic reassessments
  • Assist in updating Master Vendor Inventory as per service details and classification
  • Review vendor-provided information, security questionnaires, and supporting evidence
  • Assess inherent security risks based on:
  • Nature of services provided
  • Type and sensitivity of data accessed, processed, or stored
  • Degree of system and network access
  • Regulatory and compliance impact
  • Assign inherent risk ratings (e.g., High / Medium / Low) to new vendors as per the organization’s security risk framework
  • Identify key risk drivers and control gaps at the inherent risk stage
  • Document assessment results and rationale in the designated risk assessment template or system
  • Perform detailed security risk assessments of third parties based on profiling criteria defined in the organization’s Security Risk Assessment Framework, including evaluation of service criticality, data sensitivity, access levels, regulatory impact, and inherent risk factors, to determine overall risk classification and required risk treatment actions.
  • Coordinate with internal business stakeholders and vendor service owners to
  • Collect and validate details related to vendor services and engagement scope
  • Clarify data access, system integration, and service dependencies
  • Identify, escalat, and report any issues, gaps, or support requirements impacting the risk assessment
  • Provide periodic status updates on assessment progress, risks, and timelines to relevant stakeholders
  • Assist in review and update of security risk framework for third parties
  • Support to business units in updating vendor and its services related information
  • Build and maintain relationships with internal stakeholders
  • Track progress and closure of open observations as per defined remediation plan for each assessment
  • Support in performing process related security assessments for the organization
  • Identify gaps, document risk findings, recommend corrective actions, and track remediation closures.
Stakeholder Management
  • Work closely with:
  • IT & Security teams
  • Business units
  • Vendors and external assessors
  • Provide awareness and guidance on third-Party security and regulatory expectations.
Technical & Domain Skills
  • Strong understanding of:
  • Information security controls
  • Third-Party risk frameworks
  • Regulatory compliance in BFSI
  • Hands-on experience with:
  • Vendor security assessments
  • Compliance reporting
Soft Skills
  • Strong analytical and risk assessment skills
  • Excellent documentation and report-writing abilities
  • Good stakeholder communication and negotiation skills
  • Ability to work independently and manage multiple assessments
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Risk Management (TPRM)
Third Party Risk Management (TPRM)

UST • Chennai District

On-site
INR 1,200,000 - 2,000,000
TPRM Analyst
TPRM Analyst

IDFC FIRST Bank • Mumbai

On-site
INR 1,200,000 - 1,800,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Third Party Risk Management (TPRM) Professional
Third Party Risk Management (TPRM) Professional

UST • Chennai District

On-site
INR 900,000 - 1,500,000
Jr. GRC Engineer
Jr. GRC Engineer

GAVS Technologies N.A., Inc • Chennai District

On-site
INR 900,000 - 1,500,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
Third Party Risk Management Professional (TPRM)
Third Party Risk Management Professional (TPRM)

Contactx Resource Management • Navi Mumbai

On-site
INR 600,000 - 1,000,000
Business Controls
Business Controls

Airtel Payments Bank • Gurugram District

On-site
INR 2,500,000 - 4,500,000
TPRM Manager / Senior Manager - Cyber
TPRM Manager / Senior Manager - Cyber

Cubical Operations LLP • Bengaluru

On-site
INR 2,800,000 - 5,200,000
TPRM Analyst – Team Lead / Assistant Manager –Chennai
TPRM Analyst – Team Lead / Assistant Manager –Chennai

Golden Opportunities • Chennai District

On-site
INR 1,800,000 - 2,400,000