Jr. GRC Engineer

GAVS Technologies N.A., Inc

Chennai District

On-site

INR 900,000 - 1,500,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

GAVS Technologies N.A., Inc. is seeking an experienced Jr. GRC Engineer in Chennai to lead and support the Third-Party Risk Management program.

The role focuses on managing vendor risk across cybersecurity, privacy, and compliance domains with collaboration across Procurement, Legal, and Information Security teams. The ideal candidate brings 2–4 years of TPRM experience, familiarity with SOC 1/2, ISO 27001, and risk reporting.

Qualifications

  • 2–4 years of experience in Third-Party Risk Management / Vendor Risk Management.
  • Strong experience conducting vendor due diligence and risk assessments.
  • Familiarity with ISO 27001, NIST, SOC 2, COBIT and related control frameworks.

Responsibilities

  • Lead end-to-end Third-Party Risk Management activities across the vendor lifecycle.
  • Conduct inherent risk assessments and due diligence reviews for new and existing vendors.
  • Evaluate vendor controls related to information security, cybersecurity, data privacy, business continuity, regulatory compliance, and operational risk.
  • Review and assess vendor security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, penetration testing reports, and security questionnaires.
  • Identify, document, and communicate vendor risks and recommended mitigation strategies.
  • Drive periodic vendor reassessments and continuous monitoring activities.

Skills

Vendor risk management
Third-party risk management
Risk assessment

Tools

ServiceNow GRC
Archer
MetricStream
OneTrust
ProcessUnity

Job description

## Jr. GRC Engineer11-09-2026 11:35:31Job\\_3047162 - 4 years* Chennai, Tamil Nadu, India (CHN)Job SummaryWe are seeking an experienced Third-Party Risk Management (TPRM) professional with 2 to 4 years of experience in managing vendor risk programs, conducting third-party due diligence, and driving risk governance across the vendor lifecycle. The ideal candidate will have strong expertise in assessing and managing third-party risks across cybersecurity, operational resilience, privacy, compliance, and business continuity domains.The role requires close collaboration with Procurement, Legal, Information Security, Compliance, and Business teams to ensure effective risk management of vendors and external partners. Exposure to Governance, Risk & Compliance (GRC) frameworks and risk management practices is desirable.Key ResponsibilitiesThird-Party Risk Management (Primary Focus)Lead end-to-end Third-Party Risk Management activities across the vendor lifecycle.Conduct inherent risk assessments and due diligence reviews for new and existing vendors.Evaluate vendor controls related to Information Security, Cybersecurity, Data Privacy, Business Continuity, Regulatory Compliance, and Operational Risk.Review and assess vendor security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, penetration testing reports, and security questionnaires.Identify, document, and communicate vendor risks and recommended mitigation strategies.Track remediation plans and ensure timely closure of identified control gaps.Drive periodic vendor reassessments and continuous monitoring activities.Support contract reviews by identifying and recommending risk and compliance requirements.Develop and maintain TPRM policies, standards, procedures, and risk assessment methodologies.Produce risk reports, dashboards, and metrics for management and governance forums.Partner with internal stakeholders to ensure risk-informed vendor onboarding and management decisions.Governance & Risk Support (Secondary Focus)Support broader GRC initiatives, including risk assessments, policy reviews, and compliance activities.Maintain risk registers and support risk reporting processes.Assist during internal and external audits related to third-party risk controls.Contribute to the enhancement of risk governance frameworks and control environments.Required Qualifications2 - 4 years of overall experience in Third-Party Risk Management / Vendor Risk Management.Strong experience conducting vendor due diligence and risk assessments.Solid understanding of third-party risk domains including:Cybersecurity RiskInformation SecurityData PrivacyOperational RiskRegulatory & Compliance RiskExperience reviewing SOC reports, ISO certifications, security questionnaires, and audit reports.Experience interacting with senior stakeholders, vendors, and cross-functional teams.Strong risk analysis, reporting, and communication skills.Preferred QualificationsWorking knowledge of GRC frameworks and enterprise risk management practices.Familiarity with ISO 27001, NIST, SOC 2, COBIT and related control frameworks.Experience with TPRM/GRC platforms such as ServiceNow GRC, Archer, MetricStream, OneTrust, ProcessUnity or similar tools.Good to have certifications such as CRISC, CISA, CISSP, CISM, or CTPRPIdeal Candidate ProfileA seasoned TPRM professional who has led vendor risk assessments and third-party governance programs, can independently engage with senior stakeholders, and possesses sufficient GRC knowledge to align third-party risk activities with the organization's overall risk and compliance framework. This role should ideally be 70–80% TPRM-focused and 20–30% GRC-oriented.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC - TPRM Specialist
GRC - TPRM Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 700,000 - 1,500,000
Health insurance
Professional development
GRC Specialist – Third-Party Risk Management
GRC Specialist – Third-Party Risk Management

LogicHive® • Bengaluru

On-site
INR 600,000 - 800,000
TPRM Manager / Senior Manager - Cyber
TPRM Manager / Senior Manager - Cyber

Cubical Operations LLP • Bengaluru

On-site
INR 2,800,000 - 5,200,000
Third Party Risk Management (TPRM)
Third Party Risk Management (TPRM)

UST • Chennai District

On-site
INR 1,200,000 - 2,000,000
Third Party Risk Management (TPRM) Professional
Third Party Risk Management (TPRM) Professional

UST • Chennai District

On-site
INR 900,000 - 1,500,000
GRC Analyst- Bengaluru-Contract Role_ Immediate Joiner Required
GRC Analyst- Bengaluru-Contract Role_ Immediate Joiner Required

CIEL HR • Bengaluru

On-site
INR 900,000 - 1,300,000
TPRM Assistant Manager - Cyber
TPRM Assistant Manager - Cyber

Cubical Operations LLP • Mumbai

On-site
INR 1,000,000 - 1,500,000
TPRM Analyst – Team Lead / Assistant Manager –Chennai
TPRM Analyst – Team Lead / Assistant Manager –Chennai

Golden Opportunities • Chennai District

On-site
INR 1,800,000 - 2,400,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
GRC Analyst
GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 600,000 - 900,000