Senior Manager - Vendor Security Risk

SBI Cards and Payment Services Private Ltd.

Gurugram District

On-site

INR 1,800,000 - 2,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SBI Cards and Payment Services Private Ltd. in Gurugram, Haryana, invites application for a role focused on vendor risk assessments from an information security perspective. You will evaluate third-party security controls and help mitigate risks across the SBI Card ecosystem.

You will work with cross-functional teams to ensure timely remediation, maintain control effectiveness, and uphold standards such as ISO27001, PCI-DSS and cloud security requirements.

Qualifications

  • Bachelor’s degree in Computer Science or Information Security.
  • Knowledge of PCI-DSS and ISO27001 controls.
  • Experience in information security and risk assessments.
  • Certifications in ISO27001:2013 LA, CISA, CISM, Cloud Security (preferred).

Responsibilities

  • Conduct vendor risk assessments from information security perspective using ISO27001:2013, PCI-DSS and cloud security controls.
  • Ensure identified risks are addressed and tracked with remedial plans and timelines.
  • Review secure processes at vendor end for SBI Card integration.
  • Prepare assessment questionnaires and monitor compliance with standards.
  • Provide guidance to business users and drive remediation with cross-functional teams.

Skills

Detail Orientation
Process Orientation
Stakeholder Management
Analytical ability

Education

Bachelor’s Degree in Computer Science / Information Security or any other relevant discipline

Job description

SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto 'Make Life Simple' inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.

SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, color, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.

Join us to shape the future of digital payment in India and unlock your full potential.

What’s in it for YOU

  • SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
  • Admirable work deserves to be rewarded. We have a well curated bouquet of rewards and recognition program for the employees
  • Dynamic, Inclusive and Diverse team culture
  • Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
  • Commitment to the overall development of an employee through comprehensive learning & development framework

Role Purpose

Responsible for conducting vendor risk assessments from information security perspective based on, ISO27001:2013, PCI-DSS, Cloud security control framework etc. and to ensure identified risks are addressed appropriately in timely manner. The role is also responsible for assessing and identifying risks associated with third parties part of SBI Card extended echo system, analyzing identified risks and ensure timely reporting and remediation of the same and working closely with cross-functional teams within SBI Card and vendor /partner teams to manage security risks associated with third parties and get the same addressed within a agreed timeline.

Role Accountability

  • Conduct vendor risk assessments from information security perspective using, ISO27001:2013, PCI-DSS, Cloud security control framework etc.
  • Ensure identified risks are addressed appropriately
  • Track and report status of open observations, remedial plan and timelines for resolution
  • Perform remediation testing once identified observations have been marked as resolved
  • Review and establish secure processes and systems at vendor's end for integration with SBI Card
  • Prepare and update assessment questionaries basis various applicable standards and industry good practices such as ISO 27001, PCI-DSS etc.
  • Monitor vendor compliance, undertake vendor evaluations based on various industry standard and regulatory compliance perspective and suggest feedback / recommendations to the - business / vendor for mitigating identified risk
  • Work with appropriate business users to ensure that for any identified risk require mitigating action along with timeline is agreed and tracked the same for successful closure
  • Act as a subject matter expert to assist the business in identifying and mitigating risks pertaining to their vendor relationships
  • Deliver continuous training and awareness to Business partners on various compliance requirements such as ISO 27001, PCI-DSS etc.
  • Perform process documentation and compliance adherence

Measures of Success

  • Number of vendor risk assessments conducted successfully
  • Timely and accurate identification and reporting of information security risks pertaining to third parties/vendors
  • Timely and accurate delivery of updates, presentations, assessment reports etc. to relevant stakeholders
  • Tracking of audit findings and driving to closure within defined timelines
  • Process Adherence as per MOU

Technical Skills / Experience / Certifications

  • Knowledge in multiple information security technologies and their strengths and shortcomings
  • Knowledge of common assessment control techniques
  • Understanding of security controls from people, process and technology perspective
  • Understanding of security architectural principles and standards
  • Experience in system security, network security and information security, control objectives part of ISMS, Technology risk and compliance, BCP & DR planning, Security operations and Cloud security
  • Knowledge of standard security processes and guidelines
  • Experience in implementing or accessing compliance against PCI-DSS, ISO27001 requirements
  • Industry-standard certifications such as ISO27001:2013 LA, CISA, CISM, Cloud Security etc.

Competencies critical to the role

  • Detail Orientation
  • Process Orientation
  • Stakeholder Management
  • Analytical ability

Qualification

Bachelor’s Degree in Computer Science / Information Security or any other relevant discipline

Preferred Industry

FSI

Job Info
  • Job Identification 21449
  • Posting Date 08/07/2026, 06:46 AM
  • Apply Before 08/30/2026, 06:30 PM
  • Locations DLF Cyber City,Tower B, Block 2, Building 3, Gurugram, Haryana, 122002, IN
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager - Vendor Risk Management & Compliance
Assistant Manager - Vendor Risk Management & Compliance

SBI Card • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Wellness program
Rewards program
Diverse team culture
+3
Senior Manager - Data Governance
Senior Manager - Data Governance

SBI Card • Bengaluru

On-site
INR 900,000 - 1,300,000
Manager - Senior Incident Analyst
Manager - Senior Incident Analyst

SBI Cards and Payment Services Private Ltd. • Gurugram District

On-site
INR 1,500,000 - 1,900,000
Assistant Vice President - Vulnerability Management
Assistant Vice President - Vulnerability Management

SBI Card • Gurugram District

On-site
INR 1,200,000 - 2,400,000
Manager - Cloud Security
Manager - Cloud Security

SBI Card • Gurugram District

On-site
INR 1,800,000 - 2,600,000
Specialist, Vendor Risk Manager, Technology and Operations
Specialist, Vendor Risk Manager, Technology and Operations

DBS Bank • Mumbai

On-site
INR 1,500,000 - 2,000,000
Senior Executive - Screening (Sampling)
Senior Executive - Screening (Sampling)

SBI Cards and Payment Services Private Ltd. • Gurugram District

On-site
INR 600,000 - 900,000
PCI-DSS Consultant
PCI-DSS Consultant

Riskpro India Ventures • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Finance Analyst I
Finance Analyst I

KFC Corporation • Gurgaon

On-site
INR 800,000 - 1,200,000
Assistant Manager - Infosec
Assistant Manager - Infosec

Crisil • Kurla

On-site
INR 1,400,000 - 2,400,000