Specialist, Vendor Risk Manager, Technology and Operations

DBS Bank

Mumbai

On-site

INR 1,500,000 - 2,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

A leading banking institution in Mumbai is looking for a Specialist, Vendor Risk Manager in Technology and Operations. The role entails developing a comprehensive risk management program for third-party relationships, overseeing security assessments, and ensuring compliance with industry standards. Ideal candidates will possess in-depth knowledge of security domains and strong skills in risk management and stakeholder engagement. This full-time position offers a chance to work in a dynamic environment focused on operational excellence.

Qualifications

  • Strong understanding and practical experience with Third-Party Risk Management (TPRM) principles.
  • In-depth knowledge of information security domains.
  • Proven ability to conduct security assessments.

Responsibilities

  • Develop and improve the Third-Party Risk Management framework.
  • Conduct information security assessments of third parties.
  • Advise on security mitigating controls for various technologies.

Skills

Third-Party Risk Management principles
Information security domains (network, server, endpoint)
Cloud security (Azure/AWS/GCP/OCI)
Analytical and problem-solving skills

Job description

Overview

Specialist, Vendor Risk Manager, Technology and Operations – DBS Bank

Join to apply for the Specialist, Vendor Risk Manager, Technology and Operations role at DBS Bank

Job Description

This role is responsible for establishing, implementing, and maintaining a robust third-party risk management program. This role involves overseeing the assessment and continuous monitoring of third-party vendors and partners to identify, evaluate, and mitigate information security, compliance, and operational risks. This role will ensure that third-party relationships adhere to internal policies, industry standards, and regulatory requirements, protecting the organization's assets and reputation.

Key Responsibilities
  • Program Management: Develop, implement, and continuously improve the organization's Third-Party Risk Management (TPRM) framework, policies, procedures, and guidelines.
  • Perform comprehensive end-to-end and in-depth information security assessments of third parties throughout their lifecycle (onboarding, ongoing, offboarding).
  • Conduct due diligence reviews of prospective and existing third-party vendors, assessing their security controls, compliance posture, and operational capabilities.
  • Advise and assess security mitigating controls for Network, Server, Endpoint security, Data protection (PII, Cards), Cloud security (Azure/AWS/GCP/OCI), Encryption, and API security.
  • Review implementation of standards such as PCI-DSS, PCI-PIN, and PA-DSS as applicable to third parties.
  • Continuous Monitoring: Establish and manage processes for the periodic assessment and continuous monitoring of third-party and ecosystem partners' security posture and compliance.
Risk Mitigation & Advisory
  • Identify potential risks associated with third-party engagements and projects, advise on effective mitigation strategies.
  • Provide expert guidance on control implementation for the protection of sensitive data and adherence to security-by-design principles.
Reporting & Stakeholder Engagement
  • Responsible for audit planning, report review, and reporting on third-party risk posture to senior management and other stakeholders.
  • Liaise with business units on new third-party requirements, ensuring risk is considered from the outset.
  • Collaborate with internal teams (e.g., Legal, Procurement, IT, CISO team, Group Security) to ensure a consistent and integrated approach to third-party risk management.
  • Work with the CISO team on regulatory requirements and submissions pertaining to Digital Payment security for third-party engagements.
  • Liaise with business and partners on compliance and regulatory assurance related to third parties.
Compliance & Standards
  • Ensure third-party engagements comply with relevant laws, regulations, and industry standards.
  • Review and validate third-party adherence to recognized security frameworks and standards such as ISMS (ISO 27001), SOC (Service Organization Control reports), and NIST CSF.
Requirements
  • Strong understanding and practical experience with Third-Party Risk Management (TPRM) principles and best practices.
  • In-depth knowledge of information security domains, including network, server, endpoint, data protection, cloud security (Azure/AWS/GCP/OCI), encryption, and API security.
  • Clear understanding of application security assessments, source code review, and VAPT (Vulnerability Assessment and Penetration Testing).
  • Strong fundamentals of Defense-in-Depth security and SDLC (Software Development Life Cycle) processes.
  • Excellent understanding of industry standards and frameworks such as PCI-DSS, PCI-PIN, PA-DSS, ISMS (ISO 27001), SOC, and NIST CSF.
  • Proven ability to conduct security assessments and interpret security reports.
  • Strong analytical, problem-solving, and communication skills to effectively engage with internal and external stakeholders.
  • Experience with audit planning and reporting.
  • Ability to work independently and manage multiple third-party relationships concurrently.
Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Information Technology
Industries
  • Banking
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Business Controls
Business Controls

Airtel Payments Bank • Gurugram District

On-site
INR 2,500,000 - 4,500,000
GRC – Information Security Third‑Party Risk Assessment Specialist
GRC – Information Security Third‑Party Risk Assessment Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 1,200,000 - 2,100,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
Third Party Risk Management (TPRM)
Third Party Risk Management (TPRM)

UST • Chennai District

On-site
INR 1,200,000 - 2,000,000
Third-Party Security Analyst
Third-Party Security Analyst

Tradeweb Europe Limited • Bengaluru

On-site
INR 350,000 - 550,000
Global Banking & Market - Vendor Management(TPRM) - Analyst - Bengaluru
Global Banking & Market - Vendor Management(TPRM) - Analyst - Bengaluru

Goldman Sachs • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Vendor Management Senior Analyst
Vendor Management Senior Analyst

Deutsche Bank • Maharashtra

On-site
INR 1,400,000 - 1,800,000
Best in class leave policy
Gender neutral parental leaves
Childcare assistance reimbursement
+3
Global Banking & Market - Vendor Management(TPRM) - Analyst - Bengaluru
Global Banking & Market - Vendor Management(TPRM) - Analyst - Bengaluru

Goldman Sachs Group, Inc. • Bengaluru

On-site
INR 1,500,000 - 2,800,000
T&T | Cyber: CST | Deputy Manager | Third Party Risk Management | Bengaluru
T&T | Cyber: CST | Deputy Manager | Third Party Risk Management | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 1,800,000 - 3,000,000