Sr Analyst, Vendor Risk & Cybersecurity Policy Management

PVH Corp.

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

PVH Corp. seeks a Senior Analyst to manage third-party cyber risk and maintain the enterprise policy framework.

You will collaborate with procurement, legal, privacy, and technology teams to evaluate cybersecurity risks posed by vendors while keeping security standards current and aligned with regulatory requirements. The role requires translating technical cybersecurity concepts into practical business guidance and working in EST time zones when needed.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or related discipline (or equivalent experience).
  • 2–5 years of experience in cybersecurity, IT risk, governance, compliance, or vendor risk management.
  • Understanding of third-party risk management, cybersecurity fundamentals, information security governance, and risk assessment methodologies.
  • Familiarity with NIST CSF, ISO 27001, and CIS Controls.
  • Experience reviewing SOC reports, ISO certifications, and security questionnaires.

Responsibilities

  • Conduct cybersecurity risk assessments for prospective and existing third-party vendors.
  • Review SOC 1/SOC 2 reports, ISO 27001 certifications, penetration test summaries, security questionnaires, and BC/DR documentation.
  • Evaluate vendor security posture and identify potential risks.
  • Document assessment findings and provide risk ratings and remediation recommendations.
  • Partner with Procurement, Legal, Privacy, Compliance, and business stakeholders during vendor onboarding and renewal processes.
  • Track remediation activities and monitor outstanding vendor risks through closure.
  • Support periodic reassessments of critical suppliers.
  • Maintain third-party risk metrics and dashboards for management reporting.
  • Maintain the enterprise cybersecurity policy, standards, and supporting guideline library.
  • Coordinate policy reviews and ensure alignment with NIST CSF, ISO 27001, CIS Controls, PCI-DSS, SOX, GDPR and privacy requirements.
  • Track policy exceptions and support risk acceptance; support publication, version control, approvals, and communication.
  • Assist with development of new cybersecurity standards and audits.

Skills

Risk Assessment
Policy Management
Documentation
Stakeholder Management
Analytical Thinking
Communication
Attention to Detail
Problem Solving

Education

Bachelor's degree in Cybersecurity / IT / IS

Tools

ProcessUnity
AuditBoard
ServiceNow
Power BI
GRC platforms

Job description

About Us

We are brand builders who focus our passion and creativity to build Calvin Klein and TOMMY HILFIGER into the most desirable lifestyle brands in the world and at the same time position PVH as one of the best-performing brand groups in our sector. Guided by our values and enabled by our scale and global reach, we are driving fashion forward for good, as one team with one vision and one plan. That’s the Power of Us, that’s the Power of PVH+.

About Us

We are brand builders who focus our passion and creativity to build Calvin Klein and TOMMY HILFIGER into the most desirable lifestyle brands in the world and at the same time position PVH as one of the best-performing brand groups in our sector. Guided by our values and enabled by our scale and global reach, we are driving fashion forward for good, as one team with one vision and one plan. That’s the Power of Us, that’s the Power of PVH+. One of PVH’s greatest strengths is our people. Our collective desire is to create a workplace environment where every individual is valued, and every voice is heard, and we are committed to fostering an inclusive and diverse community of associates with a strong sense of belonging. Learn more about Inclusion & Diversity at PVH here.

Position Summary

The Senior Analyst, Vendor Risk & Cybersecurity Policy Management is responsible for supporting the organization's third-party cyber risk management program and maintaining the enterprise information security policy and standards framework. This role partners with business stakeholders, procurement, legal, privacy, and technology teams to evaluate cybersecurity risks associated with third parties while ensuring internal security policies and standards remain current, effective, and aligned with business objectives, regulatory requirements, and industry best practices.

The ideal candidate is analytical, organized, and capable of translating technical cybersecurity concepts into practical business guidance.

This position requires to work in EST time Zone.

Key Responsibilities
Third-Party Cyber Risk Management
  • Conduct cybersecurity risk assessments for prospective and existing third-party vendors.
  • Review SOC 1/SOC 2 reports, ISO 27001 certifications, penetration test summaries, security questionnaires, and business continuity/disaster recovery documentation.
  • Evaluate vendor security posture and identify potential risks.
  • Document assessment findings and provide risk ratings and remediation recommendations.
  • Partner with Procurement, Legal, Privacy, Compliance, and business stakeholders throughout vendor onboarding and renewal processes.
  • Track remediation activities and monitor outstanding vendor risks through closure.
  • Support periodic reassessments of critical suppliers.
  • Maintain third-party risk metrics and dashboards for management reporting.
Cyber Policy & Standards Management
  • Maintain the enterprise cybersecurity policy, standards, and supporting guideline library.
  • Coordinate scheduled reviews and updates with policy owners and subject matter experts.
  • Ensure policies align with NIST CSF, ISO 27001, CIS Controls, PCI-DSS, SOX, GDPR and applicable regulatory/privacy requirements.
  • Track policy exceptions and support the risk acceptance process.
  • Support policy publication, version control, approvals, and communication activities.
  • Assist with development of new cybersecurity standards supporting emerging technologies and business initiatives.
  • Support internal and external audits related to cybersecurity governance.
Governance & Reporting
  • Prepare dashboards and reporting on vendor assessments, remediation actions, policy review compliance, policy exceptions, and third-party risk trends.
  • Support risk committees and governance meetings through preparation of reports and presentations.
  • Maintain documentation supporting audit and regulatory inquiries.
Continuous Improvement
  • Identify opportunities to improve vendor assessment processes through automation and workflow optimization.
  • Recommend enhancements to policy lifecycle management processes.
  • Stay informed of emerging cybersecurity threats, regulatory changes, and industry best practices.
  • Support implementation and enhancement of Governance, Risk, and Compliance (GRC) technologies.
Qualifications

Required

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or related discipline (or equivalent experience).
  • 2–5 years of experience in cybersecurity, IT risk, governance, compliance, or vendor risk management.
  • Understanding of third-party risk management, cybersecurity fundamentals, information security governance, and risk assessment methodologies.
  • Familiarity with NIST CSF, ISO 27001, and CIS Controls.
  • Experience reviewing SOC reports, ISO certifications, and security questionnaires.
  • Strong analytical, documentation, communication, and organizational skills.

Preferred

  • Experience with ProcessUnity, AuditBoard, and ServiceNow.
  • Experience maintaining information security policies and standards.
  • Knowledge of AWS, Azure, or GCP security concepts.
  • Understanding of GDPR and CCPA.
  • Experience supporting SOX, PCI DSS, or ISO audits.
Technical Skills
  • Microsoft Office Suite (Excel, PowerPoint, Word)
  • Power BI (Dashboards)
  • GRC platforms and workflow development
  • Risk assessment methodologies
  • Documentation management
  • Dashboard and reporting tools
  • Basic understanding of networking, cloud, identity management, and security controls
Success Measures
  • Timely completion of vendor cyber risk assessments.
  • Reduction in outstanding vendor remediation items.
  • On-time completion of annual policy and standards reviews.
  • Quality and consistency of policy documentation.
  • Accuracy and effectiveness of governance reporting.
  • Positive audit outcomes with minimal policy-related findings.
  • Continuous improvement of vendor risk and policy management processes.
Core Competencies
  • Risk Analysis
  • Critical Thinking
  • Written Communication
  • Stakeholder Management
  • Attention to Detail
  • Problem Solving
  • Collaboration
  • Business Acumen
  • Process Improvement
Continuous Learning

PVH Corp. or its subsidiary ("PVH") is an equal opportunity employer and considers all applicants for employment on the basis of their individual capabilities and qualifications without regard to race, ethnicity, color, sex, gender identity or expression, age, religion, national origin, citizenship status, sexual orientation, genetic information, physical or mental disability, military status or any other characteristic protected under federal, state or local law. In addition to complying with all applicable laws, PVH is also committed to ensuring that all current and future PVH associates are compensated solely on job-related factors such as skill, ability, educational background, work quality, experience and potential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Workday HR Systems Specialist
Senior Workday HR Systems Specialist

PVH Corp. • India

On-site
INR 900,000 - 1,300,000
Supply Planning Analyst
Supply Planning Analyst

PVH Corp. • India

On-site
INR 800,000 - 1,400,000
Network Engineer
Network Engineer

PVH Corp. • Bengaluru

On-site
INR 600,000 - 900,000
End to End Product Data Analyst
End to End Product Data Analyst

PVH Corp. • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Salesforce Commerce Cloud Front End PWA Developer
Salesforce Commerce Cloud Front End PWA Developer

PVH Corp. • India

On-site
INR 2,500,000 - 4,000,000
Sr ABAP Developer
Sr ABAP Developer

PVH Corp. • India

On-site
INR 2,500,000 - 4,000,000
Senior DevOps Engineer
Senior DevOps Engineer

PVH Corp. • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Payroll Application Analyst (Workday Payroll)
Payroll Application Analyst (Workday Payroll)

PVH Corp. • Bengaluru

On-site
INR 800,000 - 1,200,000
Collections Specialist-1
Collections Specialist-1

PVH Corp. • India

Hybrid
INR 450,000 - 750,000
Hybrid work model
Senior Specialist, End to End Master Data
Senior Specialist, End to End Master Data

PVH Corp. • Bengaluru

On-site
INR 5,500,000 - 7,500,000