Staff IT Risk Analyst

Micron

Hyderabad

On-site

INR 4,000,000 - 7,000,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Micron Technology is seeking a Senior TPCRM Staff Analyst to shape and govern external supplier risk across Information Security, Privacy, Compliance, and Legal. You will lead complex risk assessments, develop TPCRM runbooks, and advise senior stakeholders on remediation priorities.

The role requires seven years in information security and third‑party risk management, familiarity with tools like ServiceNow and Archer, and strong regulatory knowledge. Hybrid work with global partners is possible.

Qualifications

  • Seven years of experience in Information Security, Cyber Risk Management, and Privacy practices.
  • Ability to lead complex supplier risk issues and influence cross‑functional stakeholders.
  • Experience with third‑party risk programs, governance, and regulatory alignment.
  • Knowledge of frameworks like NIST, ISO, GDPR, SOX, and PCI DSS.
  • Experience improving TPCRM tools, analytics, dashboards, and executive reporting.

Responsibilities

  • Serve as SME for enterprise supplier risk governance, regulation alignment, and assessment quality.
  • Lead complex third‑party risk assessments involving high-risk suppliers and data.
  • Shape TPCRM methodology, criteria, and evidence expectations for scalable outcomes.
  • Perform gap analysis against ISO 27001, NIST, GDPR, and other standards; advise remediation priorities.
  • Lead risk treatment strategies including mitigation planning and supplier escalation.
  • Develop and mature TPCRM policies, runbooks, and governance processes.
  • Lead supplier audits, risk reporting, cross‑functional groups, and escalation bands.
  • Translate risk insights into actionable themes, program enhancements, and mitigations.
  • Interpret risk tolerance, contracts, and business impact to guide decisions on risk acceptance or transfer.
  • Collaborate with procurement, legal, information security, and vendor management to embed TPCRM expectations.
  • Mentor analysts and drive automation and reporting maturity across regions.

Skills

Information Security
Cyber Risk Management
Third-Party Risk Management
Privacy practices
Regulatory Compliance

Education

Bachelor's Degree in Computer Science/Management Information Systems/Business Administration
Master's degree preferred

Tools

ServiceNow
Optro
Archer
AuditBoard
SecurityScorecard
BitSight

Job description

Our vision is to transform how the world uses information to enrich life for all .

Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever.

The Third‑Party Cybersecurity Risk Management (TPCRM) Staff Analyst is a senior individual contributor responsible for shaping, governing, and continuously improving information risk management related to external suppliers. The analyst leads complex and ambiguous third‑party cybersecurity risk issues, advises senior business and security stakeholders, drives program maturity, and supports enterprise‑level decision‑making across Information Security, Privacy, Regulatory Compliance, Procurement, Legal, and Governance.

Responsibilities
  • Serve as a staff-level subject matter expert for third‑party cybersecurity risk management, including enterprise supplier risk governance, regulatory alignment, and assessment quality.
  • Lead highly complex third‑party risk assessments involving critical suppliers, high‑risk services, sensitive data, manufacturing dependencies, or material business impact.
  • Shape assessment methodology, risk criteria, evidence expectations, and control evaluation practices to improve consistency, scalability, and defensibility of TPCRM outcomes.
  • Perform advanced gap analysis against frameworks and standards such as ISO 27001, NIST, SOX, TISAX, and GDPR, and advise stakeholders on enterprise‑level remediation priorities.
  • Lead risk treatment strategy for material supplier findings, including mitigation planning, risk acceptance recommendations, supplier escalations, evidence validation, and closure decisions.
  • Develop, revise, and mature third‑party risk management policies, standards, processes, guidelines, and runbooks through formal governance and change management.
  • Lead third‑party governance activities, including onsite supplier audits, executive risk reporting, cross‑functional working groups, and escalation of material supplier risks.
  • Translate cybersecurity, regulatory, supplier, and threat intelligence insights into actionable risk themes, program enhancements, and supplier risk mitigation strategies.
  • Interpret risk tolerance, contractual obligations, control tradeoffs, supplier criticality, and business impact to support informed risk acceptance, mitigation avoidance, or transfer decisions.
  • Partner with procurement, legal, information security, business, privacy, resilience, and vendor management teams to embed TPCRM expectations throughout the supplier lifecycle.
  • Advise business‑led initiatives on third‑party cyber risk, due diligence requirements, standards compliance, supplier engagement, and governance escalation paths.
  • Mentor senior and junior analysts, lead process improvement initiatives, advance automation and reporting maturity, and help establish consistent TPCRM execution across teams and regions.
Education

Bachelor's Degree in Computer Science/Management Information Systems/Business Administration. Master's degree is preferred.

Related field of study or equivalent combination of education and experience.

Experience :
  • Analyzing and applying Information Security, Cyber Risk Management, Third‑Party Risk Management, and Privacy practices for a minimum of seven years of experience, with demonstrated ability to lead complex supplier risk issues, influence cross‑functional stakeholders, and improve risk management practices in the following areas:
  • Advanced third‑party / vendor risk management, supplier assessments, external assurance programs, cybersecurity governance, or enterprise risk functions.
  • Strong IT business process knowledge, supplier lifecycle understanding, business acumen, and ability to connect supplier risk to operational and enterprise impact.
  • Experience influencing procurement, legal, vendor management, privacy, information security, business, and executive stakeholders on risk decisions and remediation priorities.
  • Experience working with and improving third‑party risk management tools such as ServiceNow, Optro, Archer, AuditBoard, SecurityScorecard, BitSight, or equivalent platforms.
  • Experience developing risk analytics, dashboards, scorecards, executive reporting, metrics, and narratives that communicate third‑party risk posture and program maturity.
  • Advanced understanding of threat, vulnerability, business continuity, supplier security, incident response, and third‑party risk assessment methodologies.
  • Knowledge of national and international regulatory and security frameworks including NIST Cybersecurity Framework, ISO standards, SOX, GDPR, HIPAA, PCI DSS, TISAX, and related supplier security expectations.
  • Experience leading risk treatment decisions, remediation governance, supplier escalations, executive briefings, onsite supplier assessments, or high‑risk supplier reviews.
  • CRISC, CISA, CISSP, ISO 27001 Lead Auditor, CISM, or equivalent certifications are preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Third Party Risk Management (TPRM)
Third Party Risk Management (TPRM)

UST • Chennai District

On-site
INR 1,200,000 - 2,000,000
Staff IT Risk Analyst
Staff IT Risk Analyst

Micron Technology, Inc. • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Medical, dental and vision plans
Paid time off
Paid holidays
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
Jr. GRC Engineer
Jr. GRC Engineer

Neurealm • Chennai District

On-site
INR 700,000 - 1,100,000
Associate Cybersecurity Risk Analyst
Associate Cybersecurity Risk Analyst

Finthrive • Gurugram District

Hybrid
INR 900,000 - 1,300,000
Third-Party Risk Management (TPRM) Analyst
Third-Party Risk Management (TPRM) Analyst

Gratitude India • Chennai District

On-site
INR 1,200,000 - 1,800,000
TPRM Assessor
TPRM Assessor

Defentrix Solutions Pvt. Ltd. • Bengaluru

On-site
INR 1,200,000 - 2,200,000
Analyst - Third Party Technical Assurance
Analyst - Third Party Technical Assurance

Apex Group Ltd (India Branch) • Pune District

On-site
INR 1,200,000 - 1,600,000
TPRM Manager / Senior Manager - Cyber
TPRM Manager / Senior Manager - Cyber

Cubical Operations LLP • Bengaluru

On-site
INR 2,800,000 - 5,200,000