Third-Party Risk Analyst

Simfluent

Dadri

On-site

INR 600,000 - 900,000

Full time

43 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Simfluent in India is seeking a Third-Party Risk Analyst to join its Compliance & GRC function, working daily with Procurement, Legal, and business owners to assess risk across the vendor lifecycle. The role emphasizes hands-on reviews, data-flow analysis, and remediation planning.

Responsibilities include SOC 1/2 and ISO 27001 interpretation, PCI DSS/SOX/HIPAA/GLBA alignment, contract review, and SLA tracking, with experience on GRC tools such as UpGuard, OneTrust, SecurityScorecard, and

Qualifications

  • 2+ years of dedicated experience in TPRM, information security auditing, or IT compliance.
  • Ability to read and interpret SOC 1, SOC 2, and ISO 27001 reports and translate findings into actionable risk language.
  • Strong analytical and technical literacy; ability to interpret data flows and system configurations.
  • Hands-on experience with GRC platforms and vendor risk indexing tools (UpGuard, OneTrust, SecurityScorecard, or Bitsight).
  • Excellent cross-functional stakeholder management; able to manage vendors and internal owners to commitments.
  • English communication skills.

Responsibilities

  • Execute comprehensive due diligence reviews on new and existing vendors using questionnaires, architecture diagrams, and data-flow assessments.
  • Analyze third-party audit reports and security certifications (SOC 1, SOC 2, ISO 27001) to identify weaknesses or gaps.
  • Monitor and ensure vendor alignment with privacy regulations and framework criteria (PCI DSS, SOX, HIPAA, GLBA).
  • Review contract language, security clauses, and track vendor performance against SLAs with Procurement and Legal.
  • Coordinate remediation roadmaps with business owners and external vendors to validate evidence before closing risk exceptions.
  • Maintain the centralized GRC platform inventory and update risk dashboards for executives and auditors.

Skills

TPRM
Information Security Auditing
IT Compliance
Analytical Skills
Technical Literacy
Data Flow Interpretation
System Configuration Analysis
Stakeholder Management
Written Communication
Verbal Communication
English

Education

Bachelor's degree in Information Technology / Cybersecurity / MIS / Business Administration / Finance or related

Tools

UpGuard
OneTrust
SecurityScorecard
Bitsight

Job description

Role Overview

We are looking for a Third-Party Risk Analyst acts as a critical line of defense protecting data and operational integrity. The role executes end-to-end risk assessments across the entire vendor lifecycle — from onboarding and contract review through continuous monitoring and offboarding. This is a hands-on assessment role embedded in the Compliance & GRC function, working daily with Procurement, Legal, and business owners across the enterprise.

Key Responsibilities
  • Risk assessments: Execute comprehensive due diligence reviews on new and existing vendors using specialized questionnaires, architecture diagrams, and data-flow assessments
  • Documentation review: Analyze third-party audit reports and security certifications, including SOC 1, SOC 2, and ISO 27001, to identify security weaknesses or compliance gaps
  • Regulatory compliance: Monitor and ensure vendor alignment with privacy regulations and framework criteria such as PCI DSS, SOX, HIPAA, and GLBA
  • Contract and SLA tracking: Partner with Procurement and Legal to review contract language, integrate required security clauses, and track vendor performance against Service Level Agreements (SLAs)
  • Issue remediation: Coordinate with business owners and external vendors to build remediation roadmaps, track open security items, and validate corrective evidence before closing risk exceptions
  • Reporting and metrics: Maintain the centralized Governance, Risk, and Compliance (GRC) platform inventory, updating risk dashboards and compiling status reports for executive committees and auditors
Requirements
  • Third-Party Risk Management (TPRM)
  • Information Security Auditing
  • IT Compliance
  • SOC 1 Report Analysis
  • SOC 2 Report Analysis
  • ISO 27001 Report Analysis
  • Analytical Skills
  • Technical Literacy
  • Data Flow Interpretation
  • System Configuration Analysis
  • GRC Platforms
  • Vendor Risk Indexing Tools
  • UpGuard
  • OneTrust
  • SecurityScorecard
  • Bitsight
  • Stakeholder Management
  • Written Communication
  • Verbal Communication
  • English
Preferred Skills
  • PCI DSS Compliance
  • SOX Compliance
  • HIPAA Compliance
  • GLBA Compliance
  • Contract Review
  • Vendor Inventory Management
  • Executive Dashboard Management
  • CTPRP Certification
  • CISA Certification
Qualifications
  • At least 2 years of dedicated experience in Third-Party Risk Management (TPRM), information security auditing, or IT compliance
  • Ability to read and interpret SOC 1, SOC 2, and ISO 27001 reports and translate findings into actionable risk language
  • Sharp analytical skills and strong technical literacy, including the ability to interpret data flows and system configurations
  • Hands-on experience with GRC platforms and vendor risk indexing tools (e.g., UpGuard, OneTrust, SecurityScorecard, or Bitsight)
  • Exceptional cross-functional stakeholder management — comfortable holding vendors and internal owners to commitments
  • Excellent written and verbal communication skills in English
  • Experience supporting PCI DSS, SOX, HIPAA, or GLBA compliance programs at retail or multi-brand scale (preferred)
  • Prior exposure to contract review in partnership with Procurement and Legal (preferred)
  • Experience maintaining a vendor inventory and executive-level risk dashboards (preferred)
  • Bachelor's degree in Information Technology, Cybersecurity, Management Information Systems, Business Administration, Finance, or a related discipline — or equivalent hands-on experience
  • CTPRP (Certified Third-Party Risk Professional) or CISA (Certified Information Systems Auditor) strongly preferred

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
TPRM Analyst (Third Party Risk Management)
TPRM Analyst (Third Party Risk Management)

HGS • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Third Party RIsk management consultant
Third Party RIsk management consultant

Visionet Systems Inc. • Bengaluru

On-site
INR 3,500,000 - 5,500,000
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 1,800,000 - 3,000,000
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management

EY • Hyderabad

On-site
INR 2,000,000 - 3,600,000
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management

EY • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Vendor Risk Analyst
Vendor Risk Analyst

Kaufman Rossin • Bengaluru

Hybrid
INR 800,000 - 1,200,000
Work-life balance
Hybrid work policy
People-first company culture
Analyst - Third Party Technical Assurance
Analyst - Third Party Technical Assurance

Apex Group Ltd (UK Branch) • Pune District

On-site
INR 1,500,000 - 2,500,000
TPRM Manager / Senior Manager - Cyber
TPRM Manager / Senior Manager - Cyber

Cubical Operations LLP • Bengaluru

On-site
INR 2,800,000 - 5,200,000
TPRM Analyst
TPRM Analyst

IDFC FIRST Bank • Mumbai

On-site
INR 1,200,000 - 1,800,000