Third-Party Risk Management Specialist

Infosys

Hyderabad

On-site

INR 2,500,000 - 4,000,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Infosys in Hyderabad seeks a Third-Party Cyber Risk Manager to oversee cybersecurity risk across suppliers, vendors, service providers, outsourcing partners, and strategic business partners. You will establish and sustain a robust TPRM program aligned with industry standards and regulatory requirements.

Collaborating with Procurement, Legal, Information Security, Compliance, Risk Management, and business teams, you will perform risk assessments, due diligence, risk classification, remediation

Qualifications

  • Must have strong expertise in TPRM and VRM across the vendor lifecycle.

Responsibilities

  • Maintain and continually improve the TPRM framework and risk registers.

Skills

TPRM
VRM
Supplier Risk
Outsourcing Risk
ICT Risk
Operational Resilience
Vendor due diligence
Security questionnaires
Evidence validation
Contract negotiations
Risk identification
Risk analysis
Risk rating
Remediation tracking
ISO 27001
SOC 2

Education

MCA
BCA+MCA
Bachelor of Engineering
BCA
BSc

Tools

ServiceNow GRC
OneTrust
SecurityScorecard
BitSight

Job description

Job Description
Role Summary

The Third-Party Cyber Risk Manager is responsible for managing cybersecurity risks associated with suppliers, vendors, service providers, outsourcing partners, and strategic business partners. The role ensures that cybersecurity risks are identified, assessed, monitored, reported, and mitigated throughout the third-party lifecycle. This position works closely with Procurement, Legal, Information Security, Compliance, Risk Management, and Business stakeholders to establish and maintain an effective Third-Party Risk Management (TPRM) program aligned with industry standards, regulatory requirements, and organizational security objectives.

Roles & Responsibilities
Key Responsibilities
Third-Party Risk Management
  • Maintain and continuously improve the Third-Party Risk Management (TPRM) framework.
  • Define, implement, and maintain vendor cyber risk assessment methodologies, processes, and standards.
  • Perform supplier and vendor cybersecurity risk assessments.
  • Conduct due diligence reviews for new and existing third parties.
  • Execute vendor risk classification and tiering activities.
  • Review and assess vendor security questionnaires and supporting evidence.
  • Validate cybersecurity controls implemented by external vendors and service providers.
  • Identify, document, and evaluate cybersecurity risks associated with third-party relationships.
  • Track remediation plans and monitor closure of identified risks and control gaps.
  • Perform periodic vendor reassessments and ongoing risk reviews.
  • Monitor third-party risks through continuous assessment and risk monitoring activities.
  • Support vendor onboarding, ongoing governance, and offboarding processes.
  • Partner with Procurement, Legal, Compliance, and Information Security teams throughout the vendor lifecycle.
  • Support audits, compliance assessments, and regulatory reporting initiatives.
  • Develop and maintain risk dashboards, KPIs, metrics, and executive reporting.
  • Present risk findings and recommendations to senior stakeholders and governance committees.
Governance, Risk & Compliance
  • Maintain third-party risk inventories and risk registers.
  • Support risk acceptance, exception management, and remediation governance processes.
  • Contribute to cybersecurity governance and assurance activities.
  • Support policy, standard, and procedure development related to third-party cybersecurity risk.
  • Provide guidance to business teams on vendor security requirements and risk mitigation strategies.
Assurance Reviews
  • Review and assess:
    • ISO 27001 Certifications
    • SOC 1 Reports
    • SOC 2 Reports
    • PCI DSS Attestations
    • Penetration Test Reports
    • Internal Audit Reports
    • Security Policies and Procedures
Emerging Risk Areas
  • Artificial Intelligence (AI) Vendor Risk
  • Software Supply Chain Risk
  • Cloud Concentration Risk
  • Fourth-Party Risk Management
  • ICT and Critical Supplier Risk
  • Operational Resilience and Outsourcing Risk
Technical Requirement
Required Skills & Competencies - Must Have
Third-Party Risk Management
  • Strong expertise in Third-Party Risk Management (TPRM), Vendor Risk Management (VRM), Supplier Risk Management, Outsourcing Risk, ICT Risk, and Operational Resilience.
  • Experience across the complete third-party lifecycle.
  • Hands-on experience performing vendor due diligence reviews.
  • Experience with security questionnaires and supplier assessments.
  • Knowledge of control assessments and evidence validation.
  • Experience supporting contract negotiations from a cybersecurity and risk perspective.
  • Strong understanding of risk identification, risk analysis, risk rating, and remediation tracking.
  • Experience reviewing ISO 27001 certifications and SOC 2 reports.
Cybersecurity & Risk Assessment
  • Strong cybersecurity and information risk management knowledge.
  • Experience applying frameworks and standards such as:
    • ISO 27001
    • NIST Cybersecurity Framework (CSF)
    • NIST 800 Series
    • SOC 2
    • Vendor Security Control Frameworks
  • Understanding of security governance, risk management, and compliance principles.
Stakeholder Management
  • Strong stakeholder engagement and relationship management skills.
  • Ability to collaborate effectively with Procurement, Legal, Compliance, Security, Audit, and Business teams.
  • Strong analytical, written, verbal, and presentation skills.
  • Ability to review assessment quality and exercise sound risk judgement.
Required Skills & Competencies - Good to Have
  • Knowledge of GRC and TPRM platforms such as:
    • ServiceNow GRC
    • OneTrust
    • SecurityScorecard
    • BitSight
  • Knowledge of privacy and regulatory frameworks such as GDPR and NIS2.
  • Procurement and vendor management experience.
  • Executive presentation and reporting capabilities.
  • Experience with continuous monitoring solutions and cyber risk intelligence platforms.
  • Knowledge of cloud security and software supply chain risk management.
Experience & Qualifications
Experience
  • Total Experience: 5-8 Years
  • Relevant Experience: 3-5 Years in:
    • Third-Party Risk Management (TPRM)
    • Vendor Risk Management (VRM)
    • Cyber Risk Management
    • Information Security Risk
    • Security Governance, Risk & Compliance (GRC)
    • Operational Risk Management
Educational Requirement
  • MCA,Intergrated course BCA+MCA,Bachelor of Engineering,BCA,BSc
Preferred Skills
  • Domain->Risk Services->Vendor Risk Management,Technology->Cloud Security->GCP - GRC,Technology->Cloud Security->AWS - GRC
Service Line
  • Cyber Security
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity- TPRM Assessor
Cybersecurity- TPRM Assessor

Cognizant • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Cyber Security- TPRM Analyst
Cyber Security- TPRM Analyst

Cognizant • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Cyber Security- TPRM Analyst
Cyber Security- TPRM Analyst

Cognizant • Bengaluru

On-site
INR 1,200,000 - 2,000,000
TPRM Manager
TPRM Manager

Deloitte Shared Services India • Pune District

On-site
INR 900,000 - 1,200,000
TPRM
TPRM

Deloitte Shared Services India • Pune District

On-site
INR 800,000 - 1,200,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
Third Party Risk Management (TPRM)
Third Party Risk Management (TPRM)

UST • Chennai District

On-site
INR 1,200,000 - 2,000,000
GRC – Information Security Third‑Party Risk Assessment Specialist
GRC – Information Security Third‑Party Risk Assessment Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 1,200,000 - 2,100,000
Staff IT Risk Analyst
Staff IT Risk Analyst

Micron • Hyderabad

On-site
INR 4,000,000 - 7,000,000