Third Party Risk Management (TPRM)

UST

Chennai District

On-site

INR 1,200,000 - 2,000,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

UST in Chennai is seeking a detail-oriented Information Security – Risk Analyst to assess and monitor cyber risks posed by external vendors and service providers. This role centers on risk treatment planning, remediation, and ongoing oversight across the supply chain.

You will collaborate with procurement, legal, and internal teams to document treatment plans, track remediation, and maintain audit-ready records. Knowledge of NIST CSF and ISO 27001 supports regulatory compliance.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related discipline.
  • 3+ years of experience in IT or cybersecurity risk management, with third‑party or vendor risk focus.
  • Knowledge of third‑party risk management frameworks and control standards (e.g., NIST, ISO 27001, SIG, SOC 2, CSA).

Responsibilities

  • Analyze third-party security assessments to identify risk findings and determine appropriate treatment strategies (e.g., remediation, compensating controls, or acceptance).
  • Collaborate with vendors, procurement, legal, and business stakeholders to document and manage risk treatment plans based on due diligence and ongoing monitoring results.
  • Track and follow up on risk remediation activities, ensuring that treatment plans are executed within agreed timelines.
  • Maintain a centralized register of third-party risk treatment activities and ensure all documentation is audit-ready.
  • Recommend and support the implementation of compensating controls or alternative mitigation actions when direct remediation is not feasible.
  • Escalate high-risk third-party issues and delays in remediation to leadership.
  • Contribute to the enhancement of third-party risk management frameworks, processes, and tools, ensuring alignment with NIST CSF, ISO 27001, and regulatory requirements.
  • Provide insights and reporting on risk trends, treatment status, and control effectiveness across the third-party portfolio.
  • Support audit, regulatory, and internal assurance activities related to third-party cybersecurity risk.

Skills

Vendor risk management
Third-party risk
GRC
ISO 27001
NIST 800-53
SOC 2
Regulatory requirements
Risk reporting
Stakeholder management
Audit support

Education

Bachelor’s degree in Cybersecurity or related discipline

Job description

Role Description

We are looking for a detail-oriented and strategic Information Security – Risk Analyst to support the assessment, remediation, and continuous monitoring of cyber risks posed by external vendors, partners, and service providers. This role plays a critical part in the third-party risk lifecycle, with a primary focus on driving effective risk treatment plans, collaborating with internal stakeholders and vendors to remediate control gaps and reduce exposure in the supply chain. Key Responsibilities:

  • Analyze third-party security assessments to identify risk findings and determine appropriate treatment strategies (e.g., remediation, compensating controls, or acceptance).
  • Collaborate with vendors, procurement, legal, and business stakeholders to document and manage risk treatment plans based on due diligence and ongoing monitoring results.
  • Track and follow up on risk remediation activities, ensuring that treatment plans are executed within agreed timelines.
  • Maintain a centralized register of third-party risk treatment activities and ensure all documentation is audit-ready.
  • Recommend and support the implementation of compensating controls or alternative mitigation actions when direct remediation is not feasible.
  • Escalate high-risk third-party issues and delays in remediation to leadership.
  • Contribute to the enhancement of third-party risk management frameworks, processes, and tools, ensuring alignment with NIST CSF, ISO 27001, and regulatory requirements.
  • Provide insights and reporting on risk trends, treatment status, and control effectiveness across the third-party portfolio.
  • Support audit, regulatory, and internal assurance activities related to third-party cybersecurity risk. Qualifications:
  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related discipline.
  • 3+ years of experience in IT or cybersecurity risk management, with specific experience in third-party or vendor risk.
  • Strong knowledge of third-party risk management frameworks and control standards (e.g., NIST, ISO 27001, SIG, SOC 2, CSA).
  • Hands‑on experience reviewing third-party security assessments, risk questionnaires, and due diligence documentation.
  • Familiarity with GRC or third-party risk platforms (e.g., Onspring, OneTrust, Archer, ServiceNow, Prevalent, BitSight, Panorays).
  • Excellent communication and negotiation skills to work with internal and external stakeholders.
  • Industry certifications (e.g., CRISC, CTPRP, CISA, CISSP) are a plus.
Skills
  • Compliance Management
  • GRC
  • Internal Controls
  • Risk Management
  • Audit Support
  • Due Diligence
  • ISO 27001
  • NIST 800-53
  • SOC 2
  • Stakeholder Management
  • Legal Operations
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Risk Management (TPRM) Professional
Third Party Risk Management (TPRM) Professional

UST • Chennai District

On-site
INR 900,000 - 1,500,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
GRC - TPRM Specialist
GRC - TPRM Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 700,000 - 1,500,000
Health insurance
Professional development
TPRM Manager / Senior Manager - Cyber
TPRM Manager / Senior Manager - Cyber

Cubical Operations LLP • Bengaluru

On-site
INR 2,800,000 - 5,200,000
Manager Risk Management
Manager Risk Management

Moder • Bengaluru

On-site
INR 1,200,000 - 2,200,000
Third-Party Risk Management Analyst
Third-Party Risk Management Analyst

Gratitude India • Kolkata District, Hyderabad, Chennai District

On-site
INR 1,200,000 - 1,800,000
Third-Party Risk Management (TPRM) Analyst
Third-Party Risk Management (TPRM) Analyst

Gratitude India • Chennai District

On-site
INR 1,200,000 - 1,800,000
TPRM Analyst
TPRM Analyst

IDFC FIRST Bank • Mumbai

On-site
INR 1,200,000 - 1,800,000
Third Party Risk Management Professional (TPRM)
Third Party Risk Management Professional (TPRM)

Contactx Resource Management • Navi Mumbai

On-site
INR 600,000 - 1,000,000