Third-Party Security Analyst

Tradeweb

Bengaluru

On-site

INR 1,400,000 - 2,300,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tradeweb Markets is seeking a Third-Party Security Analyst in Bengaluru to lead cybersecurity risk assessments for vendors and service providers. You will review SOC 1/2 reports, ISO certifications, and security documentation, defining risk ratings and remediation plans in collaboration with Risk, Legal, and Procurement teams.

The role requires 7+ years in cybersecurity or IT risk management and experience communicating risk to technical and non-technical stakeholders.

Qualifications

  • 7+ years of experience in cybersecurity, IT risk management, third-party risk management, or information security.
  • Strong understanding of cybersecurity principles, including access control, data protection, network security, and incident response.
  • Hands-on experience reviewing vendor security documentation (SOC reports, ISO certifications, risk assessments).
  • Solid knowledge of security frameworks and standards such as NIST, ISO 27001, SOC, and CIS.
  • Experience using GRC or third-party risk management tools.
  • Ability to assess and communicate risk clearly to both technical and non-technical stakeholders.
  • Strong analytical, documentation, and organizational skills.
  • Proven ability to manage multiple vendor assessments simultaneously and meet deadlines with minimal supervision.
  • Basic awareness of AI-enabled features within cybersecurity or vendor risk platforms (e.g., automated risk scoring, workflow automation).
  • Ability to interpret AI-assisted insights and apply human judgment to validate findings.

Responsibilities

  • Lead and perform cybersecurity risk assessments for third-party vendors, suppliers, and service providers
  • Review and analyze vendor security artifacts, including SOC 1/SOC 2 reports and ISO 27001 certifications
  • Review penetration testing summaries, architecture diagrams, technical documents, and security policies
  • Evaluate vendor responses to cybersecurity questionnaires and due diligence requests
  • Define vendor risk ratings and document identified risks, gaps, and remediation plans
  • Partner with Risk, Procurement, and Legal teams to support vendor onboarding and contract reviews
  • Track vendor remediation efforts and follow up on outstanding risk items
  • Monitor vendor-related security incidents and elevate issues in accordance with incident response procedures
  • Act as a subject matter expert and advisor to internal stakeholders on vendor cyber risk matters
  • Maintain vendor risk records, metrics, and reporting within GRC or vendor risk management platforms
  • Drive continuous improvement of third-party cyber risk management processes, standards, and controls
  • Support regulatory exams, audits, and internal reviews related to third-party cyber risk

Skills

Vendor risk management
Cybersecurity
Third-party risk
SOC 1/ SOC 2 reviews
ISO 27001
GRC tools
Risk communication
Regulatory exams
Incident response

Tools

GRC platforms
Vendor risk management tools

Job description

Functional Title

Third-Party Security Analyst

Experience

7+ years

Company Description

Tradeweb Markets is a world leader in the evolution of electronic trading. A fintech company serving approximately 2,500 clients—including the world's largest banks, asset managers, hedge funds, insurance companies, wealth managers, and retail clients—in more than 65 countries across the globe. Since our first trade in 1998, we have helped transform and electronify the fixed income markets.

Tradeweb is a culture built on innovation, creativity, and collaboration. Through a combination of incredibly talented and driven people, innovative products and solutions, cutting-edge technology, market data, and a vast client network, we continue to work together to improve the way financial markets trade.

Mission

Move first and never stop. Collaborate with clients to create and build solutions that drive efficiency, connectivity, and transparency in electronic trading.

Tradeweb Markets LLC ("Tradeweb") is proud to be an EEO Minorities/Females/Protected Veterans/Disabled/Affirmative Action Employer.

https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf

Group Details

Tradeweb's Cyber Security team plays a critical role in protecting the firm, its clients, and its employees from an evolving third-party threat landscape. The Vendor Cyber Risk Analyst will be responsible for assessing, monitoring, and managing cybersecurity risks introduced by third-party vendors and service providers.

This role works closely with Procurement, Legal, Compliance, Technology, and Business teams to ensure vendor risks are identified, assessed, and mitigated in alignment with Tradeweb's risk appetite and regulatory obligations. The ideal candidate brings strong cyber risk fundamentals, excellent communication skills, and experience operating in regulated financial environments.

Job Responsibilities
  • Lead and perform cybersecurity risk assessments for third-party vendors, suppliers, and service providers
  • Review and analyze vendor security artifacts, including SOC 1/SOC 2 reports and ISO 27001 certifications
  • Review penetration testing summaries, architecture diagrams, technical documents, and security policies
  • Evaluate vendor responses to cybersecurity questionnaires and due diligence requests
  • Define vendor risk ratings and document identified risks, gaps, and remediation plans
  • Partner with Risk, Procurement, and Legal teams to support vendor onboarding and contract reviews
  • Track vendor remediation efforts and follow up on outstanding risk items
  • Monitor vendor-related security incidents and elevate issues in accordance with incident response procedures
  • Act as a subject matter expert and advisor to internal stakeholders on vendor cyber risk matters
  • Maintain vendor risk records, metrics, and reporting within GRC or vendor risk management platforms
  • Drive continuous improvement of third-party cyber risk management processes, standards, and controls
  • Support regulatory exams, audits, and internal reviews related to third-party cyber risk
Required Qualifications
  • 7+ years of experience in cybersecurity, IT risk management, third-party risk management, or information security
  • Strong understanding of cybersecurity principles, including access control, data protection, network security, and incident response
  • Hands-on experience reviewing vendor security documentation (SOC reports, ISO certifications, risk assessments)
  • Solid knowledge of security frameworks and standards such as NIST, ISO 27001, SOC, and CIS
  • Experience using GRC or third-party risk management tools
  • Ability to assess and communicate risk clearly to both technical and non-technical stakeholders
  • Strong analytical, documentation, and organizational skills
  • Proven ability to manage multiple vendor assessments simultaneously and meet deadlines with minimal supervision
  • Basic awareness of AI-enabled features within cybersecurity or vendor risk platforms (e.g., automated risk scoring, workflow automation)
  • Ability to interpret AI-assisted insights and apply human judgment to validate findings
Preferred Qualifications
  • Experience in financial services or other highly regulated industries
  • Professional certifications such as CISA, CRISC, CISSP, or Security+ Familiarity with security rating services (e.g., BitSight, SecurityScorecard)
  • Experience producing KPIs and risk reporting for senior management
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Third-Party Security Analyst
Third-Party Security Analyst

Tradeweb Europe Limited • Bengaluru

On-site
INR 350,000 - 550,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
Third Party Risk Management (TPRM)
Third Party Risk Management (TPRM)

UST • Chennai District

On-site
INR 1,200,000 - 2,000,000
Risk Operations Specialist
Risk Operations Specialist

Tradeweb Europe Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Associate Cybersecurity Risk Analyst
Associate Cybersecurity Risk Analyst

Finthrive • Gurugram District

Hybrid
INR 900,000 - 1,300,000
Vendor Risk Analyst
Vendor Risk Analyst

Kaufman Rossin • Bengaluru

On-site
INR 800,000 - 1,200,000
Work-life balance
Hybrid work policy
People-first company culture
Risk Operations Specialist
Risk Operations Specialist

Tradeweb • Bengaluru

On-site
INR 1,200,000 - 1,800,000
GRC Information Security Third‑Party Risk Assessment Specialist
GRC Information Security Third‑Party Risk Assessment Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 900,000 - 1,300,000
Staff IT Risk Analyst
Staff IT Risk Analyst

Micron • Hyderabad

On-site
INR 4,000,000 - 7,000,000