Third Party Security Risk Analyst

Haleon

Bengaluru

On-site

INR 1,700,000 - 2,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Haleon Bengaluru Campus is seeking a Third-Party Security Risk Analyst to evaluate supplier cybersecurity controls across the full lifecycle. You’ll assess inherent and residual risks, validate evidence, and drive remediation with internal teams while maintaining audit-ready documentation.

The role requires 5+ years in security assurance and familiarity with TPRM programs, SOC 2, ISO 27001, and cloud security practices.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Systems, Technology, Engineering, or a related field.

Responsibilities

  • Execute TPSRM activities across onboarding, due diligence, contracting security review, continuous monitoring, and offboarding checks.
  • Perform third-party cybersecurity risk assessments, analyze responses, and document findings per TPSRM methodology.
  • Identify security gaps and support remediation governance, including actions, evidence, and closure validation.
  • Support ongoing monitoring including reassessments and security alerts/events follow-ups.
  • Coordinate with Procurement, TPRM, Legal, security engineering, and business teams to complete assessments efficiently.

Skills

Security risk assessments
GRC
Vendor risk management
SOC 2 evidence review
Threat analysis

Education

Bachelor’s degree in Cybersecurity or related field

Tools

OneTrust
UpGuard
GRC tools

Job description

## Third Party Security Risk AnalystApplylocations: Bengaluru Campus 31time type: Full timeposted on: Posted Yesterdaytime left to apply: End Date: August 27, 2026 (19 days left to apply)job requisition id: 545652Welcome to Haleon. We’re a purpose-driven, world-class consumer company putting everyday health in the hands of millions. In just three years since our launch, we’ve grown, evolved and are now entering an exciting new chapter – one filled with bold ambitions and enormous opportunity. Our trusted portfolio of brands – including Sensodyne, Panadol, Advil, Voltaren, Theraflu, Otrivin, and Centrum – lead in resilient and growing categories. What sets us apart is our unique blend of deep human understanding and trusted science. Now it’s time to fully realise the full potential of our business and our people. We do this through our Win as One strategy. It puts our purpose – to deliver better everyday health with humanity – at the heart of everything we do. It unites us, inspires us, and challenges us to be better every day, driven by our agile, performance-focused culture.**About the role**The Third-Party Security Risk Analyst is responsible for performing high‐quality third‐party cybersecurity risk assessments and continuous monitoring activities across the full supplier lifecycle, including Onboarding, Due Diligence, Contracting, Continuous Monitoring, and Offboarding.The role conducts inherent risk reviews, detailed due‐diligence assessments, evaluates supplier controls, identifies security gaps, and works with suppliers and internal teams to define remediation plans. The Analyst also supports ongoing monitoring activities, including periodic reassessments, threat‐driven reviews, incident follow‐ups, and supplier offboarding validation.The Analyst works closely with the Third-Party Security Risk Operations Lead to ensure consistent execution of methodologies, adherence to SLAs, high‐quality documentation, and accurate risk reporting.**Role Responsibilities** * Execute TPSRM activities across the full lifecycle, including onboarding risk segmentation, due diligence assessments, contracting security review, continuous monitoring tasks, and supplier offboarding checks.* Perform detailed third-party cybersecurity risk assessments, analyzing supplier responses, evaluating inherent and residual risks, validating supporting evidence, and documenting findings in accordance with TPSRM methodology.* Identify security gaps and support remediation governance, including proposing remediation actions, tracking supplier commitments, validating closure evidence, and escalating overdue or high-risk items.* Support continuous monitoring, conducting periodic reassessments, reviewing supplier security alerts/events, following up on incidents, and supporting onsite visit preparation where required.* Coordinate operational interactions with suppliers, business requestors, Procurement, TPRM, Legal, and security engineering teams, ensuring that assessments and risk decisions are completed efficiently and accurately.* Maintain high quality documentation, ensuring that assessments, remediation plans, evidence, risk ratings, and decisions are accurate, complete, consistent, and audit ready.**Business Expertise*** Working knowledge of cybersecurity principles, supplier security requirements, and due‐diligence processes.* Understanding of cybersecurity frameworks such as ISO 27001, SOC 2, NIST CSF, CIS Controls, and cloud/data‐protection standards.* Familiarity with supplier assurance tools, TPRM platforms, GRC systems, and standardized assessment questionnaires (e.g., SIG/CAIQ).* Knowledge of procurement processes, contracting considerations, and vendor management best practices.* Ability to analyze complex technical information, interpret evidence, and derive well‐reasoned risk conclusions.**Problem Solving:*** Evaluates incomplete or inconsistent information provided by suppliers and applies judgement to determine risk impacts and required remediation.* Balances the need for timely supplier onboarding with maintaining strong cybersecurity controls and adherence to risk tolerance thresholds.* Works across multiple stakeholder groups to resolve questions, clarify requirements, and address blockers related to supplier controls or contracting constraints.* Identifies patterns or recurring weaknesses across suppliers and proposes improvements to questionnaires, workflows, templates, and guidance.**Nature & Area of Impact:*** Directly influences Haleon’s third‐party cyber risk posture by assessing the security of suppliers and identifying risks that could impact data protection, business continuity, or regulatory compliance.* Supports business demand by ensuring timely and accurate delivery of assessments that enable contracting and onboarding decisions.* Ensures that remediation plans are clear and effective, reducing ongoing operational and cyber risk exposure.* Supports audit readiness through proper documentation and evidence‐based risk decisions.**Interactions / Interpersonal Skills:*** Interacts frequently with suppliers to obtain evidence, clarify responses, and validate remediation progress.* Works closely with internal stakeholders including Procurement, TPRM, Legal, Security Engineering, Data Protection, and business requestors.* Requires clear, concise written and verbal communication to explain complex security issues in an understandable manner.* Must be able to collaborate effectively across global teams, often under tight timelines.* Requires strong attention to detail and the ability to communicate risk in a structured and actionable way.***Why you?*****Basic Qualifications:*** Bachelor’s degree in Cybersecurity, Information Systems, Technology, Engineering, or a related field.* 5 + years in security assurance, supplier assessments, technology risk, or GRC.* Experience performing cybersecurity or supplier risk assessments.* Familiarity with TPRM or TPSRM programs and supporting technologies.* Understanding of threat vectors, control requirements, and remediation planning.* Experience reviewing security evidence such as SOC 2 reports, penetration tests, and policy documentation.* Experience working with TPRM platforms, GRC tools, assessment systems, or security questionnaires.* Experience managing Third-Party Risk Management tools, such as OneTrust and UpGuard.**Preferred Qualifications:*** Training or certifications in cybersecurity, risk management, cloud security, or supplier assurance.* Experience working with third‐party monitoring tools, questionnaire platforms, or security rating services.* Certifications such as ISO 27001 Foundations, Security+, CCSK, CISA, or equivalent**Job Posting End Date**2026-08-27
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Security Risk Analyst
Third Party Security Risk Analyst

Haleon plc. • Bengaluru

On-site
INR 1,400,000 - 2,000,000
Cyber Security Analyst
Cyber Security Analyst

Fulcrum Digital Inc • Pune City

On-site
INR 800,000 - 1,200,000
Supplier & Risk Management Senior Lead Associate
Supplier & Risk Management Senior Lead Associate

Davies Group • Pune District

On-site
INR 1,200,000 - 1,800,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • Dadri

On-site
INR 600,000 - 900,000
India: Governance, Risk & Compliance Analyst
India: Governance, Risk & Compliance Analyst

Helmerich & Payne, Inc. • Panaji, Dadri

On-site
INR 1,000,000 - 1,500,000
Supplier & Risk Management Senior Lead Associate
Supplier & Risk Management Senior Lead Associate

Davies Shared Services • Pune District

Hybrid
INR 1,200,000 - 1,800,000
Analyst - Third Party Technical Assurance
Analyst - Third Party Technical Assurance

Apex Group Ltd (UK Branch) • Pune District

On-site
INR 1,500,000 - 2,500,000
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management
TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior GRC Analyst
Senior GRC Analyst

Qualys • Pune District

Hybrid
INR 1,500,000 - 2,500,000
Third-Party Risk Analyst
Third-Party Risk Analyst

Simfluent • India

On-site
INR 1,200,000 - 2,000,000