Third-party Information Security Risk and Compliance Analyst

5 - 10 years

5 - 15 Lacs

Posted:1 week ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Roles and Responsibilities

  • Conduct comprehensive audits of third-party information security policies, procedures, and controls.
  • Participate in contract negotiations concerning the third-party information security annex.
  • Lead online and in-person meetings with third parties.
  • Analyse submitted security questionnaires and documentation to identify and assess potential vulnerabilities and risks. Raise issues promptly and provide mitigation options based on security issues identified.
  • Prepare detailed risk assessment reports for senior leadership, providing insights and recommendations for third-party risk reduction.
  • Contribute to the continuous improvement of the team's processes based on experience in third-party risk assessment, industry best practices, and internal policies and frameworks.
  • Produce clear and structured documentation of processes, meetings, and other relevant activities.
  • Initiate and lead improvement projects aimed at enhancing the efficiency and effectiveness of the Vendor Risk Management team.
  • Collaborate with other sections within the company to ensure alignment of processes.
  • Stay up-to-date with emerging technologies, threats, vulnerabilities, and industry best practices.
  • 2+ years experience in third/party risk management, information security risk management, compliance, or a background in cybersecurity.
  • Familiarity with information security processes, including risk assessment, vulnerability management, and incident response.
  • Understanding of regulatory requirements (e.g. GDPR, NIS2, DORA)
  • Proficiency in risk management, cybersecurity control frameworks and standards (e.g. NIST RMF, ISO 27001, ISO 28000, CyFun, CCM)
  • Excellent analytical and problem-solving skills, with the ability to interpret complex risk data and make informed decisions.
  • Attention to detail.
  • Strong written and verbal communication skills in English, capability to articulate complex risk concepts to technical and non-technical audiences.
  • Capable of conducting professional business communications and effectively handling information security aspects of contract negotiations.

  • Experience in aligning team processes with broader organizational goals.
  • Proven ability to initiate and drive projects.
  • A collaborative mindset and a positive attitude towards working with a diverse team.
  • Relevant certifications such as CISA, CISSP, CISM, ISO/IEC 27001Lead Implementer/Auditor, ISO/IEC 28000 Lead Implementer/Auditor, Security+.
  • Advanced knowledge of Microsoft Office Suite (Word, Excel, PowerPoint, Outlook) to create professional documentation, presentations, dashboards, prepare statistics calculations, and optimize workflows.
  • Knowledge of emerging technologies and their associated risks, especially in AI and cloud computing.
  • Experience of using a Governance, Risk, and Compliance (GRC) tool.
  • Proficiency in English.

Experience in the telecommunication domain.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Tsit Digital Technologies logo
Tsit Digital Technologies

Information Technology

Tech City

RecommendedJobs for You

hyderabad, chennai, mumbai (all areas)

hyderabad, chennai, bengaluru

kolkata, hyderabad, ahmedabad

hyderabad, bengaluru, delhi / ncr

hyderabad, chennai, bengaluru