HamburgerMenu
hirist

Cyber Security Specialist - Third-Party Risk Management

Recruitment cell
7 - 10 Years
Multiple Locations

Posted on: 02/04/2026

Job Description

Role : Cyber Security - Third Party Risk Management (TPRM) Specialist


Location : Delhi NCR


Notice Period : Immediate to 1 Month (Candidates currently serving notice period preferred)


Eligibility : Female Candidates Only


About the Role :


We are looking for a skilled and experienced Cyber Security Third Party Risk Management (TPRM) Specialist to join our team. This role is critical in ensuring that all third-party vendors and partners comply with the organizations security policies, regulatory requirements, and risk standards.


The ideal candidate will have strong expertise in cyber security governance, third-party risk assessment, and compliance frameworks, along with hands-on experience in managing vendor security evaluations. This position requires a proactive approach to identifying, analyzing, and mitigating risks associated with external stakeholders.


Key Responsibilities :


- Coordinate and conduct third-party security risk assessments in alignment with the organizations security policies and compliance requirements.


- Evaluate vendors security posture by reviewing security controls, policies, procedures, and audit reports.


- Identify, assess, and quantify risks associated with third-party engagements and provide actionable recommendations for risk mitigation.


- Manage the end-to-end Third Party Risk Management (TPRM) lifecycle, including onboarding, periodic reviews, and offboarding of vendors.


- Collaborate with internal stakeholders such as IT, Legal, Compliance, and Procurement teams to ensure vendor risk is effectively managed.


- Ensure adherence to industry-standard frameworks and regulatory requirements, including ISO 27001, NIST CSF, ISA/IEC 62443, CIS Controls, Cyber Essentials, NIS2, GDPR, and CCPA.


- Maintain accurate documentation of risk assessments, audit findings, and remediation plans.


- Monitor third-party risks continuously and ensure timely closure of identified vulnerabilities or compliance gaps.


- Support internal and external audits related to vendor security and compliance.


- Stay updated with evolving cyber threats, regulatory changes, and best practices in third-party risk management.


Required Skills & Experience :


- 7 - 10 years of experience in Cyber Security, with a strong focus on Third Party Risk Management (TPRM).


- Proven ability to identify, analyze, and quantify cyber security risks associated with third-party vendors.


- Hands-on experience with GRC (Governance, Risk & Compliance) platforms to manage risk assessment workflows and compliance tracking.


- Strong understanding of global cyber security standards and privacy regulations, including ISO 27001, NIST CSF, GDPR, and others.


- Experience in conducting vendor risk assessments, security reviews, and compliance audits.


- Excellent analytical, documentation, and stakeholder management skills.


- Strong communication skills with the ability to present risk findings to both technical and non-technical stakeholders.


Preferred Qualifications :


- Certifications such as CISM, CISSP, CRISC, or ISO 27001 Lead Auditor/Implementer will be an added advantage.


- Experience working in regulated industries (BFSI, Healthcare, etc.) is preferred.


- Exposure to data privacy and protection frameworks is a plus.

The job is for:

Women candidates preferred
info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...