Posted on: 02/04/2026
Role : Cyber Security - Third Party Risk Management (TPRM) Specialist
Location : Delhi NCR
Notice Period : Immediate to 1 Month (Candidates currently serving notice period preferred)
Eligibility : Female Candidates Only
About the Role :
We are looking for a skilled and experienced Cyber Security Third Party Risk Management (TPRM) Specialist to join our team. This role is critical in ensuring that all third-party vendors and partners comply with the organizations security policies, regulatory requirements, and risk standards.
The ideal candidate will have strong expertise in cyber security governance, third-party risk assessment, and compliance frameworks, along with hands-on experience in managing vendor security evaluations. This position requires a proactive approach to identifying, analyzing, and mitigating risks associated with external stakeholders.
Key Responsibilities :
- Coordinate and conduct third-party security risk assessments in alignment with the organizations security policies and compliance requirements.
- Evaluate vendors security posture by reviewing security controls, policies, procedures, and audit reports.
- Identify, assess, and quantify risks associated with third-party engagements and provide actionable recommendations for risk mitigation.
- Manage the end-to-end Third Party Risk Management (TPRM) lifecycle, including onboarding, periodic reviews, and offboarding of vendors.
- Collaborate with internal stakeholders such as IT, Legal, Compliance, and Procurement teams to ensure vendor risk is effectively managed.
- Ensure adherence to industry-standard frameworks and regulatory requirements, including ISO 27001, NIST CSF, ISA/IEC 62443, CIS Controls, Cyber Essentials, NIS2, GDPR, and CCPA.
- Maintain accurate documentation of risk assessments, audit findings, and remediation plans.
- Monitor third-party risks continuously and ensure timely closure of identified vulnerabilities or compliance gaps.
- Support internal and external audits related to vendor security and compliance.
- Stay updated with evolving cyber threats, regulatory changes, and best practices in third-party risk management.
Required Skills & Experience :
- 7 - 10 years of experience in Cyber Security, with a strong focus on Third Party Risk Management (TPRM).
- Proven ability to identify, analyze, and quantify cyber security risks associated with third-party vendors.
- Hands-on experience with GRC (Governance, Risk & Compliance) platforms to manage risk assessment workflows and compliance tracking.
- Strong understanding of global cyber security standards and privacy regulations, including ISO 27001, NIST CSF, GDPR, and others.
- Experience in conducting vendor risk assessments, security reviews, and compliance audits.
- Excellent analytical, documentation, and stakeholder management skills.
- Strong communication skills with the ability to present risk findings to both technical and non-technical stakeholders.
Preferred Qualifications :
- Certifications such as CISM, CISSP, CRISC, or ISO 27001 Lead Auditor/Implementer will be an added advantage.
- Experience working in regulated industries (BFSI, Healthcare, etc.) is preferred.
- Exposure to data privacy and protection frameworks is a plus.
The job is for:
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1625687