Technical Lead-Cybersecurity
Birlasoft
Birlasoft
Join our team as an experienced Third-Party Risk Management (TPRM) Specialist and play a crucial role in enhancing our organization's cybersecurity risk posture concerning third parties. This position involves leading vendor risk assessments, meticulously evaluating security measures, and actively monitoring potential risks. You'll ensure adherence to regulatory requirements and collaborate seamlessly with diverse internal departments, including business operations, procurement, legal, privacy, and technology teams, to effectively mitigate risks associated with our vendors, suppliers, and service providers.
Conduct comprehensive, end-to-end third-party risk assessments for all vendors, suppliers, and service providers. Evaluate the security controls, policies, and compliance standing of vendors through detailed reviews of questionnaires, due diligence reports, and certifications like SOC reports and ISO.
Assess and quantify cybersecurity risks linked to both new and existing third-party relationships. Monitor ongoing vendor risk postures and diligently track remediation efforts until their successful completion.
Collaborate closely with Procurement, Legal, Compliance, and Security teams throughout the vendor lifecycle, from onboarding to periodic reviews. Ensure vendor compliance with critical security standards such as ISO 27001, NIST, SOC2, GDPR, and PCI-DSS.
Manage and maintain third-party risk registers, track findings, and oversee exception and remediation processes. Analyze external attack surface data and breach intelligence to proactively identify potential vulnerabilities.
Support contract reviews, defining security requirements, and negotiating vendor security clauses. Prepare clear and concise risk assessment reports, executive summaries, and management presentations. Contribute to internal and external audits and drive continuous improvement in our vendor risk governance framework.
Proven expertise in Third-Party Risk Management (TPRM) and conducting thorough Vendor Security Assessments is essential.
Strong understanding of Cyber Risk Management principles, including risk remediation tracking and security due diligence reviews.
Proficiency in risk analysis, applying established risk rating methodologies, and managing vendor onboarding processes with robust risk governance.
Familiarity with regulatory compliance requirements and audit support is necessary. Experience with security questionnaires, SIG reviews, and assessing security policies and controls is highly valued.
Knowledge of attack surface and external risk monitoring, coupled with strong security reporting and dashboarding skills.
An understanding of supply chain management principles would be beneficial for this role.
Birlasoft
IT Consulting