Apply Edge Start your job search

GRC - TPRM Specialist

Soffit Infrastructure Services (P) Ltd · Gurugram, Haryana, India

Apply & track with Apply Edge
Role SummaryThe role involves managing Information Security Governance, Risk, and Compliance (GRC) with a strong focus on Third‑Party / Vendor Risk Assessments. The incumbent will ensure that vendors, service providers, and partners comply with applicable regulatory, industry, and organizational information security requirements.Key ResponsibilitiesThird‑Party Risk Management (TPRM)Conduct end‑to‑end information security risk assessments of third parties, vendors, partners, service providers.Perform inherent risk profiling and residual risk evaluation while vendors onboarding, renewals and periodic reassessmentsAssist in updating Master Vendor Inventory as per service details and classificationReview vendor‑provided information, security questionnaires, and supporting evidenceAssess inherent security risks based on:Nature of services providedType and sensitivity of data accessed, processed, or storedDegree of system and network accessRegulatory and compliance impactAssign inherent risk ratings (e.g., High / Medium / Low) to new vendors as per the organization’s security risk frameworkIdentify key risk drivers and control gaps at the inherent risk stageDocument assessment results and rationale in the designated risk assessment template or systemPerform detailed security risk assessments of third parties based on profiling criteria defined in the organization’s Security Risk Assessment Framework, including evaluation of service criticality, data sensitivity, access levels, regulatory impact, and inherent risk factors, to determine overall risk classification and required risk treatment actions.Coordinate with internal business stakeholders and vendor service owners toCollect and validate details related to vendor services and engagement scopeClarify data access, system integration, and service dependenciesIdentify, escalate, and report any issues, gaps, or support requirements impacting the risk assessmentProvide periodic status updates on assessment progress, risks, and timelines to relevant stakeholdersAssist in review and update of security risk framework for third partiesSupport to business units in updating vendor and its services related informationBuild and maintain relationships with internal stakeholdersTrack progress and closure of open observations as per defined remediation plan for each assessmentSupport in performing process related security assessments for the organizationIdentify gaps, document risk findings, recommend corrective actions, and track remediation closures.Stakeholder ManagementWork closely with:IT & Security teamsProcurement & LegalBusiness unitsVendors and external assessorsProvide awareness and guidance on third‑party security and regulatory expectations.Required Skills & CompetenciesTechnical & Domain SkillsStrong understanding of:Information security controlsThird‑party risk frameworksRegulatory compliance in BFSIHands‑on experience with:Vendor security assessmentsRisk rating methodologiesCompliance reportingSoft SkillsStrong analytical and risk assessment skillsExcellent documentation and report‑writing abilitiesGood stakeholder communication and negotiation skillsAbility to work independently and manage multiple assessments