- Role Description –
- ISMS or Third-Party Risk Assessments
- Lead engagement team in delivering client engagements
- Support Managers/AD/D in assessment/ audit execution, reporting, quality review and tracking • Support Managers/AD/D in responding to RFP, proposals, new opportunities
- Lead discussions with client teams from various depts. Such as compliance teams, auditing and regulators to identify and document various requirements/obligations
- Flexible to step-in and perform work on ground such as conducting risk assessments and audits with respect to people, process and technology
- Act as subject matter expert (SME) for providing guidance and share knowledge with team members. Assist team members during engagements
- Should be able to work as independently on short term engagements
- Perform quality reviews of work performed by team members
Desired qualifications
- 6+ Relevant years of experience in Third party risk management
- Relevant years of experience in IT Audits, Cloud security
- Experience with ISO22301 implementation and audits
- Preferred certifications CBCI / CBCP / ISO22301 LI or LA Offensive Security Certified Professional, CISA to work in a cross-functional, cross-cultural matrix environment
- Understanding of Third party/vendor/supplier risk management considerations
- Knowledge of Data Protection & Privacy related risks associated with Third-Party and relevant control frameworks for Third party risk management
- Excellent written/verbal communication
- Excellent documentation and presentation skills
- Highly motivated and willing to work in local and global environments
- Security certifications like CISSP, CISA, CISM, CEH, ISO27001
- Work experience in Infrastructure / Application Security
- Work experience in IT Audit
- Work experience in Information Risk Management
Location and way of working
- Base location: Bengaluru , KA
- This profile involves frequent / occasional travelling to client locations OR this profile does not involve extensive travel for work.
- Hybrid is our default way of working. Each domain has customized the hybrid approach to their unique needs.