IT&Data CS 3rd Party Risk Mgt
-
Infosys Limited
- Hyderabad
- 5 - 8 Years
- Full Time
- AWS - GRC
- GCP - GRC
- Vendor Risk Management
Posted October 1, 2026 applications close October 31, 2026
Please sign in or register for free to apply.
Job Description
Responsibilities
Key Responsibilities
Third-Party Risk Management
- Maintain and continuously improve the Third-Party Risk Management (TPRM) framework.
- Define, implement, and maintain vendor cyber risk assessment methodologies, processes, and standards.
- Perform supplier and vendor cybersecurity risk assessments.
- Conduct due diligence reviews for new and existing third parties.
- Execute vendor risk classification and tiering activities.
- Review and assess vendor security questionnaires and supporting evidence.
- Validate cybersecurity controls implemented by external vendors and service providers.
- Identify, document, and evaluate cybersecurity risks associated with third-party relationships.
- Track remediation plans and monitor closure of identified risks and control gaps.
- Perform periodic vendor reassessments and ongoing risk reviews.
- Monitor third-party risks through continuous assessment and risk monitoring activities.
- Support vendor onboarding, ongoing governance, and offboarding processes.
- Partner with Procurement, Legal, Compliance, and Information Security teams throughout the vendor lifecycle.
- Support audits, compliance assessments, and regulatory reporting initiatives.
- Develop and maintain risk dashboards, KPIs, metrics, and executive reporting.
- Present risk findings and recommendations to senior stakeholders and governance committees.
Governance, Risk & Compliance
- Maintain third-party risk inventories and risk registers.
- Support risk acceptance, exception management, and remediation governance processes.
- Contribute to cybersecurity governance and assurance activities.
- Support policy, standard, and procedure development related to third-party cybersecurity risk.
- Provide guidance to business teams on vendor security requirements and risk mitigation strategies.
Assurance Reviews
- Review and assess:
o ISO 27001 Certifications
o SOC 1 Reports
o SOC 2 Reports
o PCI DSS Attestations
o Penetration Test Reports
o Internal Audit Reports
o Security Policies and Procedures
Emerging Risk Areas
- Artificial Intelligence (AI) Vendor Risk
- Software Supply Chain Risk
- Cloud Concentration Risk
- Fourth-Party Risk Management
- ICT and Critical Supplier Risk
- Operational Resilience and Outsourcing Risk
Technical and Professional Requirements
Required Skills & Competencies – Must Have
Third-Party Risk Management
- Strong expertise in Third-Party Risk Management (TPRM), Vendor Risk Management (VRM), Supplier Risk Management, Outsourcing Risk, ICT Risk, and Operational Resilience.
- Experience across the complete third-party lifecycle.
- Hands-on experience performing vendor due diligence reviews.
- Experience with security questionnaires and supplier assessments.
- Knowledge of control assessments and evidence validation.
- Experience supporting contract negotiations from a cybersecurity and risk perspective.
- Strong understanding of risk identification, risk analysis, risk rating, and remediation tracking.
- Experience reviewing ISO 27001 certifications and SOC 2 reports.
Cybersecurity & Risk Assessment
- Strong cybersecurity and information risk management knowledge.
- Experience applying frameworks and standards such as:
o ISO 27001
o NIST Cybersecurity Framework (CSF)
o NIST 800 Series
o SOC 2
o Vendor Security Control Frameworks
- Understanding of security governance, risk management, and compliance principles.
Stakeholder Management
- Strong stakeholder engagement and relationship management skills.
- Ability to collaborate effectively with Procurement, Legal, Compliance, Security, Audit, and Business teams.
- Strong analytical, written, verbal, and presentation skills.
- Ability to review assessment quality and exercise sound risk judgement.
________________________________________
Required Skills & Competencies – Good to Have
- Knowledge of GRC and TPRM platforms such as:
o ServiceNow GRC
o OneTrust
o SecurityScorecard
o BitSight
- Knowledge of privacy and regulatory frameworks such as GDPR and NIS2.
- Procurement and vendor management experience.
- Executive presentation and reporting capabilities.
- Experience with continuous monitoring solutions and cyber risk intelligence platforms.
- Knowledge of cloud security and software supply chain risk management.
________________________________________
Experience & Qualifications
Experience
- Total Experience: 5-8 Years
- Relevant Experience: 3-5 Years in:
o Third-Party Risk Management (TPRM)
o Vendor Risk Management (VRM)
o Cyber Risk Management
o Information Security Risk
o Security Governance, Risk & Compliance (GRC)
o Operational Risk Management
Preferred Skills
- Vendor Risk Management
- GCP – GRC
- AWS – GRC
Educational Requirements
MCA,Intergrated course BCA+MCA,Bachelor of Engineering,BCA,BSc