Skip to main content
Posted 17 June, 2026

Cyber Security - GRC - Vendor Risk Assessment~Cyber Security - GRC - Data Security~EIS : QA Auditin

ClifyX
India Full Time
Reference: 365_594563_26-01762

Summary Information
Request Type: Contract - IND
Geography: India
Labor Category: IT_IND
Procurement Type: Contingent Labor
Tax Work Location: IND Default
Status: Open
Submitted: 2/13/2026 9:00:14 AM
Has Assignments: No
Request Information
Request: Information Technology_IND - IND_Developer
Qty: 1
Candidate Submission Limit Per Supplier: 4
Candidate Submission Limit Per Request: 0
Desired Start Date: 2/26/2026
End Date: 8/26/2026
Hrs/Wk: 45.00
MSP Owner: EJ, Jannet
GBAMS Requisition ID: 10563235
Estimated Expense: Rs0.00 (Sum of Expense * Quantity of Candidates)
General Information
Job Description: Location : Pune

Skills: TPRM (4+ yrs in Vendor Risk Assessment)

Experience Required: 6-10 years

Job Description:

Technical/Functional Skills from the Role
Access management-Privilege access management , Segregation of duties, least privilege principle , RBAC , Password management , User access management, personal accounts & Non personal technical accounts
Data security – Encryption at rest and in transit , Key lifecycle management, Ciphers,
Secure operations- Log monitoring, Log protection, Log management, Endpoint security, Patching
Data Leakage Prevention- Understanding of DLP tools & technologies, structured and unstructured data, Instances (Dev, Test , PROD), Email security, Data classification.
Cyber Threat management – Threat & Vulnerability management, Hardening process, External attacks ( DDoS) , Penetration testing , Incident management
Network security- Basic network security components understanding ( Firewall, IDS ,IPS, WAF), Network ports & protocols, Network segmentation etc.
System acquisition , development & Change management– SLDC process for application design , development , deployment & Operations including defined change controls for approval and testing.
Operation resilience – BCP , Backup & restore, Records management , Data retention.
Governance , risk & compliance- Polices , Procedures, Risk management framework , Cyber risk management, Supply chain risk management.
Assurance reports – SOC 1, SOC 2 reports, ISO 27001 certificate including Statement of applicability, CSA star level 2 etc
Asset management- Asset inventory , Hardware & Software Life cycle management
Data center security
Physical security
HR security
Relevant experience in TPRM (Program/Framework level).
Expertise in Third Party Risk Assessments
Expertise in cyber security including standards such as ISO27001, PCI-DSS, ISO 22301 etc. Experienced in review of SSAE18, SOC 2, HITRUST, SIG and CAIQ reports.
Certifications such as CTPRP, CTPRA, CRVPM, CRISC, CISA, CISSP are good to have.

Roles and Responsibilities
Ø Should be able to develop and manage a comprehensive third party risk management framework / program.
Ø Should be able to drive regulatory compliance / remediation programs such as Digital Operational Resilience Act (DORA).
Ø Should be independently able to manage third party due diligence including initial risk assessments and ongoing monitoring.
Ø Contribute to governance and facilitate remediation recommendations of related risks, deficiencies, gaps or issues, advice with identifying compensating controls alternative where compliance requirements cannot be met.
Ø Document and present overall residual risk to higher management for approvals and risk acceptances.
Ø Interact with vendors, business, and multiple stakeholders to assess, explain and remediate the risks identified.
Ø Ongoing monitoring activities such as performance monitoring, contractual compliance, SLA/KPI adherence, negative news monitoring etc.
Ø Test design and operating effectiveness of TPRM controls, identify gaps and recommend improvements.
Ø Support key reporting activities associated within key functions. Perform adhoc IT risk analysis and reporting.
Comments for Suppliers:
Rate Details
Rate Card Class: IND_Developer
Category: Category 3
Level: Level II
Bill Rate: Rs70,000.00 - Rs110,000.00 Monthly NOOT

Sign up for Job Alerts