Posted 15 August, 2026
Cyber Security Engineer -Third party risk and control assessment
ClifyX
Bengaluru,Karnataka,India
Full Time
Reference: 365_594563_25-03272
• 5+ years of hands-on experience with controls management and related lifecycle, including design, implementation, validation and operational effectiveness testing.
• Third party risk and control assessment experience
Experience managing stakeholders across a variety of seniorities and technical understanding, with the ability to explain and educate stakeholders on IT risk and controls and related topics
• Ability to work under time pressured conditions against deadlines whilst achieving or exceeding KPIs measuring completion of testing and assessments work
• Business level fluency in spoken and written English
• IT risk and control related certifications, such as ISO27001, CRISC, CISM, CISA or CISSP
• Knowledge of risks and controls commonly found in the Financial Services sector, such as those related to GDPR, DORA, ISF Standard of Good Practice, NIST CSF, PCI DSS and PSD2
• IT-related academic background (experience information systems, and network design, cloud infrastructure, system administration or similar).
• Providing SME guidance to IT colleagues in the design, implementation and/or enhancement of technology controls
• Collaborating with technology-risk focussed colleagues executing IT risk assessments, including providing control testing conclusions and highlighting weaknesses in the design, implementation or operation of controls mitigating key technology risks
• Responding to and proactively resolve technology controls-related concerns and requests submitted by stakeholders.
• Conducting and facilitating workshops covering technology controls and associated technology risks, supported by high quality documentation of the conclusions from these workshops
• Third party risk and control assessment experience
Experience managing stakeholders across a variety of seniorities and technical understanding, with the ability to explain and educate stakeholders on IT risk and controls and related topics
• Ability to work under time pressured conditions against deadlines whilst achieving or exceeding KPIs measuring completion of testing and assessments work
• Business level fluency in spoken and written English
• IT risk and control related certifications, such as ISO27001, CRISC, CISM, CISA or CISSP
• Knowledge of risks and controls commonly found in the Financial Services sector, such as those related to GDPR, DORA, ISF Standard of Good Practice, NIST CSF, PCI DSS and PSD2
• IT-related academic background (experience information systems, and network design, cloud infrastructure, system administration or similar).
• Providing SME guidance to IT colleagues in the design, implementation and/or enhancement of technology controls
• Collaborating with technology-risk focussed colleagues executing IT risk assessments, including providing control testing conclusions and highlighting weaknesses in the design, implementation or operation of controls mitigating key technology risks
• Responding to and proactively resolve technology controls-related concerns and requests submitted by stakeholders.
• Conducting and facilitating workshops covering technology controls and associated technology risks, supported by high quality documentation of the conclusions from these workshops