Infosys
IT&Data CS 3rd Party Risk Mgt
Hyderabad, India
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Role family
- Supply chain
- Seniority
- Mid level
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 30 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Role Summary
The Third-Party Cyber Risk Manager is responsible for managing cybersecurity risks associated with suppliers, vendors, service providers, outsourcing partners, and strategic business partners. The role ensures that cybersecurity risks are identified, assessed, monitored, reported, and mitigated throughout the third-party lifecycle.
This position works closely with Procurement, Legal, Information Security, Compliance, Risk Management, and Business stakeholders to establish and maintain an effective Third-Party Risk Management (TPRM) program aligned with industry standards, regulatory requirements, and organizational security objectives.
Responsibilities
Key Responsibilities
Third-Party Risk Management
Maintain and continuously improve the Third-Party Risk Management (TPRM) framework.
Define, implement, and maintain vendor cyber risk assessment methodologies, processes, and standards.
Perform supplier and vendor cybersecurity risk assessments.
Conduct due diligence reviews for new and existing third parties.
Execute vendor risk classification and tiering activities.
Review and assess vendor security questionnaires and supporting evidence.
Validate cybersecurity controls implemented by external vendors and service providers.
Identify, document, and evaluate cybersecurity risks associated with third-party relationships.
Track remediation plans and monitor closure of identified risks and control gaps.
Perform periodic vendor reassessments and ongoing risk reviews.
Monitor third-party risks through continuous assessment and risk monitoring activities.
Support vendor onboarding, ongoing governance, and offboarding processes.
Partner with Procurement, Legal, Compliance, and Information Security teams throughout the vendor lifecycle.
Support audits, compliance assessments, and regulatory reporting initiatives.
Develop and maintain risk dashboards, KPIs, metrics, and executive reporting.
Present risk findings and recommendations to senior stakeholders and governance committees.
Governance, Risk & Compliance
Maintain third-party risk inventories and risk registers.
Support risk acceptance, exception management, and remediation governance processes.
Contribute to cybersecurity governance and assurance activities.
Support policy, standard, and procedure development related to third-party cybersecurity risk.
Provide guidance to business teams on vendor security requirements and risk mitigation strategies.
Assurance Reviews
Review and assess:
o ISO 27001 Certifications
o SOC 1 Reports
o SOC 2 Reports
o PCI DSS Attestations
o Penetration Test Reports
o Internal Audit Reports
o Security Policies and Procedures
Emerging Risk Areas
Artificial Intelligence (AI) Vendor Risk
Software Supply Chain Risk
Cloud Concentration Risk
Fourth-Party Risk Management
ICT and Critical Supplier Risk
Operational Resilience and Outsourcing Risk
Technical requirements
Required Skills & Competencies – Must Have
Third-Party Risk Management
Strong expertise in Third-Party Risk Management (TPRM), Vendor Risk Management (VRM), Supplier Risk Management, Outsourcing Risk, ICT Risk, and Operational Resilience.
Experience across the complete third-party lifecycle.
Hands-on experience performing vendor due diligence reviews.
Experience with security questionnaires and supplier assessments.
Knowledge of control assessments and evidence validation.
Experience supporting contract negotiations from a cybersecurity and risk perspective.
Strong understanding of risk identification, risk analysis, risk rating, and remediation tracking.
Experience reviewing ISO 27001 certifications and SOC 2 reports.
Cybersecurity & Risk Assessment
Strong cybersecurity and information risk management knowledge.
Experience applying frameworks and standards such as:
o ISO 27001
o NIST Cybersecurity Framework (CSF)
o NIST 800 Series
o SOC 2
o Vendor Security Control Frameworks
Understanding of security governance, risk management, and compliance principles.
Stakeholder Management
Strong stakeholder engagement and relationship management skills.
Ability to collaborate effectively with Procurement, Legal, Compliance, Security, Audit, and Business teams.
Strong analytical, written, verbal, and presentation skills.
Ability to review assessment quality and exercise sound risk judgement.
________________________________________
Required Skills & Competencies – Good to Have
Knowledge of GRC and TPRM platforms such as:
o ServiceNow GRC
o OneTrust
o SecurityScorecard
o BitSight
Knowledge of privacy and regulatory frameworks such as GDPR and NIS2.
Procurement and vendor management experience.
Executive presentation and reporting capabilities.
Experience with continuous monitoring solutions and cyber risk intelligence platforms.
Knowledge of cloud security and software supply chain risk management.
________________________________________
Experience & Qualifications
Experience
Total Experience: 5-8 Years
Relevant Experience: 3-5 Years in:
o Third-Party Risk Management (TPRM)
o Vendor Risk Management (VRM)
o Cyber Risk Management
o Information Security Risk
o Security Governance, Risk & Compliance (GRC)
o Operational Risk Management
Education
MCA,Intergrated course BCA+MCA,Bachelor of Engineering,BCA,BSc
Similar jobs
- QA AutomatizationIvalua · Pune, Maharashtra, IndiaFirst seen today
- Purchase Order Management & Invoice Operations Specialist - AVPDeutsche Bank · IndiaFirst seen today
- Aftermarket Engineering IHyster-Yale Group · IndiaFirst seen today
- Purchase ExecutiveQuality HR India · Gurgaon, Haryana, IndiaFirst seen today
- Procurement Operations AnalystAccenture · IndiaFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job