Third-Party Risk Analyst
Bhubaneswar, Odisha, India · Full Time
Be the first to apply
- Experience
- 6–12 yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 days ago
- Work mode
- In office
- Education
- Any graduate
- Eligibility
- Candidates with qualifications such as B.C.A., B.Tech/B.E., Diploma, B.Sc, or B.Com in any specialization are eligible to apply.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About SIRO Clinpharm
SIRO Clinpharm is a renowned leader in Functional Service Provider solutions, offering extensive expertise in clinical research IT systems, SAP and ERP implementations, network infrastructure, and cybersecurity. The company collaborates with multinational corporations to provide tailored IT and CRO support services aligned with strategic objectives globally.
Role Overview
We are seeking a seasoned Third-Party Risk Analyst with 6 to 12 years of experience in areas such as cybersecurity, vendor risk management, IT risk, supply chain security, or governance, risk, and compliance (GRC). The role involves conducting comprehensive vendor security assessments, identifying and managing third-party cybersecurity risks, tracking remediation efforts, and ensuring alignment with organizational and regulatory security frameworks.
Key Responsibilities
- Perform comprehensive risk assessments for vendors throughout their lifecycle including onboarding, due diligence, recurrent evaluations, remediation, and decommissioning.
- Analyze cybersecurity risks related to hardware suppliers, OEM/ODM partners, electronics manufacturers, and technology service providers.
- Review and evaluate vendor security documents such as SOC 2 reports, ISO certifications, audit findings, penetration test summaries, vulnerability scans, policies, risk registers, and remediation strategies.
- Assess security controls pertaining to identity and access management, network security, vulnerability management, software development lifecycle, encryption, incident response, data protection, and business continuity.
- Identify security control deficiencies, document results, assign risk ratings, and suggest suitable remediation measures.
- Monitor and ensure closure of remediation tasks by engaging with vendors and internal teams.
- Apply applicable third-party risk and supply-chain security standards and best practices.
- Maintain vendor risk assessment records and processes using GRC or vendor risk management platforms such as ServiceNow, Archer, OneTrust, or equivalents.
- Collaborate closely with Cybersecurity, IT, Procurement, Legal, Business stakeholders, and external vendors to meet assessment timelines.
- Manage multiple vendor assessments and remediation follow-ups simultaneously, ensuring thorough documentation and risk mitigation.
Required Qualifications & Skills
- 6 to 12 years of professional experience in third-party risk management, cybersecurity risk, IT risk, supply chain security, or GRC roles.
- Practical experience with conducting vendor security risk assessments and due diligence processes.
- In-depth understanding of third-party cybersecurity and supply-chain risk dynamics.
- Familiarity with security standards such as NIST SP 800-161, ISO/IEC 27001, ISO 28000, and SOC 2 frameworks.
- Working knowledge of security domains: identity and access management, network security, vulnerability management, software development lifecycle, encryption, incident response, data protection, and business continuity.
- Adeptness at identifying security gaps, performing risk ratings, documenting findings, and tracking remediation activities.
- Experience using GRC or vendor risk management tools like ServiceNow, Archer, OneTrust, or comparable software.
- Strong analytical, reporting, communication, and stakeholder engagement capabilities.
Eligibility
Applicants holding degrees such as B.C.A., B.Tech / B.E., Diploma, B.Sc, or B.Com in any specialization are eligible to apply.
Locations
Job openings are available in Pune, Bangalore, Hyderabad, Bhubaneswar, and Noida.
Minimum education
Bachelor's Degree