Job Summary
Execute vendor security assessment lifecycle end-to-end • Collect and validate vendor questionnaires and security documentation • Follow up with vendors and internal stakeholders for assessment completion • Maintain vendor risk data accuracy in tracking systems • Track onboarding assessments and ensure closure within SLA timelines • Track and report vendor risk and assessment status • Support SOX and security audits by providing documentation and evidence • Maintain SOPs, audit templates, and compliance artifacts • Coordinate with internal teams and vendors for audit readiness • Provide periodic reporting on vendor risk posture • Ensure SLA adherence and timely
Key Responsibilities
The GRC (TPRM – Assessment & Audit) resource is responsible for operational execution of Third-Party Risk Management activities within a managed services framework. The role focuses on vendor security assessments, audit support, and compliance documentation while ensuring SLA adherence and governance alignment.
Skill Requirements
5–8 years experience in GRC / Vendor Risk / Compliance roles with strong focus on vendor assessments Key KPIs • Timely completion of vendor assessments • SLA adherence for assessments and audit deliverables • Zero backlog in vendor assessments • Audit readiness and documentation accuracy • Reduction in audit findings
Other Requirements
Strong experience in vendor / third party assessments (TPRM) • Understanding of security questionnaires and compliance requirements • Knowledge of SOX / ISO / NIST frameworks (awareness) • Experience with audit processes and documentation • Familiarity with ITSM / GRC tools