Information Security Program Manager (third Party Risk Assessment)

Year    Bangalore, Karnataka, India

Job Description

Company Name: VARITE India Private Limited
About The Client:
A data management and cloud services company headquartered in the United States specializes in simplifying backup, recovery, and data protection processes. The firm offers a cloud-based platform integrating backup, instant recovery, archival, search, and analytics functions. Known for its innovative data management approach, the company caters to organizations seeking efficient and scalable solutions.
About The Job:

  • Client is seeking an experienced Program Manager to join our Third-Party Risk Assessment team.
  • This team focuses on analyzing and managing risks associated with our vendors, service providers, and other third parties, ensuring our organization upholds the highest standards of compliance, security, and business resilience.
  • While your primary responsibility will be Third-Party Risk Management, you will also collaborate on other cybersecurity risk management initiatives. Building strong cross-functional relationships across the company is a key component of this role.
  • To excel, you must showcase exceptional leadership, communication, and decision-making skills, and have a proven track record in managing third-party risk, vendor governance, or related domains.
Essential Job Functions:
  • Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory compliance.
  • Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentation.
  • Coordinate with vendors to request and verify security controls, remediation plans, and ongoing compliance.
  • Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolution.
  • Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediation.
  • Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profiles.
  • Participate in continuous security monitoring of existing suppliers to track changing risk profiles.
  • Partner with Procurement, Legal, Privacy, and InfoSec teams to improve supplier security management processes.
  • Identify opportunities to automate parts of the assessment process, thereby reducing manual work and enhancing efficiency.
  • Keep abreast of emerging risks, industry standards, and regulatory requirements affecting third-party vendors.
  • Manage and mentor contractors and junior team members, fostering professional growth and maintaining a collaborative team environment.
Qualifications:
  • Bachelors degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related field.
  • 8-10 years of professional experience in third-party risk assessment within cybersecurity or information risk management.
  • Understanding of relevant information security frameworks, including related regulatory compliance requirements, such as ISO 27001/2 (including ISO 27017 & 18), FedRAMP, SOC 2 Trust Services Criteria, PCI DSS, NIST CSF.
  • Solid understanding of risk assessment methodologies and best practices.
  • Ability to synthesize and communicate complex risk findings to both technical and non-technical audiences.
  • Detail-oriented, process-driven, and capable of managing multiple vendor assessments concurrently.
  • Experience with tools such as Coupa, OneTrust, JIRA and Coverbase is a plus.
  • Professional certifications in Information Security or Risk Management (e.g. CISA, CISM, CISSP, CRISC) is a plus.
How to Apply: Interested candidates are encouraged to respond/submit their updated resumes, and for additional job opportunities, please visit
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the preferred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral: 0-2 years INR 5,000
2-6 years INR 7,500
6+ years INR 10,000
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.

Skills Required

Beware of fraud agents! do not pay money to get a job

MNCJobsIndia.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.


Job Detail

  • Job Id
    JD4689868
  • Industry
    Not mentioned
  • Total Positions
    1
  • Job Type:
    Full Time
  • Salary:
    Not mentioned
  • Employment Status
    Permanent
  • Job Location
    Bangalore, Karnataka, India
  • Education
    Not mentioned
  • Experience
    Year