Job Description
Role: Third Party Cyber Risk Services Operations Lead Analyst
Location: Bellandur, Bangalore
Work Timings: 01:30 PM – 10:30 PM
Type: Contract to hire
Work Mode: Monday (WFH), Tuesday–Friday (WFO)
Experience: 10–12 Years
Job Summary
Role Summary The Lead Analyst will support Third-Party Cyber Risk Services operations by managing daily intake, executing workflows, and delivering data-driven risk assessments. This role is responsible for making defensible third-party risk decisions (including accept/reject), partnering with cross-functional stakeholders, and strengthening organizational cyber resilience.
Key Responsibilities
Third-Party Risk Management
- Manage and maintain the third-party risk management framework
- Perform inherent and residual risk assessments using data-driven methodologies
- Identify cyber risks associated with third-party vendors
Risk Analysis & Mitigation
- Define, implement, and track mitigation and risk treatment plans
- Analyse trade-offs to manage residual risk effectively
- Support defensible risk decisions aligned with business objectives
Stakeholder Collaboration
- Partner with:
- Procurement (contract advisors, category managers)
- Legal teams
- Business/Product owners
- Risk managers & analysts
- Security engineers & threat intelligence teams
- Communicate risk insights, impacts, and recommendations clearly
Operations & Delivery
- Manage intake and prioritize work based on risk
- Meet SLAs without compromising quality
- Handle escalations and resolve high-risk issues promptly
Process Improvement & Automation
- Define and enhance processes, procedures, and tools
- Identify efficiency opportunities and leverage automation/AI
- Drive continuous improvement initiatives
Metrics & Reporting
- Develop and analyse risk metrics and dashboards
- Track trends, risk posture, and control effectiveness
Required Qualifications
Core Expertise
- Strong experience in Third-Party Risk Management (TPRM)
- Knowledge of information security concepts: threat, vulnerability, impact
- Ability to apply risk concepts to policies, standards, and controls
Framework Knowledge
- Hands-on experience with NIST Cybersecurity Framework (CSF)
- Understanding of control effectiveness and compliance assurance
Analytical & Problem-Solving Skills
- Strong critical thinking and risk analysis capability
- Ability to break down complex problems and work in ambiguous environments
- Experience in designing and maturing processes
Communication & Leadership
- Excellent written and verbal communication skills
- Ability to influence stakeholders across levels
- Strong cross-functional collaboration skills
Agile & Execution Skills
- Experience working in agile environments
- Ability to prioritize tasks, remove blockers, and adapt quickly
Key Competencies
- Risk Assessment & Decision-Making
- Cybersecurity & Compliance
- Stakeholder Management
- Process Optimization
- Data-Driven Insights
- Automation & Innovation
Want AI-powered job matching?
Upload your resume and get every job scored, your resume tailored, and hiring manager emails found - automatically.
Get Started Free