Role Overview
Soffit Infrastructure Services (P) Ltd is hiring a mid-level GRC - TPRM Specialist. This is a full-time role in IN. Part of Soffit Infrastructure Services (P) Ltd's Risk hiring. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Sign up free to auto-tailor your resume with all these keywords and get a higher ATS score
Job Description
Role Overview:
As an Information Security Governance, Risk, and Compliance (GRC) Manager with a specialization in Third-Party / Vendor Risk Assessments, your primary responsibility will be to ensure that vendors, service providers, and partners adhere to relevant regulatory, industry, and organizational information security standards.
Key Responsibilities:
- Conduct comprehensive information security risk assessments for third parties, vendors, partners, and service providers.
- Profile inherent risks and evaluate residual risks during vendor onboarding, renewals, and regular assessments.
- Update the Master Vendor Inventory with accurate service details and classifications.
- Review vendor-supplied information, security questionnaires, and supporting evidence.
- Assess inherent security risks based on the nature of services, data sensitivity, system and network access, and regulatory impact.
- Assign inherent risk ratings (High/Medium/Low) to new vendors according to the organization's security risk framework.
- Identify key risk drivers and control gaps during the inherent risk stage.
- Document assessment results and rationale using the designated risk assessment template or system.
- Perform detailed security risk assessments of third parties based on defined profiling criteria in the Security Risk Assessment Framework.
- Coordinate with internal stakeholders and vendor service owners to validate service details, data access, system integration, and service dependencies.
- Identify, escalate, and report any issues, gaps, or support requirements affecting the risk assessment.
- Provide regular updates on assessment progress, risks, and timelines to relevant stakeholders.
- Assist in enhancing the security risk framework for third parties.
- Support business units in updating vendor and service-related information.
- Establish and maintain relationships with internal stakeholders.
- Monitor the closure of open observations based on the defined remediation plan for each assessment.
- Assist in conducting process-related security assessments and recommending corrective actions.
Qualification Required:
- Strong understanding of information security controls, third-party risk frameworks, and regulatory compliance in the BFSI sector.
- Hands-on experience with vendor security assessments, risk rating methodologies, and compliance reporting.
Additional Details: N/A Role Overview:
As an Information Security Governance, Risk, and Compliance (GRC) Manager with a specialization in Third-Party / Vendor Risk Assessments, your primary responsibility will be to ensure that vendors, service providers, and partners adhere to relevant regulatory, industry, and organizational information security standards.
Key Responsibilities:
- Conduct comprehensive information security risk assessments for third parties, vendors, partners, and service providers.
- Profile inherent risks and evaluate residual risks during vendor onboarding, renewals, and regular assessments.
- Update the Master Vendor Inventory with accurate service details and classifications.
- Review vendor-supplied information, security questionnaires, and supporting evidence.
- Assess inherent security risks based on the nature of services, data sensitivity, system and network access, and regulatory impact.
- Assign inherent risk ratings (High/Medium/Low) to new vendors according to the organization's security risk framework.
- Identify key risk drivers and control gaps during the inherent risk stage.
- Document assessment results and rationale using the designated risk assessment template or system.
- Perform detailed security risk assessments of third parties based on defined profiling criteria in the Security Risk Assessment Framework.
- Coordinate with internal stakeholders and vendor service owners to validate service details, data access, system integration, and service dependencies.
- Identify, escalate, and report any issues, gaps, or support requirements affecting the risk assessment.
- Provide regular updates on assessment progress, risks, and timelines to relevant stakeholders.
- Assist in enhancing the security risk framework for third parties.
- Support business units in updating vendor and service-related information.
- Establish and maintain relationships with internal stakeholders.
- Monitor the closure of open observations based on the defined remediation plan for each assessment.
- Assist in conducting process-related security assessments and recommending corrective actions.
Qualification Required:
- Strong understanding of information security controls, third-party risk frameworks, and regulatory compliance in the BFSI sector.
- Hands-on experience with vendor security assessments, risk rating methodologies, and compliance reporting.
Additional Details: N/A
Frequently Asked Questions
How do I apply for the GRC - TPRM Specialist position at Soffit Infrastructure Services (P) Ltd?
Use the Apply button above to submit your application directly to Soffit Infrastructure Services (P) Ltd. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the GRC - TPRM Specialist position at Soffit Infrastructure Services (P) Ltd located?
This position is based in IN. Soffit Infrastructure Services (P) Ltd has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a GRC - TPRM Specialist at Soffit Infrastructure Services (P) Ltd earn?
Soffit Infrastructure Services (P) Ltd has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the GRC - TPRM Specialist role at Soffit Infrastructure Services (P) Ltd posted?
This role was posted on May 9, 2026 (37 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get Started FreeNo credit card to start