Job Description – TPRM Assistant Manager
Location : Bangalore
Experience : 4+ Years
Preference : Early Joiners
Role Overview
We are looking for an experienced Third-Party Risk Management (TPRM) Assistant Manager with a strong background in Information Security, ISMS, and ISO 27001 . The ideal candidate will support end-to-end third-party assessments, drive compliance initiatives, and ensure risks are identified, evaluated, and mitigated effectively.
Key Responsibilities
- Conduct end-to-end third-party risk assessments , including documentation review, gap identification, and remediation follow-up.
- Evaluate vendors’ security controls in alignment with ISO 27001, ISMS, NIST, and internal security policies .
- Review security artefacts such as SOC reports, penetration test reports, incident logs, data flow diagrams, etc.
- Work closely with cross-functional teams (Legal, Procurement, IT Security, Business Teams) to manage vendor onboarding and risk approvals.
- Maintain and update third-party risk registers, dashboards, and tracking mechanisms.
- Support internal and external audits related to TPRM, infosec, and compliance programs.
- Drive continuous improvement of TPRM processes, frameworks, and documentation.
- Track and validate vendor remediation actions to ensure timely closure of findings.
- Assist with policy creation, review, and implementation related to information security and third-party governance.
Required Skills & Experience
4+ years of experience in TPRM / Information Security / ISMS / ISO 27001 .Strong understanding of security controls , risk assessment methodologies, and governance frameworks.Hands-on experience with ISO 27001 implementation or audits , vendor security evaluations, and compliance reviews.Ability to interpret and assess complex security documents and technical controls.Excellent communication and stakeholder management skills.Strong analytical and reporting abilities.Early joiners preferred.Educational Qualification
Bachelor’s degree in Computer Science, IT, Cybersecurity, or a relevant field.Certifications preferred : ISO 27001 LA / LI, CISA, CRISC, CISSP (advantage) .