Job Description
We are seeking an expert to lead vendor due diligence and ongoing assessments, reviewing evidence such as SOC 2, ISO 27001, HIPAA / HiTRUST certifications, penetration tests, and security policies.
This individual will assess third-party control environments against frameworks and regulations including NIST CSF, ISO 27001, GDPR, PCI-DSS, HIPAA, and HiTRUST.
The successful candidate will develop, implement, and enhance third-party risk governance programs, aligning them with client enterprise risk management objectives.
This role requires executive-level advisory skills, translating technical risk findings into business-aligned recommendations.
The ideal candidate will support clients in leveraging GRC platforms (e.g., Archer, OneTrust, ProcessUnity, JupiterOne, StrikeGraph, Vanta) to streamline risk assessments, monitoring, and reporting.
They will present results to senior stakeholders (CISOs, Risk Committees, Procurement Leaders) in a clear, business-aligned manner.
Collaboration with internal teams and client stakeholders is crucial to track remediation progress and validate corrective actions to ensure risks are managed effectively.
This opportunity also includes contributing to business development efforts by supporting go-to-market strategies and assisting with proposals related to third-party governance services.
Required Skills and Qualifications
Benefits
Risk Management • Gandhinagar, Gujarat, India