Job Title : Manager – Third Party Risk Management (TPRM)
Location : Bangalore
Experience Required : 6+ years
Role Overview
We are seeking an experienced professional to join our team as a TPRM Manager , with a strong background in Third Party Risk Management and working knowledge of Data Privacy frameworks . The role involves assessing third-party vendors, managing risks related to information security and compliance, and ensuring adherence to regulatory standards.
Key Responsibilities
- Lead and manage the Third Party Risk Management (TPRM) process, including vendor onboarding, due diligence, monitoring, and offboarding.
- Conduct risk assessments on third parties across security, privacy, compliance, and operational domains.
- Collaborate with internal stakeholders (IT Security, Legal, Compliance, Procurement, and Business Units) to ensure third parties meet organizational standards.
- Review and interpret data privacy regulations (GDPR, DPDP Act, etc.) to evaluate vendor compliance.
- Track, report, and remediate third-party risks through risk registers and dashboards.
- Support the development and implementation of TPRM policies, frameworks, and playbooks .
- Manage audit and compliance activities related to third-party vendors.
- Provide subject matter expertise in cybersecurity, risk, and privacy to improve vendor governance.
Qualifications & Skills
Bachelor’s degree in Information Technology, Computer Science, Risk Management, or related field.Minimum 6+ years of experience in Third Party Risk Management, Vendor Risk, Information Security, or related fields.Exposure to Data Privacy frameworks (GDPR, DPDP Act, HIPAA, or equivalent).Strong understanding of ISO 27001, NIST, SOC 2, PCI DSS frameworks.Certifications preferred : CISA, CISSP, CISM (any one or more).Strong analytical and problem-solving skills with the ability to manage multiple stakeholders.Excellent communication, reporting, and vendor management skills.Good to Have
Experience in risk consulting, BFSI, or IT / ITES industries.Hands-on experience with GRC platforms (e.g., Archer, ServiceNow, OneTrust, MetricStream).Familiarity with contract reviews and data protection clauses.