Looking for Third-Party Risk Management Analyst
Location : Remote
Description
The ThirdParty Risk Management Analyst is responsible for supporting our customer s ThirdParty Cyber Risk Management (TPCRM) program by performing cybersecurity risk assessments, driving project execution, and improving risk management processes through automation and tooling. This role balances handson cybersecurity engineering work with structured project management to ensure thirdparty risks are identified, tracked, mitigated, and communicated effectively across the organization.
Essential Functions:
- Leading ThirdParty Cyber Risk Management initiatives across the full project lifecycle, including planning, execution, stakeholder coordination, reporting, and ongoing monitoring
- Perform comprehensive cybersecurity risk assessments of thirdparty partners, identify security gaps, and deliver clear, actionable assessment reports with minimal supervision
- Execute standardized inherent risk assessments and validate the accuracy of risk ratings, control evaluations, and remediation plans
- Track, document, and follow up on thirdparty risk remediation activities to ensure timely closure and alignment with Customer risk tolerance
- Leverage Governance, Risk, and Compliance (GRC) platforms and AIdriven automation to streamline assessment workflows, reporting, and evidence collection
- Partner with cybersecurity, procurement, legal, internal audit, and business stakeholders to support consistent and scalable thirdparty risk practices
- Support continuous improvement of TPCRM processes by identifying inefficiencies and recommending process or tooling enhancements
- Provide cybersecurity risk education to internal teams and thirdparty partners, promoting secure behaviors and awareness of emerging threats
- Prepare metrics, dashboards, and summaries to support leadership visibility into thirdparty cyber risk posture
- Utilize AI platforms and industry data to optimize assessment of workflows and enable greater focus on mitigating identified risks.
Competencies:
- Cybersecurity Fundamentals: Demonstrates a solid understanding of security controls, threats, and risk concepts
- Risk Assessment & Analysis: Ability to identify, assess, and document thirdparty cyber risks and control gaps
- Project Management: Effectively plans, tracks, and executes work across multiple concurrent initiatives
- Process Improvement: Identifies opportunities to streamline workflows and improve operational efficiency
- Stakeholder Collaboration: Works effectively with crossfunctional teams and external partners
- Communication: Clearly communicates technical risk information to both technical and nontechnical audiences
- Attention to Detail: Produces accurate, welldocumented assessments and maintains reliable risk records
- AI-Driven Risk Mitigation: Leverages AI platforms and industry partnerships to accelerate risk identification and maximize time spent on executing risk reduction.
Requirements
- Bachelor s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience
- 1 3 years of experience in cybersecurity, thirdparty risk management, IT risk, compliance, or a related discipline
- Foundational understanding of cybersecurity principles, risk assessment methodologies, and common security control frameworks
- Experience supporting projects or initiatives that require coordination across multiple stakeholders
- Strong written and verbal communication skills, with the ability to clearly document risks and recommendations
If Intrested please provide Visa copy, passport number, DL, updated resume along with your employer details.
Submission Format:
Full Name:
Phone Number:
Email ID :
Work StatAuthorization:
Pay Rate:
Current Location:
Relocate (if applicable)?:
LinkedIn Profile:
Available Time for an Interview:
Notice Period:
Upcoming Vacations:
Referral? If so, who? :
PREVIOUS HCL EMPLOYEE? If so, who was the HM/Supervisor s full name & email (if available):
Skill Matrix
Skills Required | Years of Exp. | Self-Rating (out of 10) | Remarks |
ThirdParty Risk Management | | | |
Cybersecurity risk assessments, | | | |
Driving project execution | | | |
risk management | | | |
GRC | | | |
Cybersecurity | | | |