Current: English
Job Description
Responsibilities
Third-Party Cybersecurity Assessments
- Perform end-to-end third-party cybersecurity assessments in accordance with established assessment methodology and risk requirements.
- Conduct engagement and/or application-specific remote assessments based on defined scope.
- Review vendor security questionnaires, supporting documentation, policies, procedures, and evidence.
- Compare current Control Assessment (CA) vendor responses with previous assessments to identify and document changes in the vendor’s control environment.
- Identify control gaps, risk observations, and changes in the vendor’s security posture.
- Request and participate in assessment kickoff meetings and conduct follow-up discussions with vendors where required.
- Conduct SME interviews, control walkthroughs, demonstrations, and evidence validation sessions.
- Validate the effectiveness and implementation of applicable cybersecurity controls.
Control Mapping & Assessment Analysis
- Map vendor SOC 2 controls, SIG questionnaire responses, or equivalent third-party assurance artifacts to applicable company security questionnaires and control requirements.
- Evaluate whether existing third-party assurance reports and artifacts provide sufficient coverage of required controls.
- Identify control areas requiring additional clarification, evidence, or testing.
- Assess the applicability and effectiveness of controls based on the vendor’s environment, services, data access, and risk profile.
Findings & Reporting
- Identify and document initial assessment observations and potential control exceptions.
- Work with vendors and internal stakeholders to clarify assessment findings and obtain additional evidence where required.
- Determine and document final Control Exceptions based on assessment results.
- Prepare clear, concise, and evidence-based assessment findings and recommendations.
- Produce final assessment letters, results, and supporting documentation.
- Ensure assessment records are complete, accurate, and audit-ready.
Stakeholder Management
- Collaborate with vendors, internal security teams, application owners, procurement, risk teams, and other stakeholders.
- Communicate assessment requirements, observations, evidence gaps, and control exceptions effectively.
- Conduct assessment follow-ups and manage outstanding actions through closure.
- Support consistent application of the organization’s third-party cybersecurity assessment methodology.
Required Skills & Experience
- 5+ years of experience in Information Security, IT Audit, Cybersecurity Risk, GRC, or Third-Party Risk Management.
- Proven experience conducting Third-Party Cybersecurity / TPRM assessments.
- Strong experience in:
- Security control assessments
- Evidence review and validation
- SME interviews and walkthroughs
- Vendor risk assessments
- Control gap identification
- Assessment report writing
- Experience validating controls through walkthroughs, demonstrations, interviews, and supporting evidence.
- Strong understanding of cybersecurity controls and risk management practices.
- Ability to independently assess vendor security environments and determine control effectiveness.
Cybersecurity Domain Knowledge
Strong understanding of the following areas:
- Identity & Access Management (IAM)
- Privileged Access Management (PAM)
- Vulnerability Management
- Patch Management
- Cloud Security
- Incident Response & Management
- Security Operations
- Security Governance
- Data Protection & Sensitive Data Handling
- Production Support Controls
- Change Management
- Business Continuity / Disaster Recovery
- Physical Security
- Third-Party / Vendor Risk Management
Framework & Assurance Knowledge
Working knowledge of cybersecurity frameworks and assurance standards, including:
- NIST CSF
- ISO/IEC 27001
- CIS Controls
- SOC 2
- SIG / SIG Lite or equivalent third-party security questionnaires
- IT General Controls (ITGC)
- Risk-based control assessment methodologies
Assessment & Audit Capabilities
- Ability to perform onsite and remote assessments, where required.
- Experience validating controls through control walkthroughs, interviews, system demonstrations, and evidence inspection.
- Ability to distinguish between control design and operating effectiveness.
- Strong documentation and report-writing skills.
- Ability to translate technical control observations into clear business and risk language.
- Strong attention to detail and ability to challenge inadequate or incomplete evidence.
Preferred Qualifications
- CISA, CISSP, CRISC, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent certification.
- Experience with enterprise TPRM/GRC platforms.
- Experience assessing cloud service providers, SaaS vendors, technology vendors, and critical third parties.
- Experience working in regulated or highly controlled environments.
Key Competencies
- Third-Party Cybersecurity Assessment
- Cyber Risk Assessment
- Control Testing & Validation
- Evidence Review
- Vendor/Supplier Risk Management
- SOC 2 & SIG Assessment
- Control Mapping
- IAM & Privileged Access
- Cloud & Infrastructure Security
- Risk & Control Analysis
- Findings & Exception Management
- Assessment Report Writing
- Stakeholder & Vendor Management
Strong Analytical & Communication Skills
The candidates should be experienced on:
- Security Frameworks:
- Deep understanding of widely accepted information security frameworks, NIST Cybersecurity, HIPAA, PCI, Shared Assessments (SIG), etc
- Cloud Security:
- Demonstrated understanding of cloud security.
- Experience evaluating cloud hosting environment
- Risk Management:
- Experience identifying, assessing, monitoring, and prioritizing Infosec risks across multiple domains
- Experience evaluating the effectiveness of supplier/third party managed cybersecurity requirements.
- Vulnerability & Pen testing:
- Experience evaluating pen testing and vuln scanning methodologies.
- Experience interpreting the security testing results.
- Relevant Information Security/Risk Management Certifications (nice to have)
- CISM, CRISC, CISA, CISSP, CCSP, CCSK, CCSA



