跳到主要內容

Cybersecurity- TPRM Assessor

00070547546

#Cyber Security Experts#

Job Title: Third-Party Cybersecurity Risk Management (3PCRM) Assessor / SME

Experience: 5 to 15 years

Location: Bangalore only {Re-location fine}

Function: Cybersecurity / Third-Party Risk Management

Role Type: Individual Contributor

Role Overview

We are looking for an experienced 3PCRM Assessor to perform third-party cybersecurity risk assessments, evaluate vendor security controls, review evidence, conduct SME interviews and walkthroughs, and prepare assessment findings and final reports. The role requires strong knowledge of cybersecurity controls, risk frameworks, and third-party security assessment methodologies.

Key Responsibilities

Third-Party Cybersecurity Assessments

  • Perform end-to-end third-party cybersecurity assessments in accordance with established assessment methodology and risk requirements.
  • Conduct engagement and/or application-specific remote assessments based on defined scope.
  • Review vendor security questionnaires, supporting documentation, policies, procedures, and evidence.
  • Compare current Control Assessment (CA) vendor responses with previous assessments to identify and document changes in the vendor's control environment.
  • Identify control gaps, risk observations, and changes in the vendor's security posture.
  • Request and participate in assessment kickoff meetings and conduct follow-up discussions with vendors where required.
  • Conduct SME interviews, control walkthroughs, demonstrations, and evidence validation sessions.
  • Validate the effectiveness and implementation of applicable cybersecurity controls.

Control Mapping & Assessment Analysis

  • Map vendor SOC 2 controls, SIG questionnaire responses, or equivalent third-party assurance artifacts to applicable company security questionnaires and control requirements.
  • Evaluate whether existing third-party assurance reports and artifacts provide sufficient coverage of required controls.
  • Identify control areas requiring additional clarification, evidence, or testing.
  • Assess the applicability and effectiveness of controls based on the vendor's environment, services, data access, and risk profile.

Findings & Reporting

  • Identify and document initial assessment observations and potential control exceptions.
  • Work with vendors and internal stakeholders to clarify assessment findings and obtain additional evidence where required.
  • Determine and document final Control Exceptions based on assessment results.
  • Prepare clear, concise, and evidence-based assessment findings and recommendations.
  • Produce final assessment letters, results, and supporting documentation.
  • Ensure assessment records are complete, accurate, and audit-ready.

Stakeholder Management

  • Collaborate with vendors, internal security teams, application owners, procurement, risk teams, and other stakeholders.
  • Communicate assessment requirements, observations, evidence gaps, and control exceptions effectively.
  • Conduct assessment follow-ups and manage outstanding actions through closure.
  • Support consistent application of the organization's third-party cybersecurity assessment methodology.

Required Skills & Experience

  • 5+ years of experience in Information Security, IT Audit, Cybersecurity Risk, GRC, or Third-Party Risk Management.
  • Proven experience conducting Third-Party Cybersecurity / TPRM assessments.
  • Strong experience in:
  • Security control assessments
  • Evidence review and validation
  • SME interviews and walkthroughs
  • Vendor risk assessments
  • Control gap identification
  • Assessment report writing
  • Experience validating controls through walkthroughs, demonstrations, interviews, and supporting evidence.
  • Strong understanding of cybersecurity controls and risk management practices.
  • Ability to independently assess vendor security environments and determine control effectiveness.

Cybersecurity Domain Knowledge

Strong understanding of the following areas:

  • Identity & Access Management (IAM)
  • Privileged Access Management (PAM)
  • Vulnerability Management
  • Patch Management
  • Cloud Security
  • Incident Response & Management
  • Security Operations
  • Security Governance
  • Data Protection & Sensitive Data Handling
  • Production Support Controls
  • Change Management
  • Business Continuity / Disaster Recovery
  • Physical Security
  • Third-Party / Vendor Risk Management

Framework & Assurance Knowledge

Working knowledge of cybersecurity frameworks and assurance standards, including:

  • NIST CSF
  • ISO/IEC 27001
  • CIS Controls
  • SOC 2
  • SIG / SIG Lite or equivalent third-party security questionnaires
  • IT General Controls (ITGC)
  • Risk-based control assessment methodologies

Assessment & Audit Capabilities

  • Ability to perform onsite and remote assessments, where required.
  • Experience validating controls through control walkthroughs, interviews, system demonstrations, and evidence inspection.
  • Ability to distinguish between control design and operating effectiveness.
  • Strong documentation and report-writing skills.
  • Ability to translate technical control observations into clear business and risk language.
  • Strong attention to detail and ability to challenge inadequate or incomplete evidence.

Preferred Qualifications

  • CISA, CISSP, CRISC, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent certification.
  • Experience with enterprise TPRM/GRC platforms.
  • Experience assessing cloud service providers, SaaS vendors, technology vendors, and critical third parties.
  • Experience working in regulated or highly controlled environments.

Key Competencies

  • Third-Party Cybersecurity Assessment
  • Cyber Risk Assessment
  • Control Testing & Validation
  • Evidence Review
  • Vendor/Supplier Risk Management
  • SOC 2 & SIG Assessment
  • Control Mapping
  • IAM & Privileged Access
  • Cloud & Infrastructure Security
  • Risk & Control Analysis
  • Findings & Exception Management
  • Assessment Report Writing
  • Stakeholder & Vendor Management

Strong Analytical & Communication Skills

The candidates should be experienced on:

  • Security Frameworks:
    • Deep understanding of widely accepted information security frameworks, NIST Cybersecurity, HIPAA, PCI, Shared Assessments (SIG), etc
  • Cloud Security:
    • Demonstrated understanding of cloud security.
    • Experience evaluating cloud hosting environment
  • Risk Management:
    • Experience identifying, assessing, monitoring, and prioritizing Infosec risks across multiple domains
    • Experience evaluating the effectiveness of supplier/third party managed cybersecurity requirements.
  • Vulnerability & Pen testing:
    • Experience evaluating pen testing and vuln scanning methodologies.
    • Experience interpreting the security testing results.
  • Relevant Information Security/Risk Management Certifications (nice to have)
    • CISM, CRISC, CISA, CISSP, CCSP, CCSK, CCSA




关于高知特 (Cognizant)
高知特(Cognizant)(纳斯达克代码:CTSH)作为一家AI Builder和相关技术服务提供商,致力于通过打造全栈AI解决方案,帮助企业将人工智能投资转化为实际价值。公司凭借深厚的行业经验、流程优化和工程技术专长,将企业独特的业务场景融入科技系统,赋能组织释放人才潜能,推动切实成果,并帮助全球企业在瞬息万变的环境中保持领先。如需了解更多详情,敬请访问 cognizant.ai 或关注@cognizant。

补充雇佣信息
薪酬信息截至本职位发布之日为准。Cognizant 保留在适用法律允许的范围内随时修改该信息的权利。
申请人可能需要通过现场面试或视频会议的方式参加面试。此外,候选人在每次面试时可能需要出示其当前所在州或政府签发的有效身份证件。
Cognizant 是一家提供平等就业机会的雇主。在招聘过程中,您的申请和候选资格不会因种族、肤色、性别、宗教、信仰、性取向、性别认同、国籍、残疾、遗传信息、怀孕、退伍军人身份或任何其他受联邦、州或地方法律保护的特征而受到影响。

帮助您蓬勃发展与成长的福利

我们的福利计划以您为中心打造——帮助您享受充实、平衡且健康的生活。
有葉子的植物的藍色線條圖

财务健康

我们会定期审查市场数据,确保薪酬体现您所带来的价值。您的福利不仅限于薪资,还可能包括退休计划、财务教育等。

Stay Healthy Midnight Blue RGB

身心健康

我们通过带薪休假、在条件允许下的灵活工作安排、医疗保障计划、心理咨询、心理健康盟友计划等,赋能您将身心健康放在首位。

Build The Career You Want Midnight Blue RGB

您的职业发展,由您做主

在 Cognizant 提供的 35 万多个岗位中,您将有机会探索新的技术、行业和工作地点,并打造推动职业发展的关键技能。

Making A Meaningful Impact Midnight Blue RGB

现实世界的影响力

想想您所依赖的那些知名品牌。很可能,他们也依赖我们来帮助强化其业务。在这里,您将把大胆的想法转化为改善全球生活的解决方案。

还没有找到合适的机会吗?

获取为您量身定制的最新职位机会、招聘活动和公司新闻!

掌握最新动态