メインコンテンツに移動します。

Cybersecurity- TPRM Assessor

00070547546

#Cyber Security Experts#

Job Title: Third-Party Cybersecurity Risk Management (3PCRM) Assessor / SME

Experience: 5 to 15 years

Location: Bangalore only {Re-location fine}

Function: Cybersecurity / Third-Party Risk Management

Role Type: Individual Contributor

Role Overview

We are looking for an experienced 3PCRM Assessor to perform third-party cybersecurity risk assessments, evaluate vendor security controls, review evidence, conduct SME interviews and walkthroughs, and prepare assessment findings and final reports. The role requires strong knowledge of cybersecurity controls, risk frameworks, and third-party security assessment methodologies.

Key Responsibilities

Third-Party Cybersecurity Assessments

  • Perform end-to-end third-party cybersecurity assessments in accordance with established assessment methodology and risk requirements.
  • Conduct engagement and/or application-specific remote assessments based on defined scope.
  • Review vendor security questionnaires, supporting documentation, policies, procedures, and evidence.
  • Compare current Control Assessment (CA) vendor responses with previous assessments to identify and document changes in the vendor's control environment.
  • Identify control gaps, risk observations, and changes in the vendor's security posture.
  • Request and participate in assessment kickoff meetings and conduct follow-up discussions with vendors where required.
  • Conduct SME interviews, control walkthroughs, demonstrations, and evidence validation sessions.
  • Validate the effectiveness and implementation of applicable cybersecurity controls.

Control Mapping & Assessment Analysis

  • Map vendor SOC 2 controls, SIG questionnaire responses, or equivalent third-party assurance artifacts to applicable company security questionnaires and control requirements.
  • Evaluate whether existing third-party assurance reports and artifacts provide sufficient coverage of required controls.
  • Identify control areas requiring additional clarification, evidence, or testing.
  • Assess the applicability and effectiveness of controls based on the vendor's environment, services, data access, and risk profile.

Findings & Reporting

  • Identify and document initial assessment observations and potential control exceptions.
  • Work with vendors and internal stakeholders to clarify assessment findings and obtain additional evidence where required.
  • Determine and document final Control Exceptions based on assessment results.
  • Prepare clear, concise, and evidence-based assessment findings and recommendations.
  • Produce final assessment letters, results, and supporting documentation.
  • Ensure assessment records are complete, accurate, and audit-ready.

Stakeholder Management

  • Collaborate with vendors, internal security teams, application owners, procurement, risk teams, and other stakeholders.
  • Communicate assessment requirements, observations, evidence gaps, and control exceptions effectively.
  • Conduct assessment follow-ups and manage outstanding actions through closure.
  • Support consistent application of the organization's third-party cybersecurity assessment methodology.

Required Skills & Experience

  • 5+ years of experience in Information Security, IT Audit, Cybersecurity Risk, GRC, or Third-Party Risk Management.
  • Proven experience conducting Third-Party Cybersecurity / TPRM assessments.
  • Strong experience in:
  • Security control assessments
  • Evidence review and validation
  • SME interviews and walkthroughs
  • Vendor risk assessments
  • Control gap identification
  • Assessment report writing
  • Experience validating controls through walkthroughs, demonstrations, interviews, and supporting evidence.
  • Strong understanding of cybersecurity controls and risk management practices.
  • Ability to independently assess vendor security environments and determine control effectiveness.

Cybersecurity Domain Knowledge

Strong understanding of the following areas:

  • Identity & Access Management (IAM)
  • Privileged Access Management (PAM)
  • Vulnerability Management
  • Patch Management
  • Cloud Security
  • Incident Response & Management
  • Security Operations
  • Security Governance
  • Data Protection & Sensitive Data Handling
  • Production Support Controls
  • Change Management
  • Business Continuity / Disaster Recovery
  • Physical Security
  • Third-Party / Vendor Risk Management

Framework & Assurance Knowledge

Working knowledge of cybersecurity frameworks and assurance standards, including:

  • NIST CSF
  • ISO/IEC 27001
  • CIS Controls
  • SOC 2
  • SIG / SIG Lite or equivalent third-party security questionnaires
  • IT General Controls (ITGC)
  • Risk-based control assessment methodologies

Assessment & Audit Capabilities

  • Ability to perform onsite and remote assessments, where required.
  • Experience validating controls through control walkthroughs, interviews, system demonstrations, and evidence inspection.
  • Ability to distinguish between control design and operating effectiveness.
  • Strong documentation and report-writing skills.
  • Ability to translate technical control observations into clear business and risk language.
  • Strong attention to detail and ability to challenge inadequate or incomplete evidence.

Preferred Qualifications

  • CISA, CISSP, CRISC, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent certification.
  • Experience with enterprise TPRM/GRC platforms.
  • Experience assessing cloud service providers, SaaS vendors, technology vendors, and critical third parties.
  • Experience working in regulated or highly controlled environments.

Key Competencies

  • Third-Party Cybersecurity Assessment
  • Cyber Risk Assessment
  • Control Testing & Validation
  • Evidence Review
  • Vendor/Supplier Risk Management
  • SOC 2 & SIG Assessment
  • Control Mapping
  • IAM & Privileged Access
  • Cloud & Infrastructure Security
  • Risk & Control Analysis
  • Findings & Exception Management
  • Assessment Report Writing
  • Stakeholder & Vendor Management

Strong Analytical & Communication Skills

The candidates should be experienced on:

  • Security Frameworks:
    • Deep understanding of widely accepted information security frameworks, NIST Cybersecurity, HIPAA, PCI, Shared Assessments (SIG), etc
  • Cloud Security:
    • Demonstrated understanding of cloud security.
    • Experience evaluating cloud hosting environment
  • Risk Management:
    • Experience identifying, assessing, monitoring, and prioritizing Infosec risks across multiple domains
    • Experience evaluating the effectiveness of supplier/third party managed cybersecurity requirements.
  • Vulnerability & Pen testing:
    • Experience evaluating pen testing and vuln scanning methodologies.
    • Experience interpreting the security testing results.
  • Relevant Information Security/Risk Management Certifications (nice to have)
    • CISM, CRISC, CISA, CISSP, CCSP, CCSK, CCSA




コグニザントについて   
コグニザント(NASDAQ: CTSH)は、AI Builderおよびテクノロジーサービスプロバイダーとして、お客様にフルスタックのAIソリューションを構築することで、AI投資と企業価値を結ぶ架け橋となっています。業界、ビジネスプロセス、エンジニアリングに関する当社の深い専門知識を活かし、組織固有のビジネス環境をテクノロジー・システムに組み込みます。これにより、人間の可能性を最大限に引き出し、確かな成果を実現するとともに、急速に変化する世界においてグローバル企業が常に一歩先を行くための支援を行っています。 詳細については、cognizant.ai をご覧ください。  

雇用に関する追加情報
本募集に記載されている報酬情報は、掲載日時点で正確なものです。Cognizantは、適用される法令に従い、いつでも本情報を変更する権利を留保します。

応募者は、対面またはビデオ会議による面接への参加を求められる場合があります。また、各面接の際に、現在有効な州政府または政府発行の身分証明書の提示を求められる場合があります。

Cognizantは機会均等雇用主です。応募および選考において、人種、肌の色、性別、宗教、信条、性的指向、性自認、国籍、障がい、遺伝情報、妊娠、退役軍人の地位、その他連邦法・州法・地方自治体の法律により保護されるいかなる特性に基づく差別も行いません。

あなたが成長し、活躍できるよう支える福利厚生

当社の福利厚生プログラムは、あなたを第一に考えて設計されており、充実し、バランスの取れた健やかな生活を送れるようサポートします。

葉のある植物の青い線画

経済的なウェルビーイング

当社では市場データを定期的に見直し、皆さんがもたらす価値が正しく報酬に反映されるよう努めています。福利厚生は給与だけにとどまらず、退職金・年金制度や金融教育などが含まれる場合があります。

Stay Healthy Midnight Blue RGB

身体的およびメンタルヘルス

有給休暇、可能な範囲での柔軟な働き方、医療保険制度、カウンセリング、メンタルヘルス・アライシップ・プログラムなどを通じて、あなたが自身のウェルビーイングを大切にできるよう支援します。

Build The Career You Want Midnight Blue RGB

あなたのキャリアは、あなたの思い描くかたちで

Cognizantでは35万人以上の職種があり、新しいテクノロジー、業界、勤務地に挑戦する機会が広がっています。キャリア成長に必要なスキルを身につけ、自分らしいキャリアを築くことができます。
Making A Meaningful Impact Midnight Blue RGB

現実社会へのインパクト

あなたが信頼している世界的な大手ブランドを思い浮かべてみてください。その多くが、ビジネスをさらに強化するために私たちを頼りにしています。ここでは、大胆なアイデアを、世界中の人々の暮らしをより良くするソリューションへと形にしていくことができます。

まだ最適なポジションが見つかっていませんか?

あなたに合わせてカスタマイズされた、最新の求人情報、採用イベント、そして会社からのお知らせをお届けします!

最新情報を見逃さない