Alvarez & Marsal
See all jobs at Alvarez & MarsalAssociate, Security Governance Risk and Compliance
Posted 18 days ago
- Pay
- Not shared
- Location
- On-site · Bengaluru, Mumbai, Gurugram
- Experience
- 4–8 yrs · Mid-level
- Type
- Full-time
1
About Alvarez & Marsal
Alvarez & Marsal (A&M) is a global consulting firm with over 10,000 entrepreneurial, action and results-oriented professionals in over 40 countries. We take a hands-on approach to solving our clients' problems and assisting them in reaching their potential. Our culture celebrates independent thinkers and doers who positively impact our clients and shape our industry. The collaborative environment and engaging work—guided by A&M's core values of Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity—are why our people love working at A&M.
For details, please visit the company website: http://www.alvarezandmarsal.com
About A&M Global Capability Center Private Limited
In 2023, A&M established a high-quality global capability center in India. The capability center has dedicated centers of expertise which work with A&M leadership across multiple business units and geographies to enable efficient service delivery to A&M clients.
The GCC is designed to efficiently and innovatively scale client delivery teams to meet ongoing demands. It helps
A&M's global business units expand their talent pool in India, allowing them to hire specialized professionals, maintain competitive pricing, accelerate delivery speeds with a hybrid onshore-offshore team, and leverage automation with top-tier digital and analytics talent. The GCC blends industry and consulting professionals across multiple domains to drive change and add value.
Unlike traditional GCC models focused on back-office support, we partner with case teams for end-to-end case delivery and thought leadership. Nearly 90% of our consultants hold advanced degrees, and our leadership team boasts over 1000 years of combined experience. We serve all major markets, including the Americas, EMEA, and APAC, and work across various industries such as Consumer & Retail, Healthcare, Software & Technology, Automotive & Industrials, Hospitality & Leisure, Energy & Natural Resources, and Financial Services.
As we embark on this unique journey, the firm is actively seeking to build a strong, capable team for the center. The GCC is growing rapidly and is already a 500+ member team.
Position overview
The Security GRC Associate will play a critical role in managing and enhancing our Information Security third-party risk management program. This position will align to the team responsibilities of assessing, monitoring, and mitigating risks associated with third-party vendors, ensuring compliance with regulatory requirements and internal security policies.
This role will be focused on supporting client security questionnaires, vendor security assessments, and working closely with business stakeholders to align security measures commensurate with risk. The successful candidate requires a strong understanding of security controls with the ability to effectively assess and communicate technical security requirements to teams across the firm.
JD- Associate, Security Governance,
Risk & Compliance
2
How will you contribute?
The ideal candidate will have one or more of the following responsibilities:
- Security Third Party Risk Management:
- Identify vendor security risks for assessment against A&M risk appetite and submit risks into risk management platform.
- Maintain oversight of risk treatment and incorporate updates into monthly reports.
- Produce and deliver comprehensive risk assessments of vendors.
- Contribute to process improvements and development of vendor risk assessment frameworks and questionnaires.
- Execute vendor assessments within defined SLA’s utilizing GRC platforms and tools in line with A&M’s vendor security assessment process.
- Maintain, monitor and follow through on vendor security performance alerts by actively managing remediation and delivering monthly posture reviews.
- Client Security Questionnaires:
- Manage and complete client security questionnaires and assessments within defined SLA’s utilizing platforms in line with GRC’s client security assessment processes.
- Collaborate with internal teams (Privacy, Legal, IT) to gather accurate and comprehensive responses.
- Support and contribute to process improvements and continuous maintenance of question and response database.
- Contract Reviews:
- Evaluate Information Security terms in contracts to mitigate risks associated with client and vendor engagements, within defined SLA’s.
- Work with legal, privacy and business teams to ensure that contractual obligations align with the organization’s security policies and compliance requirements.
- Security Risk Reporting & Communication:
- Communicate identified risks and remediation strategies to both technical and non-technical stakeholders.
- Participate and execute governance activities including metrics gathering and reporting, and the performance of recurring internal assessment activities.
- Continuous Improvement:
- Suggest and implement process improvements, including use of Artificial Intelligence and automation.
3
Qualifications
The ideal candidate will have one or more of the following responsibilities:
Education & experience
- Bachelor's degree in Information Security, Risk Management, Business, or related field.
- Industry recognized certification in security (e.g., CRISC (Certified in Risk and Information Systems
Control), CTPRP (Certified Third-Party Risk Professional), CISSP (Certified Information Systems
Security Professional), CISM (Certified Information Security Manager)
- 3+ years of experience in GRC, third-party risk management, or information security.
- Experience in conducting vendor risk assessments and audits.
- Experience in managing and completing client security questionnaires.
- Experience in reviewing and advising on security clauses in legal contracts
Technical skills
- Familiarity with third-party risk management tools and platforms
- Knowledge of information security regulatory requirements
- Good understanding of security frameworks such as ISO 27001, NIST, etc.
Core competencies
- Excellent analytical, problem-solving, and decision-making skills.
- Strong communication and interpersonal skills.
- Ability to translate security risks to business accessible language and format.
- Ability to work collaboratively with cross-functional teams.
- Detail-oriented with the ability to prioritize, and manage multiple tasks simultaneously.
Your journey at A&M
We recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person’s unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy.
With top-notch training and on-the-job learning opportunities, you can acquire new skills and advance your career. We prioritize your well-being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M. The possibilities are endless for high-performing and passionate professionals.
Skills
- Third-Party Vendor Management
- Network Security Assessment
- Risk Assessment
- Remediation Tracking
- Security Audits
- Risk Registers
- Security Controls
- ISO 27001
- net framework
- Information Security Standards
- Information Security Contract Review
- Stackholder management
- Analytical skills
- Workflow Optimization
- Knowledge management