Assistant Manager, Vendor Information Security Risk Management Specialist
Bengaluru, KA, India
Altisource
Helping servicers, originators and investors maximize results, minimize costs and mitigate risksCompany Description
ARE YOU READY TO WORK AT ALTISOURCE?
If so, nice to meet you; We are Altisource! We are seeking energetic, highly skilled self-starters who thrive in a dynamic and fast-paced environment. We can offer you an exciting career with meaningful work and great colleagues as well as many development opportunities.
Job Description
Job Overview
We are seeking a highly skilled and motivated Vendor Information Security Risk Management Specialist to join our team. This individual will be responsible for evaluating and tracking information security risks posed by third-party vendors and partners. As part of the G&C team, you will collaborate with various stakeholders to ensure the integrity, confidentiality, and availability of our data and systems when interacting with external entities.
Key Responsibilities
- Vendor Risk Assessments: Conduct comprehensive information security risk assessments on third-party vendors and service providers. Evaluate their security posture, identify vulnerabilities, and ensure compliance with company policies, industry standards, and legal/regulatory requirements.
- Risk Mitigation & Management: Collaborate with stakeholders to define risk mitigation strategies for third-party vendors. Monitor and manage the lifecycle of vendor risk and ensure that risk treatment plans are in place and executed.
- Compliance & Regulatory Oversight: Ensure that third-party vendors comply with relevant industry standards (e.g., GDPR, ISO 27001, SOC 2, etc.) and internal security policies.
- Contractual Security Requirements: Work closely with the legal and procurement teams to establish and enforce security terms in third-party contracts, including Service Level Agreements (SLAs) and Data Processing Agreements (DPAs).
- Continuous Monitoring: Implement processes and tools for ongoing monitoring of third-party security posture. Evaluate third-party security reports, incident response, and performance metrics to ensure adherence to agreed-upon security controls.
Qualifications
Qualifications
- Education: Bachelor’s degree any field.
- Experience:
- Minimum of 6 years of experience in information security, risk management, or a related field, with a focus on third-party risk management.
- Demonstrated experience in assessing and mitigating risks associated with third-party vendors, including security assessments, audits, and compliance management.
- Knowledge of industry frameworks such as SOC2, ISO 27001, and NIST.
- Skills:
- Strong understanding of information security principles and third-party risk management processes.
- Experience with vendor management tools and security risk assessment platforms.
- Strong communication skills to interact with technical and non-technical stakeholders.
- Ability to evaluate, interpret, and communicate security and compliance risks.
- Project management skills with the ability to prioritize tasks and meet deadlines.
- Technical Proficiency:
- Familiarity with security technologies, threat intelligence, and risk management tools.
- Understanding of cloud security, data protection, and privacy laws.
Personal Attributes
- Strong analytical and problem-solving skills.
- Detail-oriented with a focus on risk identification and mitigation.
- Proactive and self-motivated, able to work independently and in teams.
- Strong interpersonal skills, with the ability to build effective relationships across departments and external parties.
Additional Information
WORKING AT ALTISOURCE ADVANTAGES
Prosperity
· Competitive salary based on your experience and skills
Good Health
· Comprehensive insurance plans; - Medical insurance for employees and family, Personal Accident Benefit and Life Insurance for employees
· Wellness Programs – Doctor support, Psychologist, Counselor, Onsite health checkup camps, etc.
Happiness
· 10 paid holidays, plus 26 paid days off per year
· Lots of employee engagement activities
·
OUR CORE VALUES
For our employees, customers, and shareholders, we commit to…
· Act with Integrity – exhibit unwavering integrity, compliance, and ethical conduct at all times
· Energize People – enable exceptional people to energize their teams and drive results
· Empower Innovation – reward the relentless creation of innovative and compliant solutions to achieve our mission and generate value for our customers
· Exceed Customer Expectations – execute world-class solutions to deliver value and delight our customers
· Win as a Team – embrace the passion, energy, and power of our global teams to win as “One-Altisource”
· Enrich Communities – create positive impacts for the communities where we live and serve
Are you up to the challenge? What are you waiting for? Apply today!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits C Cloud Compliance GDPR Incident response ISO 27001 Monitoring NIST Privacy Risk assessment Risk management Security assessment SLAs SOC SOC 2 Threat intelligence Vendor management Vulnerabilities
Perks/benefits: Career development Competitive pay Health care Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.