TRPD-26-04464
Cybersecurity Assessment Specialist – Third-Party Risk Management (TPRM)
Hire a 5–10 year cybersecurity/technology risk professional to run third-party cybersecurity assessments (TPRM): review supplier questionnaires and evidence (SOC1/SOC2, ISO 27001, pen test and vulnerability reports, policies, BCP/DR docs), identify control gaps, rate inherent/residual risk, agree remediation/compensating controls or risk acceptance, and track findings to closure while meeting SLAs and supporting audit/regulatory needs.
Position summary
- Location
- India
- Workplace
- Hybrid
- Employment
- Full Time
- Experience
- Minimum 5 years and Maximum 10 years
Role overview
Why This Role Matters.
Hire a 5–10 year cybersecurity/technology risk professional to run third-party cybersecurity assessments (TPRM): review supplier questionnaires and evidence (SOC1/SOC2, ISO 27001, pen test and vulnerability reports, policies, BCP/DR docs), identify control gaps, rate inherent/residual risk, agree remediation/compensating controls or risk acceptance, and track findings to closure while meeting SLAs and supporting audit/regulatory needs.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Review and evaluate supplier responses to security questionnaires and assessment frameworks against defined control requirements.
Analyze supporting evidence such as SOC 1/SOC 2 reports, ISO 27001 certificates, penetration testing reports, policies, vulnerability reports, business continuity documentation and security assessments.
Identify control gaps, cybersecurity risks and potential areas of exposure; assess the inherent and residual risk associated with third parties.
Validate remediation plans and track open findings/issues through to closure.
Support risk-based decision making, including identification of compensating controls, risk acceptance and remediation requirements.
Perform assessments of third parties providing critical, high-risk or technology-enabled services.
Document assessment results, risk ratings, findings and recommendations in TPRM platforms/tools.
Engage with third-party stakeholders and internal teams to obtain clarifications, evidence and remediation updates.
Support escalation and reporting of overdue or high-risk findings to relevant stakeholders.
Contribute to continuous improvement of TPRM assessment methodologies, processes, control frameworks and assessment templates.
Support regulatory and audit requirements related to third-party cybersecurity and operational resilience.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
TPRM
Third-Party Risk Management
Third Party Risk
Vendor Risk Management
VRM
Cybersecurity assessment
Technology risk
IT risk
GRC
SOC 1
SOC 2
ISO 27001
NIST CSF
CIS Controls
PCI DSS
IAM
PAM
Vulnerability management
Patch management
Penetration testing
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Third-Party Risk Management (TPRM) / third-party cybersecurity assessments
Cybersecurity risk assessment methodologies (inherent vs residual risk, risk rating)
Control assessment/control testing and gap analysis
Security questionnaire/framework evaluation
Evidence review and interpretation (SOC 1/SOC 2, ISO 27001, pen test reports, vulnerability reports, policies, BCP/DR documentation)
Cybersecurity domain knowledge: IAM/PAM, vulnerability & patch management, network/infrastructure security, application/SDLC security, data protection & privacy, cloud security, security monitoring & incident response, BCP/DR, cryptography/key management, governance
Framework familiarity: ISO 27001, NIST CSF, CIS Controls, SOC 2, PCI DSS (or similar)
Remediation validation and issue tracking to closure (open findings management)
Documentation and reporting (assessment results, risk ratings, findings, recommendations)
Stakeholder management and ability to manage multiple assessments to SLA/turnaround
Preferred
Nice to Have
Certifications: CISA, CISM, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer (or equivalent)
Experience with TPRM/GRC platforms/tools
Financial services/banking/insurance experience
Knowledge of regulatory expectations for third-party risk and operational resilience
Cloud service provider and SaaS vendor assessments
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Cybersecurity Assessment Specialist – Third-Party Risk Management (TPRM)
One page, about two minutes. We only ask for what we actually need to have a first conversation.