Third Party Cyber Risk Services Operations - Lead Analyst at oil and Gas Industry (petroleum refinery) Ā· Bengaluru (Bangalore) Ā· 10 - 15 years Ā· ā¹15L - ā¹40L / yr Ā· Posted 22 Apr 2026

Third Party Cyber Risk Services Operations - Lead Analyst
at oil and Gas Industry (petroleum refinery)
š¹ Role: Third Party Cyber Risk Services Operations ā Lead Analyst
š Location: Bellandur, Bangalore
š Work Timings: 01:30 PM ā 10:30 PM
š Type: Contract to hire
š¢ Work Mode: Monday (WFH), TuesdayāFriday (WFO)
š Experience: 10ā12 Years
Ā
Job Summary:
Role Summary
The Lead Analyst will support Third-Party Cyber Risk Services operations by managing daily intake, executing workflows, and delivering data-driven risk assessments. This role is responsible for making defensible third-party risk decisions (including accept/reject), partnering with cross-functional stakeholders, and strengthening organizational cyber resilience.
Ā
Key Responsibilities
Third-Party Risk Management
- Manage and maintain the third-party risk management framework
- Perform inherent and residual risk assessments using data-driven methodologies
- Identify cyber risks associated with third-party vendors
Risk Analysis & Mitigation
- Define, implement, and track mitigation and risk treatment plans
- Analyse trade-offs to manage residual risk effectively
- Support defensible risk decisions aligned with business objectives
Stakeholder Collaboration
- Partner with:
- Procurement (contract advisors, category managers)
- Legal teams
- Business/Product owners
- Risk managers & analysts
- Security engineers & threat intelligence teams
- Communicate risk insights, impacts, and recommendations clearly
Operations & Delivery
- Manage intake and prioritize work based on risk
- Meet SLAs without compromising quality
- Handle escalations and resolve high-risk issues promptly
Process Improvement & Automation
- Define and enhance processes, procedures, and tools
- Identify efficiency opportunities and leverage automation/AI
- Drive continuous improvement initiatives
Metrics & Reporting
- Develop and analyse risk metrics and dashboards
- Track trends, risk posture, and control effectiveness
Required Qualifications
Core Expertise
- Strong experience in Third-Party Risk Management (TPRM)
- Knowledge of information security concepts: threat, vulnerability, impact
- Ability to apply risk concepts to policies, standards, and controls
Framework Knowledge
- Hands-on experience with NIST Cybersecurity Framework (CSF)
- Understanding of control effectiveness and compliance assurance
Analytical & Problem-Solving Skills
- Strong critical thinking and risk analysis capability
- Ability to break down complex problems and work in ambiguous environments
- Experience in designing and maturing processes
Communication & Leadership
- Excellent written and verbal communication skills
- Ability to influence stakeholders across levels
- Strong cross-functional collaboration skills
Agile & Execution Skills
- Experience working in agile environments
- Ability to prioritize tasks, remove blockers, and adapt quickly
Key Competencies
- Risk Assessment & Decision-Making
- Cybersecurity & Compliance
- Stakeholder Management
- Process Optimization
- Data-Driven Insights
- Automation & InnovationĀ

Similar jobs (4)
ServiceNow TPRM Sr.Solution Engineer (Offshore)
Ā· Location- Remote
Ā· Contract- 6 months
Ā· Budget- 1.50 lpm
Job Description
Position Description:Ā
Ā
Templar Shield is seeking a highly skilled ServiceNow TPRM Sr. Solution Engineer to provide advisory and technical leadership for the design, optimization, implementation, and sustainment of ServiceNow Third-Party Risk Management solutions. This role translates business needs into practical platform capabilities, prioritizes out-of-box functionality, and delivers solutions aligned with Templar Shield and ServiceNow best practices.Ā
Ā ā
Requirements
Primary Objectives:
Ā· Provide advisory support and implementation best practices for ServiceNow Third-Party Risk Management.
Ā· Assess and optimize existing ServiceNow TPRM implementations, including processes, workflows, configurations, and operating practices.
Ā· Review and refine third-party risk tiering, Inherent Risk Questionnaires (IRQ), Vendor Risk Assessments (VRA), and scoring methodologies to improve consistency and alignment with business needs.
Ā· Define and recommend solution options for formally tracking risk mitigation activities in ServiceNow, considering applicable licensing constraints and other business, technical, and operational factors.
Ā· Support the creation, review, and refinement of ServiceNow user stories, acceptance criteria, process designs, test plans, and implementation documentation using Agile/Scrum methods.
Ā· Provide advisory and subject matter expert support for client-led development, testing, validation, defect management, user acceptance testing, rollout planning, and rollout execution.
Ā· Prepare and support project-related documentation, solution demonstrations, and stakeholder presentations.
Ā· Provide post-rollout hypercare, troubleshooting, and knowledge transfer for the TPRM solution in accordance with the applicable project plan or other written agreement.Ā Ā
Ā· Provide knowledge transfer and advisory support to client personnel for ongoing operation, administration, and sustainment of the TPRM program following project completion.Ā Ā
Ā· Design, configure, implement, and support TPRM workflows, assessments, notifications, reporting, dashboards, portals, integrations, approval paths, exceptions, and ongoing monitoring.Ā Ā
Ā· Develop and maintain integrations between ServiceNow TPRM and third-party tools using APIs and web services, including JSON, SOAP, and XML.Ā Ā
Ā· Create and maintain solution design specifications, configuration records, deployment notes, troubleshooting guidance, and technical knowledge articles.Ā
Ā· Provide technical guidance and TPRM best practices to client teams; train and mentor junior consultants and administrators.Ā Ā
Ā· Collaborate effectively with distributed teams and manage assigned work in alignment with client expectations and delivery standards.
Qualifications:Ā
Core Experience:
Ā· 5+ years of ServiceNow development or implementation experience, including at least 3 years focused on ServiceNow TPRM.
Ā· Bachelor's degree from an accredited college or university, or equivalent relevant professional experience.
Ā· Demonstrated ability to lead technical workstreams, facilitate client discussions, solve complex problems, and exercise independent judgment in a customer-focused consulting environment.
Ā· Excellent written and verbal communication, analytical, documentation, troubleshooting, and teamwork skills.
Technical Skills:
Ā· Strong hands-on knowledge of ServiceNow TPRM and relevant platform capabilities, including Flow Designer, UI Builder, business rules, notifications, UI pages, UI macros, formatters, database views, reporting, dashboards, and role-based security.
Ā· Proficiency in ServiceNow scripting and development, including JavaScript, Glide API, web services, and application configuration; experience with HTML and CSS. Familiarity with React, AngularJS, or Java is beneficial.
Ā· Ability to design TPRM data models, workflow automation, integrations, security roles, reports, and client-specific configurations while maintaining platform upgradeability.
Ā· Knowledge of third-party risk assessment, compliance, control testing, issue management, remediation, internal audit, and continuous monitoring methodologies.
Ā· Knowledge of common security and compliance frameworks, such as NIST SP 800-53, NIST SP 800-171, NIST CSF, ISO 27000 series, PCI DSS, CIS, and NERC CIP. Knowledge of ServiceNow Performance Analytics, ITSM, or ITOM is a plus.
Certifications:
Ā· ServiceNow Certified System Administrator required. ServiceNow Certified Implementation Specialist in TPRM preferred.
This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).
Key responsibilities:
- Perform security control assessments against organizational policies, security standards, and regulatory requirements.
- Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
- Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
- Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
- Conduct control testing and risk assessments and support internal/external security audits.
- Review security policies, procedures, standards, and governance frameworks for compliance.
- Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
- Support overall security governance, regulatory compliance, and IT risk management activities.
Required Skills
- Cyber Security Risk & Compliance / GRC
- IT Risk & Controls
- Security Control Assessment & Testing
- Security Audits
- Backup & Disaster Recovery
- BCP / DR
- Risk Assessment
- Compliance & Governance
- Security Policies & Standards
- Audit Finding & Remediation Management
This role will be permanent with NAM info and deploy to client location Chennai.
Work Mode: WORK FROM OFFICE
Offer salary can offer on a decent hike
Role Descriptions:
Exp Range: 6-10 years
Primary Competency : Terraform, Hashi Sentinel (IaC/PaC), Kubernetes (GKE/EKS)
City Locations: Bengaluru or Chennai
Key Responsibilities*
Experience Required: 6-10
Role Descriptions:
Security Monitoring & Incident Response
Investigate and analyze security alerts escalated by L1 SOC analysts.
Perform triage, containment, eradication, and recovery activities for security incidents.
1. Perform in-depth analysis of security alerts escalated from L1
2. Investigate suspicious activities using SIEM, EDR, and threat intelligence tools
3. Correlate events across multiple log sources (firewalls, endpoints, IAM, cloud logs)
4. Validate true positives and recommend reducing false positives
5. Lead triage and response for medium to high severity incidents
6. Coordinate with IT, network, and application teams during incidents and support deep investigations when required
7. Conduct proactive threat hunting based on TTPs (e.g., MITRE ATT&CK)
8. Fine-tuning and optimize SIEM use cases to reduce false positives
9. Develop new correlation rules and detection logic
10. Document incidents, findings, and response actions
11. Prepare weekly , monthly reports for SOC leadership and stakeholders
Desire candidate
- Candidate should have valid PF.
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
Roles & Responsibilities
- Develop and customize ServiceNow solutions with strong focus onĀ IRM and Third-Party Risk Management (TPRM).
- Configure and customizeĀ TPRM workflowsĀ covering third-party onboarding, due diligence, risk assessments and review processes.
- ConfigureĀ questionnaires, assessment templates, scoring methodologies, risks, controls and control objectives.
- Develop and configureĀ Business Rules, Client Scripts, UI Policies, ACLs, Forms and Catalog components.
- Automate approval and vendor onboarding workflows usingĀ Flow Designer.
- Work on ServiceNow scripting usingĀ JavaScript and Glide APIs.
- Develop integrations with external systems usingĀ REST APIs, Scripted REST APIs and REST Messages.
- Create and customize tables, fields, forms, reports and dashboards based on business requirements.
- Work on ServiceNowĀ Policy & Compliance / Risk & ComplianceĀ capabilities wherever required.
- Troubleshoot workflows, approvals, notifications, integrations and other ServiceNow issues.
- Follow ServiceNow development best practices, change management and deployment processes.
Ideal Candidate
1.Strong ServiceNow Developer / ServiceNow IRM / TPRM profiles
2.Mandatory (Experience 1) - Must have minimum 3+ years of overall IT experience with strong hands-on experience in ServiceNow Development, including configuration, customization and implementation.
3Mandatory (Experience 2) - Must have strong hands-on experience in ServiceNow Integrated Risk Management (IRM), with specific experience in Third-Party Risk Management (TPRM)
4.Mandatory (Experience 3) - Must have hands-on experience working on end-to-end TPRM processes, including Third-Party/Vendor Onboarding, Due Diligence, Risk Assessment, Review and Approval workflows
5.Mandatory (Experience 4) - Must have experience configuring and customizing TPRM questionnaires, assessment templates, scoring methodologies, Risk, Risk Statements, Controls and Control Objectives
6.Mandatory (Experience 5) - Must have strong ServiceNow development experience with Business Rules, Client Scripts, UI Policies, ACLs, Forms, Tables and Fields
7Mandatory (Experience 6) - Must have hands-on experience with Flow Designer for workflow automation, including vendor onboarding, approvals and TPRM-related business processes
8.Mandatory (Experience 7) - Must have strong programming/scripting experience in JavaScript and ServiceNow Glide APIs, with hands-on development of client-side and server-side scripts
9.Mandatory (Experience 8) - Must have experience developing integrations with external systems using REST APIs, Scripted REST APIs and REST Messages
10.Mandatory (Experience 9) - Must have strong experience troubleshooting ServiceNow workflows, approvals, notifications and integrations
11.Mandatory (Domain Exclusion) - Candidate must have hands-on development experience in TPRM/IRM; profiles with only ServiceNow ITSM, ServiceNow Administration or generic ServiceNow support experience will not be considered. - Required
12.Mandatory (Age) - Candidate's Age should be below 28 years.
13.Mandatory (CTC) - The CTC breakup offered will be 75% fixed + 25% variable, as per company policy
14.Preferred (Experience 1) - Candidates with experience in ServiceNow Policy & Compliance and/or Audit Management modules will be preferred.
15.Preferred (Experience 2) - Candidates with ServiceNow CSA / CIS certifications, particularly certifications related to IRM, Risk, Compliance or relevant ServiceNow modules, will be preferred.
16.Preferred (Experience 3) - Experience with ServiceNow Workspace, instance upgrades, quarterly cloning, deployment/change management and platform optimization will be preferred
17.Preferred (Certification) - ServiceNow CSA or CIS certifications, especially CIS-IRM or CIS-TPRM.






