📍 Hyderabad, India

About this role

Job Summary

Security GRC Analyst - Third Party Risk Management (TPRM) L1 Role Summary The Security GRC TPRM L1 Analyst is responsible for supporting the organization\'s Third-Party Risk Management program by assessing, monitoring, and reporting security risks associated with vendors, suppliers, and external partners. The role involves conducting security assessments, reviewing vendor security controls, tracking remediation activities, and ensuring compliance with organizational and regulatory requirements. Experience Range: 1-3 Years Job Level: L1 Analyst Function: Security Governance, Risk & Compliance (GRC) - Third Party Risk Management (TPRM) Technical Skills • Understanding of Information Security and Cybersecurity principles. • Knowledge of Third-Party Risk Management processes. • Familiarity with security frameworks such as: o NIST Cybersecurity Framework o ISO 27001 o SOC 2 o CIS Controls o PCI-DSS • Basic understanding of cloud security concepts (Azure, AWS, GCP). • Experience with security questionnaires and vendor assessments.

Security GRC Analyst - Third Party Risk Management (TPRM) L1\\\\r\\\\nRole Summary\\\\r\\\\nThe Security GRC TPRM L1 Analyst is responsible for supporting the organization\\\\\\\'s Third-Party Risk Management program by assessing, monitoring, and reporting security risks associated with vendors, suppliers, and external partners. The role involves conducting security assessments, reviewing vendor security controls, tracking remediation activities, and ensuring compliance with organizational and regulatory requirements.\\\\r\\\\nExperience Range: 1-3 Years\\\\r\\\\nJob Level: L1 Analyst\\\\r\\\\nFunction: Security Governance, Risk & Compliance (GRC) - Third Party Risk Management (TPRM)\\\\r\\\\nTechnical Skills\\\\r\\\\n• Understanding of Information Security and Cybersecurity principles.\\\\r\\\\n• Knowledge of Third-Party Risk Management processes.\\\\r\\\\n• Familiarity with security frameworks such as: \\\\r\\\\no NIST Cybersecurity Framework\\\\r\\\\no ISO 27001\\\\r\\\\no SOC 2\\\\r\\\\no CIS Controls\\\\r\\\\no PCI-DSS\\\\r\\\\n• Basic understanding of cloud security concepts (Azure, AWS, GCP).\\\\r\\\\n• Experience with security questionnaires and vendor assessments.\\\\r\\\\nKey Responsibilities\\\\r\\\\nThird-Party Security Assessments\\\\r\\\\n• Perform initial and recurring security assessments for third-party vendors.\\\\r\\\\n• Review vendor security questionnaires and supporting evidence.\\\\r\\\\n• Analyze vendor security controls against organizational security requirements.\\\\r\\\\n• Identify security risks and document assessment findings.\\\\r\\\\nRisk Management\\\\r\\\\n• Evaluate risks associated with third-party engagements.\\\\r\\\\n• Assign risk ratings based on established risk assessment methodologies.\\\\r\\\\n• Track identified risks and remediation actions.\\\\r\\\\n• Escalate high-risk findings to senior security and business stakeholders.\\\\r\\\\nCompliance & Governance\\\\r\\\\n• Ensure vendor compliance with security policies, standards, and regulatory requirements.\\\\r\\\\n• Support compliance initiatives related to ISO 27001, SOC 2, GDPR, HIPAA, PCI-DSS, NIST, and other applicable frameworks.\\\\r\\\\n• Maintain assessment records and audit evidence.\\\\r\\\\nRequired Skills\\\\r\\\\nGovernance, Risk & Compliance Skills\\\\r\\\\n• Risk identification and assessment.\\\\r\\\\n• Policy and compliance management.\\\\r\\\\n• Audit support and evidence management.\\\\r\\\\n• Vendor risk analysis and reporting. 

Key Responsibilities

Key Responsibilities Third-Party Security Assessments • Perform initial and recurring security assessments for third-party vendors. • Review vendor security questionnaires and supporting evidence. • Analyze vendor security controls against organizational security requirements. • Identify security risks and document assessment findings. Risk Management • Evaluate risks associated with third-party engagements. • Assign risk ratings based on established risk assessment methodologies. • Track identified risks and remediation actions. • Escalate high-risk findings to senior security and business stakeholders. Compliance & Governance • Ensure vendor compliance with security policies, standards, and regulatory requirements. • Support compliance initiatives related to ISO 27001, SOC 2, GDPR, HIPAA, PCI-DSS, NIST, and other applicable frameworks. • Maintain assessment records and audit evidence.

Skill Requirements

Required Skills Governance, Risk & Compliance Skills • Risk identification and assessment. • Policy and compliance management. • Audit support and evidence management. • Vendor risk analysis and reporting.

Other Requirements

Frequently Asked Questions

Is the salary disclosed for the Sr Analyst position at HCLTech?
The salary for this Sr Analyst role at HCLTech is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Sr Analyst position at HCLTech located?
This Sr Analyst role at HCLTech is based in Hyderabad, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
How do I apply for the Sr Analyst position at HCLTech?
Click the "Apply Now" button on this page. You will be redirected to HCLTech's official application portal hosted on successfactors where you can submit your application directly.
When was the Sr Analyst job at HCLTech posted?
This Sr Analyst position at HCLTech was posted on Sep 29, 2026. Apply as soon as possible — early applications are often reviewed first.
Sr Analyst
HCLTech
Apply for this role ↗

You'll be redirected to HCLTech's official application page on successfactors.