Overview
Associate role supporting Baker Tilly One India’s third-party risk management, governance, risk, and compliance activities.
What you'll do
- Support vendor onboarding, risk assessments, due diligence reviews, ongoing monitoring, and periodic reassessments.
- Review third-party/vendor documentation (e.g., SOC 2 Type II reports, security/privacy policies, ISO reports, penetration test reports, architectural diagrams) to identify risks and control gaps.
- Maintain third-party risk records, documentation, remediation items, approvals, and supporting evidence in the Third-Party Risk Management tool.
- Coordinate stakeholder responses for client due diligence requests, security questionnaires, RFPs, and audit inquiries.
- Maintain and update response libraries and supporting documentation used for client due diligence.
- Support audit and compliance activities across frameworks and programs (e.g., SOC 2 Type II, ISO 27001, NIST CSF, HIPAA, PCI-DSS, SOX).
- Prepare management updates including status, metrics, dashboards, and summaries.
What you'll need
- Bachelor’s degree in information technology systems, cybersecurity, risk management, internal audit, or a related field.
- 2 years of experience in third-party risk management, governance, risk & compliance, IT audit, internal audit, or cybersecurity/control assessment.
- Familiarity with one or more compliance/audit frameworks such as SOC 2, ISO 27001, NIST CSF, HIPAA, CMMC, HITRUST, PCI-DSS, or SOX.
- Ability to collaborate cross-functionally with strong written and verbal communication, including drafting responses.
- Attention to detail, ability to manage multiple priorities/deadlines, and to analyze documentation to summarize findings.
- Basic understanding of contract terms related to cybersecurity, privacy, confidentiality, data processing, audit rights, breach notification, and regulatory compliance.
Read the full description and apply on the company’s own careers page.