TPRM Analyst-3-6Yrs || Immediate joiners || Gurgaon ONLY

  • Full-time

Company Description

WNS, part of Capgemini, is an Agentic AI-powered leader in intelligent operations and transformation, serving more than 700 clients across 10 industries, including Banking and Financial Services, Healthcare, Insurance, Shipping and Logistics, and Travel and Hospitality. We bring together deep domain excellence – WNS’ core differentiator – with AI-powered platforms and analytics to help businesses innovate, scale, adapt and build resilience in a world defined by disruption.Our purpose is clear: to enable lasting business value by designing intelligent, human-led solutions that deliver sustainable outcomes and a differentiated impact. With three global headquarters across four continents, operations in 13 countries, 65 delivery centers and more than 66,000 employees, WNS combines scale, expertise and execution to create meaningful, measurable impact.

Job Description

Job Title: TPRM Analyst
Experience: 1–3 years
Location: Gurgaon (WFO)
Department: Risk / Information Security / GRC

The TPRM Analyst will support the client organization’s Third-Party Risk Management program by assessing and monitoring risks arising from vendors, suppliers, and other external partners across cybersecurity, privacy, business continuity, and compliance domains. The role requires strong analytical ability, stakeholder coordination, and clear written and verbal communication to review vendor submissions, identify risk indicators, and support remediation and reporting activities.

Responsibilities

• Perform third-party risk assessments and due diligence reviews for vendors across cyber, privacy, BCP, and compliance domains.

• Review vendor questionnaires, policies, certifications, audit reports, and supporting evidence to identify gaps, inconsistencies, and risk indicators.

• Coordinate with internal SMEs such as Information Security, Privacy, Compliance, Legal, Procurement, and Business teams to validate assessment responses and support risk decisions.

• Track remediation items, follow up on open issues, and maintain assessment records, dashboards, and evidence repositories.

• Support maintenance of TPRM procedures, templates, SOPs, and reporting documentation to improve consistency and audit readiness.

• Assist with vendor tiering, ongoing monitoring, and periodic reassessments based on risk exposure and business criticality.

• Prepare concise risk summaries and communicate findings clearly to internal stakeholders and management.

Requirements
• 1–3 years of experience in TPRM, GRC, information security, privacy, compliance, audit, or related risk roles.

• Basic understanding of third-party risk management, vendor due diligence, risk assessment, and control review methodologies.

• Familiarity with cybersecurity, privacy, business continuity, and compliance frameworks such as ISO 27001, NIST, GDPR, or similar standards are preferred.

• Strong written and verbal communication skills, with the ability to engage stakeholders professionally and document findings clearly.

• Good analytical and problem-solving skills, with attention to detail in reviewing questionnaires and evidence.

• Ability to work collaboratively across cross-functional teams and manage multiple assessments within timelines.

• Exposure to tools such as ServiceNow, Archer, OneTrust, Coupa, or similar GRC/TPRM platforms is preferred.

 

Qualifications

Bachelor's Degree. Preferred certifications can include CISA, CISM, ISO 27001, ISO 22301, Certified in Data Privacy or other risk, privacy, business continuity, or compliance-related certifications.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy NoticeImprint