Tata Consultancy Services

GRC TPRM Assessment and Remediation SME

Tata Consultancy Services$80K — $140K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
  • Knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ frameworks.
  • Experience with GRC/TPRM tools like OneTrust, Archer, or SupplierNinja.
  • Proven record managing complex communication workflows with tracking requirements.
  • Strong written communication skills for remote client engagement.
  • Experience in distributed or remote team environments.

Responsibilities

  • Maintain the Supplier Inventory as a single source of truth for assessment status.
  • Evaluate suppliers using established cybersecurity frameworks and validate evidence.
  • Own Corrective Action Plans, defining SLAs and tracking progress toward closure.
  • Coordinate with multiple departments on remediation timelines and controls.
  • Conduct structured stakeholder outreach and manage escalation processes.
  • Produce weekly metrics reports detailing outreach and assessment status.

Benefits

  • Fully remote work opportunity.
  • Engagement with high-visibility stakeholders.
  • Opportunity to manage critical vendor relationships.
  • Access to advanced GRC and TPRM tools.
  • Exposure to leadership reporting and metrics analysis.
Full Job Description
We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation from inventory governance through assessment coordination, escalation management, and executive reporting in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.

Key Responsibilities

1. Supplier Inventory Management
• Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
• Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
• Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).

2. Assessment Execution
• Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
• Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
• Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
• Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
• Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.

3. Remediation Management
• Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
• Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.

4. Stakeholder Communication & Escalation
• Run a structured outreach cadence with DRIs (kick-off 3 follow-ups 3 escalations to management).
• Track response/non-response rates for every outreach cycle.
• Escalate unresolved/high-risk findings to client leadership and track to closure.

5. Weekly Reporting

Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.

Required Qualifications
• 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
• Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
• Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
• Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
• Excellent written communication for remote, client-facing engagement.
• Experience operating in distributed/remote teams.

Preferred Qualifications
• Certification: CTPRP, CRISC, CISA, or CISSP.
• Experience with Wrike, AirTable, Jira, or similar tracking tools.
• Prior experience in regulated industries (financial services, healthcare, insurance).
• Track record producing leadership-facing weekly reporting.

Location : Sunnyvale, CA/Austin, TX

Salary Range : $80,000-$140,000 a year

#LI-AS3

About Tata Consultancy Services

Tata Consultancy Services (TCS) is an Indian multinational information technology (IT) services and consulting company, headquartered in Mumbai, Maharashtra, India. It is a subsidiary of Tata Group and operates in 149 locations across 46 countries. TCS is the largest Indian company by market capitalization and is ranked 11th on the Forbes Global 2000 list of the world's biggest public companies. TCS is also the second-largest IT services company in the world by revenue and the largest employer of women in India. The company provides services in areas including IT, consulting, and business solutions.
Learn more about Tata Consultancy Services
Size
469,261 employees
Industry

Similar Jobs

More Jobs at Tata Consultancy Services

More Enterprise Technology Jobs

Find similar GRC TPRM Assessment and Remediation SME jobs: