Source description
About the role
Why we need this role We are seeking a Security Supply Chain Risk Management Specialist to join our Security Governance, Risk and Compliance (GRC) team. This roleis responsible foridentifying, assessing, managing, andmonitoring security and ICT risks arising from third party suppliers, outsourcing arrangements, and sub contractors across the full vendor lifecycle. The position plays a critical role in ensuring compliance with DORA, NIS2, ISO/IEC 27001 , and related regulatory and contractual obligations, while strengthening the overall digital and operational resilience of the organization. Join us and you will be part of a fast-growing community of like-minded experts to grow and learn alongside you in your career. What you will do 1. ThirdParty Security Risk Management Design,operate, and continuously improve thesecurity supply chain risk management framework Performsecurity risk assessments and due diligenceof ICT suppliers, cloud providers, SaaS vendors, and critical service providers Classify suppliers based oncriticality, data access, service dependency, and systemic risk Identifyand trackconcentration risk, single points of failure, and exit complexity 2. Regulatory & Framework Alignment Ensure thirdparty security controls and processes align with: DORA (ICT thirdparty risk management requirements) NIS2 supply chain security obligations ISO/IEC 27001:2022 Annex A (supplier and ICT supply chain controls) Interpret regulatory requirements and translate them intopractical control expectations for suppliers Support audits, supervisory reviews, and assurance activities related to supply chain security 3. Supplier Lifecycle & Contractual Controls Define and enforcesecurity requirements for supplier onboarding, including: Minimum security baselines Evidence expectations (ISO certifications, SOC reports, penetration test summaries, etc.) Review and contribute tosecurityrelated contractual clauses, including: Audit and access rights Incident notification timelines Suboutsourcing controls Exit, portability, and business continuity provisions Support secureoffboarding andexit strategiesfor ICT providers 4. Continuous Monitoring & Assurance Establish andmaintainongoing monitoring of supplier security posture Track remediation plans, risk acceptances, and exceptions Coordinate periodic reassessments ofcritical and highrisk suppliers Maintainaccuratesupplier risk documentation and registers 5. Reporting & Stakeholder Engagement Providerisk reporting and insightsto security leadership and management Support internal awareness on supply chain risk trends and emerging threats Engage constructively with suppliers to driverisk reduction and security maturity What were looking for Must haves: Proven experience (typically 7+ years) in: Thirdparty risk management Information security risk management Technology, cloud, or outsourcing risk Strong understanding of ICT and cybersecurity risk concepts Supplier and outsourcing models Practical familiarity with ISO/IEC 27001 and supplierrelated controls Experience working with risk assessments, control frameworks, and remediation tracking Strong analytical and riskbased thinking Ability to translate regulatory requirements into actionable controls Confident communication with technical, legal, and business stakeholders Structured, detailoriented, and auditready mindset Pragmatic approach to balancing security, compliance, and business needs Might haves: Experience with DORA and/or NIS2 implementation or readiness programs Exposure to digitalinfrastructureservices, regulated environments, or critical infrastructure Certifications such as: ISO/IEC 27001 Lead Implementer / Auditor CISM, CRISC, CISSP (or equivalent)
More at Colt Technology Services
Related open roles
Technical Lead, Global Customer Assurance (IP Data)
Bangalore · Delhi NCR · Hybrid
Technical Lead, IP(BGP & MPLS)
Remote · Delhi NCR
Technical Consultant- SF Compensation Module
Bangalore · Delhi NCR · Hybrid
IT Infrastructure Architect - M365, GCP, Azure
Bangalore · Delhi NCR · Hybrid
ICT Risk Management Specialist (Information and Communication)
Bangalore · Delhi NCR · Hybrid
Senior IT Infrastructure Engineer (Network)
Bangalore · Delhi NCR · Hybrid