OSTTRA

Sr. Associate - TPRM

OSTTRA  •  Gurugram, IN (Hybrid)  •  16 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About the Role

The team:

Vendor Risk Management(VRM) is a critical sub-function within the Procure to Pay function within OSTTRA Finance department. The Vendor Risk Management team ensures thorough reviews of each vendor engaged globally, supporting the business in making risk-informed and data-driven decisions.

We collaborate closely with Legal, Risk & Compliance, Business Units (such as Technology) and Risk Domain Subject Matter Experts (SMEs), such as Cyber Risk, to conduct assessments and recertifications in compliance with regulatory requirements. When issues are identified, VRM team is responsible for ensuring risk mitigation and providing feedback to leadership before engaging with the vendor.

Responsibilities and impact:

The TPRM Specialist will support and guide the organization’s Third-Party/Vendor Risk Management program by assessing and monitoring vendor risks throughout the vendor lifecycle. Designed for a seasoned professional, this role involves a blend of hands-on operational execution (80%) and strategic process enhancement (20%). The role involves conducting complex vendor due diligence, reviewing risk and compliance documentation, identifying potential risks, maintaining vendor records, mentoring junior team members, and coordinating with internal teams and vendors to ensure timely completion of high-priority risk assessments. This role will functionally report to the TPRM Lead for OSTTRA.

Key Responsibilities

  • Vendor Risk Assessments & Lifecycle Monitoring: Lead and support complex vendor risk assessments during onboarding, periodic reviews, and ongoing monitoring.
  • Comprehensive Due Diligence & Risk Evaluation: Perform deep-dive vendor due diligence by reviewing questionnaires, policies, certifications, financial information, and supporting documentation, assessing risks across information security, cybersecurity, data privacy, business continuity, disaster recovery, regulatory and compliance, financial and operational, and subcontractor/fourth-party risk.
  • Evidence Review, Deficiency Management & Risk Rating: Review and challenge evidence (such as SOC 1/2 reports, ISO 27001 certificates, penetration testing reports, business continuity plans, and privacy documentation), identify gaps, exceptions, and control deficiencies, document findings, negotiate remediation directly with vendors, assign or validate risk ratings based on established methodologies, track remediation activities, and follow up on outstanding issues.
  • Records, Reporting & SLA Compliance: Maintain accurate vendor risk records, dashboards, assessment results, approvals, and supporting documentation; prepare risk summaries, metrics, and management reports; and ensure vendor assessments are completed within defined SLA/KPI timelines.
  • Stakeholder Coordination & Audit Support: Coordinate efficiently with Procurement, Information Security, Privacy, Legal, Compliance, Business Owners, and other stakeholders, and support audits and regulatory reviews by providing necessary vendor risk documentation and evidence.
  • Strategic Program Optimization & Compliance: Contribute to strategically improving and maturing vendor risk management processes, procedures, methodologies, and templates; act as an escalation point and work with MitraTech (Prevalent Tool) stakeholders; and ensure support for critical compliances like DORA.

What we’re looking for

Required Experience & Skills

  • Education & Experience: Bachelor’s degree in Finance, Business, Risk Management, Legal, Information Security, IT, or a related field, backed by 10+ years of hands-on experience in Vendor Risk Management, Third-Party Risk Management (TPRM), Operational Risk, Compliance, IT Risk, or a related function.
  • Core TPRM & Technical Knowledge: Deep understanding of TPRM principles, vendor lifecycle management, risk assessment, control evaluation concepts, and information security and privacy, supported by a strong ability to review, interpret, and challenge complex security/compliance documentation.
  • Skills & Proficiencies: Strong analytical, problem-solving, and written/verbal communication skills to manage senior stakeholder expectations, alongside strong attention to detail, the ability to manage multiple complex assessments simultaneously, and proficiency in Microsoft Excel, Word, PowerPoint, and Outlook.

Preferred Qualifications (Nice-to-Have)

  • Familiarity with frameworks such as NIST, ISO 27001, SOC 2, COBIT, PCI DSS, GDPR, or similar standards.
  • Experience working with TPRM/GRC platforms such as ServiceNow, Archer, RSA, OneTrust, LogicGate, or similar tools.
  • Certifications such as CRISC, CISA, Security+, ISO 27001, or relevant risk/compliance certifications are a plus.
  • Experience in financial services, banking, insurance, healthcare, technology, or other regulated industries is advantageous.

The location: Gurgaon,India

Our Benefits: Global vision, local impact

At OSTTRA, our benefits philosophy offers a market-competitive package that reflects our position as an industry leader. We want to ensure you feel valued, secure, and empowered wherever you are in the world.

Our approach is built on three core pillars:

  • Global foundations: We provide a baseline of excellence across all our offices, focusing on comprehensive Health & Wellness, Financial Security, and Work-Life Balance. No matter your location, you are part of a culture that prioritizes your holistic well-being.
  • Locally tailored: We benchmark in each market to ensure our packages are genuinely competitive where you live and work.
  • Flexibility and growth: We empower you to work in a way that suits your life. This includes a hybrid working model, generous leave policies, and a commitment to your continuous professional development.

The Trust employee ownership plan

Every employee at OSTTRA is an owner, and a member of The Trust, our employee ownership programme. Our distinct culture encourages colleagues to think and act like owners and raise the bar constantly. This plan reflects our belief that when we work together to build a stronger, more valuable organisation, then all colleagues should benefit from the value we create.

About OSTTRA

We build and operate the infrastructure that the world’s post-trade financial system runs on. Launched in 2021, we have unified more than 20 years of heritage and expertise from four industry leaders into a single, integrated business.

Today,we operate a trusted network that connects thousands of market participants to streamline end-to-end workflows, from trade capture through portfolio optimisation.We translate industry change into workable process, engineering an open, intelligent ecosystem that removes friction and reduces risk for the global markets.

Our distinct ownership culture is underpinned by four behaviours: boldness, curiosity, accountability, and collaboration. In 2025 we were acquired by KKR, one of the world’s most successful private equity firms, and are on a journey of growth and impact.

Joining our team now is a unique opportunity - you will help to shape the next generation of post-trade, transform shared infrastructure into shared benefit, and accelerate your own career. Learn more atwww.osttra.com.

Equal opportunity employer statement at OSTTRA

We are committed to fostering a connected and engaged workplace where all colleagues have access to opportunities based on their skills, experience, and contributions. Our hiring practices emphasise fairness, transparency, and merit, ensuring that we attract and retain the best talent. By valuing different perspectives and promoting a culture of respect and collaboration, we drive and operate the infrastructure that the world’s post-trade financial system runs on.

OSTTRA

About OSTTRA

OSTTRA provides critical post trade infrastructure to global financial markets. Launched in 2021 through the combination of four businesses that have been at the heart of Post Trade innovation for more than 20 years (MarkitServ, Traiana, TriOptima and Reset), the OSTTRA network connects thousands of market participants to process millions of trades each day, streamlining end to end workflows – from trade capture and confirmation, through portfolio optimisation, to clearing and settlement.

To contact an OSTTRA subject matter expert, please send an email request to info@osttra.com

Industry
Finance & Insurance
Company Size
1,001-5,000 employees
Headquarters
London, GB
Year Founded
2021
Social Media