Associate - Security Governance, Risk & Compliance

Alvarez & Marsal

Associate, Security Governance, Risk & Compliance


Location: Gurgaon, Bengaluru, Mumbai

Experience: 3-5 years of relelavant exp inclusing dedicated third-party risk management experience


About the Company

Alvarez & Marsal (A&M) is a global consulting firm with more than 10,000 entrepreneurial, action- and results-oriented professionals across over 40 countries. A&M takes a hands-on approach to solving client problems and helping organizations reach their potential. Its culture values independent thinking, collaboration, and measurable impact, guided by Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity. Established in India in 2023, A&M Global Capability Center Private Limited partners with leadership across business units and geographies to enable efficient service delivery, specialized talent, competitive pricing, faster delivery, automation, and digital and analytics capabilities. The GCC supports end-to-end case delivery and thought leadership rather than traditional back-office work. It serves the Americas, EMEA, and APAC across industries including Consumer and Retail, Healthcare, Software and Technology, Automotive and Industrials, Hospitality and Leisure, Energy and Natural Resources, and Financial Services. The rapidly growing center already has more than 500 team members.


About the Role

The Security GRC Associate will own execution and improvement of the Information Security third-party risk management program. Through GRC platforms, assessment workflows, risk registers, reporting routines, and documented controls, the role will identify, evaluate, monitor, and help remediate vendor risks. The associate will complete client security questionnaires, review information security contract terms, and coordinate with Privacy, Legal, IT, procurement, and business stakeholders to produce accurate, timely responses. Success requires dedicated third-party risk management experience, including assessing at least 100 vendors annually, managing remediation within defined SLAs, and translating technical security requirements into practical business language. The role will strengthen governance visibility, support regulatory and policy compliance, and improve the firm’s ability to make risk-based decisions across vendor and client engagements.


Key Responsibilities

  • Own vendor risk identification and assessment against A&M’s risk appetite, completing assessments for at least 100 vendors annually through approved GRC platforms and documented workflows.
  • Track risk treatment, remediation commitments, security performance alerts, and overdue actions, converting current evidence into accurate monthly posture reviews and management reporting.
  • Manage client security questionnaires within defined SLAs, coordinating with Privacy, Legal, IT, and business stakeholders to deliver complete, consistent, and evidence-based responses.
  • Maintain and improve security assessment frameworks, questionnaires, response libraries, and supporting knowledge repositories so recurring reviews become faster, more consistent, and easier to govern.
  • Evaluate information security clauses in client and vendor contracts, identifying obligations that could create exposure and aligning recommendations with security policies and compliance requirements.
  • Communicate control gaps, risk ratings, and remediation strategies to technical and non-technical stakeholders, enabling proportionate decisions based on business context and risk appetite.
  • Execute recurring governance activities, including metrics gathering, internal assessments, reporting, and process improvements using automation or Artificial Intelligence to increase efficiency and control visibility.


Essential Skills & Technologies

  • Third-party risk management experience with vendor security assessments, audits, remediation tracking, GRC platforms, and annual throughput of at least 100 vendor assessments.
  • Working knowledge of security controls, regulatory requirements, ISO 27001, NIST, information security questionnaires, and security terms commonly included in legal contracts.
  • Strong analytical, written, verbal, and stakeholder-management skills, with the ability to translate technical risk into concise, business-accessible decisions and actions.


Additional Plus

  • An industry-recognized certification such as CRISC, CTPRP, CISSP, or CISM will strengthen your ability to evaluate control maturity and advise stakeholders.
  • Experience improving third-party risk processes through automation, Artificial Intelligence, workflow redesign, reporting enhancements, or structured knowledge management will be valuable.
  • Exposure to global consulting, professional services, or multi-region regulatory and client environments will help you navigate varied stakeholders, obligations, and delivery expectations.


What You'll Bring

You will bring 4–8 years of total relevant experience, including 3–5 years dedicated to third-party risk management, governance, risk, compliance, or information security. Your background should demonstrate ownership of vendor security assessments and audits, with experience managing risk reviews for at least 100 vendors in a year. You will be comfortable using GRC and third-party risk management platforms to document findings, assign treatments, monitor remediation, and produce management reporting. You can complete client security questionnaires within agreed SLAs, maintain reliable evidence and response libraries, and collaborate with Privacy, Legal, IT, procurement, and business teams. You will understand security frameworks such as ISO 27001 and NIST, relevant regulatory expectations, security controls, and information security contract clauses. A bachelor’s degree in Information Security, Risk Management, Business, or a related field is required. CRISC, CTPRP, CISSP, or CISM certification is advantageous. You are analytical, detail-oriented, organized, and able to prioritize multiple deadlines without losing accuracy. Most importantly, you communicate risk clearly, apply sound judgment, and connect control decisions to business impact.


Why Join Us

  • Join a rapidly growing India capability center that contributes to end-to-end global case delivery and thought leadership rather than operating as a traditional back-office function.
  • Build international exposure by supporting stakeholders and clients across the Americas, EMEA, and APAC, with opportunities to solve varied third-party security and governance challenges.
  • Grow in an entrepreneurial, meritocratic environment that values independent thinking, measurable impact, continuous learning, and inclusive collaboration across disciplines and geographies.


What We Offer

  • Structured performance development, professional training, and on-the-job learning designed to build deeper expertise in security governance, third-party risk, compliance, and consulting delivery.
  • Career growth opportunities within a global consulting firm and a rapidly expanding India capability center, supported by experienced leaders and cross-functional collaboration.
  • A workplace that prioritizes employee well-being and provides benefits and resources supporting professional development and personal needs.
  • An inclusive culture guided by Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity, with meaningful work and strong team engagement.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.