Third Party Technology Assurance at Apex Group Ltd.
pune, maharashtra, India -
Full Time


Start Date

Immediate

Expiry Date

19 Jun, 26

Salary

0.0

Posted On

21 Mar, 26

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Third Party Risk Assessments, Due Diligence, Ongoing Monitoring, Vendor Risk Scoring, Incident Management, Contractual Control Reviews, Policy Development, Stakeholder Engagement, Audit Preparation, Market Intelligence, GRC, Outsourcing, NIST, ISO 27001, SOC 1, SOC 2

Industry

Financial Services

Description
The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers. Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion. That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience. Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities. For our business, for clients, and for you Job Description: Third Party Technology Assurance – Senior Associate. Location:- Pune, Viman Nagar. Position Overview A Third-Party Technology Assurance Analyst plays a critical role in safeguarding an organisation’s technology landscape by managing and assessing the risks associated with third-party vendors and service providers. The analyst proactively analyses, monitors, and assures the compliance, security, and operational effectiveness of external technology services upon which the organisation relies. This position is vital in a world where organizations increasingly depend on external partners for software, cloud infrastructure, and data processing, making assurance and oversight of third parties a top priority for operational resilience and regulatory compliance. Key Responsibilities Third Party Risk Assessments: Conduct comprehensive risk assessments of third-party technology vendors and service providers. Evaluate security postures, technical controls, and compliance with organizational and regulatory requirements before onboarding and throughout the partnership lifecycle. Due Diligence Activities: Lead and support due diligence efforts by gathering, reviewing, and analyzing documentation such as SOC1/SOC2 reports, ISO certifications, data protection agreements, GDPR and other compliance artefacts. Ongoing Monitoring: Continuously monitor third party technology services for changes in risk profile, compliance status, or incidents. Maintain updated records and risk ratings and ensure periodic re-assessment in line with organizational policies. Vendor Risk Scoring & Reporting: Develop and update risk scoring models for technology vendors. Produce regular management reports and dashboards highlighting risk trends, non-conformities, and remediation progress. Incident Management: Participate in the identification, escalation, and remediation of incidents involving third party technology services. Coordinate with internal stakeholders to ensure effective response and lessons learned. Contractual Control Reviews: Review and advise on contract terms with technology vendors, ensuring that security, confidentiality, and compliance clauses are embedded and enforceable. Policy & Framework Development: Contribute to the development, maintenance, and enhancement of third-party risk management policies, standards, and guidelines aligned with best practices (e.g., NIST, ISO 27001, SOC 1, SOC 2, DORA, GDPR, NCA). Stakeholder Engagement: Work closely with procurement, legal, information security, compliance, and business teams to build awareness and understanding of third-party risks and controls. Audit Preparation & Support: Assist in the preparation for internal and external audits related to third-party technology risk. Provide evidence, documentation, and subject matter expertise as required. Market Intelligence: Stay current with emerging risks, regulatory changes, and best practices in third-party technology risk and assurance. Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities. Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes. Need to meet delivery of all requirements from Group Chief Information Security Officer (CISO) Need to meet delivery of all requirements of Group or Cyber Strategy Support the wider CISO function with GRC and Outsourcing requirements, where needed Required Skills and Qualifications Education: Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, or related field. Professional certifications (e.g., CISA, CISM, CRISC, CISSP) are highly desirable. Experience: 6+ years of experience in technology risk management, third party security assessments, or audit/assurance roles, preferably within financial services, healthcare, or other regulated industries. Technical Knowledge: Understanding of IT infrastructure, cloud architecture, SaaS platforms, and data protection frameworks. Familiarity with common security controls and risk management methodologies. Regulatory Awareness: Solid knowledge of relevant regulations and standards (e.g., GDPR, HIPAA, SOX, PCI DSS, NIST, ISO 27001). Analytical & Problem Solving: Strong analytical skills to identify, assess, and mitigate complex technology risks. Ability to evaluate large amounts of information and make informed recommendations. Communication: Excellent verbal and written communication skills for preparing reports, presenting findings, and influencing stakeholders at all organizational levels. Organizational Skills: Demonstrated ability to manage multiple priorities, meet deadlines, and adapt in a fast-paced environment. Attention to Detail: High degree of accuracy and attention to detail in reviewing documentation and risk artefacts. Collaboration: Effective team player with a proactive approach to cross-functional projects and initiatives. Continuous Learning: Eagerness to stay abreast of technological advancements, threat landscapes, and evolving assurance techniques. Desirable Skills and Competencies Automation and Tooling: Experience with third-party risk management platforms, GRC (Governance, Risk, and Compliance) tools, and automation of risk assessment processes. Project Management: Familiarity with project management methodologies and the ability to drive assurance initiatives from inception to completion. Innovation: Ability to recommend and implement process improvements to increase the efficiency and effectiveness of third-party risk management activities. Negotiation: Confidence in negotiating with vendors to achieve favorable assurance and compliance terms. Presentation Skills: Experience delivering risk-related findings and assurance updates to senior management, boards, or external regulators. Reporting Line Typically reports to: Head of Technology Assurance Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners. About Apex Group We are dedicated to driving positive change in financial services while fuelling the growth and ambitions of asset managers, allocators, financial institutions, and family offices. Established in Bermuda in 2003, the Group has continually disrupted the asset serving industry through our investment in innovation and talent. Today, we set the pace in asset servicing and stand out for our unique single-source solution and unified cross asset-class platform which supports the entire value chain, harnesses leading innovative technology, and benefits from cross-jurisdictional expertise delivered by a long-standing management team and over 13,000 highly integrated professionals. We’re a people-powered business, and our people are full of ambition. Together, we’re inspired to lead the new era of data and tech enabled service. Bringing new products and services to market. Sharpening our client focus. Disrupting the market to exceed expectations. Innovating across a range of specialisms. With our focus on making a difference to our people, our planet and our society, you’ll experience more here than you would at most other companies. Prepare to accelerate. We’re a people-powered business with a vision to inspire a new era of service-led FinTech. We’re expanding globally and offering more to our clients. This means you get more opportunities to grow with us. So prepare to accelerate. We’ll make sure the time and effort you put in takes you further, faster. Positive change starts with you. We’re a people-powered business with a vision to inspire a new era of service-led FinTech. We’re expanding globally and offering more to our clients. This means you get more opportunities to grow with us. So prepare to accelerate. We’ll make sure the time and effort you put in takes you further, faster. The journey is yours to own. When you stretch yourself, you grow. We want you to explore ways of working that will see you thrive as part of something bigger. We’ll help you with a solid structure, challenging projects, vibrant networks, supportive colleagues and approachable leaders. All the things you need to own your unique journey. Find out more about us

How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities
The Senior Associate will conduct comprehensive risk assessments, due diligence, and continuous monitoring of third-party technology vendors to assure compliance, security, and operational effectiveness. Key duties include developing risk scoring models, reporting findings, managing incidents, and reviewing contractual controls related to external technology services.
Loading...