O

Principal Engineer - IT Risk Management

Oliver Wyman · Pune, Maharashtra, India

~₹50L (est.)10–18 yrs experiencefull_timePosted 1w ago
Apply now →

Job description

We are seeking a talented individual to join our GIS at Marsh. This role will be based in Pune. This is a hybrid role that has a requirement of working at least three days a week in the office. **Principal Engineer IT Risk Management** The Global Information Security (GIS) team at Marsh is seeking a motivated and detail-oriented **Analyst** to support technical risk management activities across cyber, IT, third party, and AI-related risk domains. In this role, you will help assess and track risk, maintain risk documentation, support remediation efforts, and contribute to reporting and governance activities. You will work closely with more senior team members and partner with engineering, security, infrastructure, procurement, and business teams to help ensure risks are identified, recorded, and managed appropriately. **WHAT YOU CAN EXPECT:** - A fast-paced environment with a great culture and supportive leadership. - Opportunities to learn how technical risk is identified, assessed, and managed. - Meaningful work that supports the team's risk management and reporting activities. - Collaboration with experienced colleagues across technical and business teams. **WE WILL COUNT ON YOU TO:** - Support technical risk assessments across infrastructure, applications, cloud environments, endpoints, SaaS solutions, and supporting platforms. - Help identify control gaps and potential risk concerns by reviewing technical documentation, evidence, and system information. - Assist teams with risk management activities and provide feedback on necessary outstanding tasks. - Escalate complex issues or concerns to more senior team members for review and decision-making. - Assist in maintaining the risk register, ensuring risks are documented accurately and tracked through resolution. - Support the development and tracking of risk treatment plans and remediation actions. - Assist with third party technical assessments by reviewing vendor documentation, evidence, and control descriptions. - Help assess SaaS and other technology solutions for basic security, resilience, data handling, access management, logging, and recovery considerations. - Work with senior team members to document findings, track issues, and follow up on remediation progress. - Help prepare risk metrics, dashboards, and reporting materials for leadership and governance forums. - Assist with the improvement of risk workflows, evidence collection, and reporting processes. - Review technical documentation, architecture diagrams, and system summaries to help identify risk exposure. - Support issue management, remediation tracking, and risk acceptance documentation. - Contribute to the development of standards, templates, and guidance for risk management activities. - Assist with AI-related technical risk reviews and related governance activities as needed. - Communicate clearly with internal stakeholders and vendors to gather information and support assessments. **WHAT YOU NEED TO HAVE:** - 1-3 years of experience in technical risk, cybersecurity, IT risk, third party risk, audit, compliance, or related field. - Basic understanding of cybersecurity, IT risk, and third party risk management concepts. - Familiarity with risk registers, issue tracking, remediation plans, or reporting tools. - Ability to review technical documentation and identify potential gaps or concerns. - Strong attention to detail and analytical thinking. - Good written and verbal communication skills. - Ability to work collaboratively with technical and non-technical stakeholders. - Willingness to learn about security controls, cloud services, SaaS applications, and modern infrastructure environments. - Ability to manage multiple tasks and follow through on deadlines. - Comfort working in a large, complex, and cross-functional environment. **WHAT MAKES YOU STAND OUT** - Exposure to technical risk assessments, third party reviews, or vendor due diligence. - Familiarity with cloud, infrastructure, SaaS, or application environments. - Experience supporting remediation tracking, risk documentation, or reporting activities. - Interest in risk management, governance, and technology controls. - Strong organizational skills and a proactive attitude. - Eagerness to learn and grow in a technical risk or third party risk role. - Ability to work independently on routine tasks while knowing when to escalate. **WHY JOIN OUR TEAM** - We help you be your best through professional development opportunities, interesting work, and supportive leaders. - We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and make an impact for colleagues, clients, and communities. - Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to support your well-being. Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.