Senoir Manager - IT Risk Management
Oliver Wyman · Pune, Maharashtra, India
Oliver Wyman · Pune, Maharashtra, India
### Job Summary We are seeking a talented individual to join our GIS at Marsh. This role will be based in Pune. This is a hybrid role that has a requirement of working at least three days a week in the office. The Global Information Security (GIS) team at Marsh is seeking a highly skilled and collaborative IT Specialist to support technical risk assessments, SaaS risk reviews, and third party risk management activities. In this role, you will play a key part in evaluating technology and vendor risks, reviewing control environments, and partnering across security, infrastructure, procurement, and business teams to support sound risk decisions and effective remediation. This position is well suited for an experienced professional who can work independently, lead complex assessments, and contribute to the maturation of risk processes and practices. This is a hybrid role requiring three days per week in the office and two days per week remote. ### What you can expect - A fast-paced environment with great culture and leadership. - Passionate team members who are dedicated to business enablement. - Autonomy to deliver in your role, while getting strong support from management to collaborate across the organization. ### Responsibilities - Perform technical risk assessments across infrastructure, applications, cloud environments, SaaS solutions, and supporting platforms. - Review SaaS products and vendor environments for security, resilience, and control considerations. - Evaluate vendor-provided documentation, architecture, and control evidence to identify risk and inform decision-making. - Support third party risk management activities, including vendor reviews, issue tracking, remediation follow-up, and stakeholder communication. - Collaborate with engineering, security, infrastructure, procurement, and business teams to evaluate risk and define practical next steps. - Develop and maintain risk metrics, dashboards, and reporting for leadership visibility. - Contribute to the improvement and standardization of risk workflows, evidence collection, and assessment processes. - Participate in issue management, remediation tracking, and follow-up on technical findings. ### What you need to have - Experience in third party risk, IT risk, cybersecurity, audit, compliance, or a related field. - Basic understanding of cybersecurity, IT risk, and third party risk management concepts. - Strong analytical skills and attention to detail. - Ability to review documentation, compare it to requirements, and identify basic gaps or concerns. - Strong written and verbal communication skills. - Comfort working with spreadsheets, trackers, and reporting tools. - Ability to manage multiple tasks and follow through on deadlines. - Willingness to learn technical concepts related to infrastructure, cloud, applications, and security controls. - Experience working in a professional environment with cross-functional teams. - Ability to work independently on routine tasks while seeking guidance when needed. ### What makes you stand out - Exposure to third party risk assessments, vendor reviews, or security questionnaires. - Familiarity with technical risk concepts across infrastructure, cloud, applications, or endpoints. - Experience supporting issue management, remediation tracking, or control monitoring activities. - Strong organizational skills and ability to maintain accurate records and reporting. - Interest in process improvement, automation, or workflow efficiency. - A proactive, curious mindset and eagerness to build technical and risk management knowledge. - Ability to communicate clearly with both technical and non-technical stakeholders. Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.