FinThrive

Associate Cybersecurity Risk Analyst

FinThrive Gurugram, Haryana, India

Hospitals and Health Care · 1,001-5,000 employees

Yesterday
security Junior (0-2 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Associate Cybersecurity Risk Analyst will manage third-party security risk assessments and respond to customer security inquiries. They will collaborate cross-functionally to ensure security compliance and maintain standardized documentation for security reviews.

What they look for

Third party security risk management Vendor security assessments SOC 2 ISO 27001 HITRUST Customer security questionnaires Risk management Information security Compliance SaaS architecture Data privacy Communication skills Microsoft Office Vanta Whistic

Requirements

Candidates should have 1-3 years of experience in information security, risk management, or due diligence response. A bachelor's degree in IT, Information Security, or Business Administration is preferred, along with knowledge of security frameworks like SOC 2, HIPAA, and ISO 27001.

Benefits

Professional development opportunities Term life insurance Accidental insurance Medical insurance Meal arrangements Transport arrangements

Full description

Overview We are seeking a detail-oriented and collaborative Associate Cybersecurity Risk Analyst to join our growing security team. In this role, you will jointly push forward FinThrive’s Third Party Security Risk Management (TPRM) program and manage responses to customer security inquiries. You will work cross-functionally with IT, Engineering, Product, Sales, Procurement, and Legal to deliver timely, accurate, and defensible diligence on both sides of the security review. Responsibilities

  • Third Party Security Risk Management

◦ Execute and mature the day-to-day TPRM program, including risk-based vendor tiering aligned to data sensitivity, criticality, and regulatory obligations. ◦ Perform vendor security assessments using questionnaires and evidence (SIG, CAIQ, custom) and review assurance artifacts such as SOC 2 Type II, ISO 27001, HITRUST, PCI, and pen test results. ◦ Document findings, drive remediation to closure, and manage time-bounded risk acceptances and exceptions. ◦ Support continuous monitoring (security ratings, attestation refresh) and secure vendor offboarding. ◦ Partner with Legal and Procurement to embed security requirements in contracts (security addendums, DPAs, breach notification, right to audit).

  • Customer Security Inquiries

◦ Manage and respond to customer security questionnaires, RFPs, and due diligence requests. ◦ Maintain a repository of standardized responses and supporting documentation to enable cross-functional team independence. ◦ Translate complex security concepts into customer-friendly language and represent FinThrive’s security posture to prospects and customers.

  • Cross-Functional Collaboration & Tooling

◦ Work closely with IT, Engineering, Product, and Sales to ensure timely, accurate completion of both vendor and customer reviews. ◦ Implement and manage tools (e.g., Whistic, Vanta, security ratings platforms) to streamline and automate inquiry and assessment workflows. ◦ Produce metrics and dashboards covering vendor risk posture, remediation aging, inquiry volume, and SLA performance.

  • Product, Infrastructure & Compliance Knowledge

◦ Maintain a strong understanding of FinThrive’s products, SaaS architecture, data flows, and security controls. ◦ Support FinThrive’s Audit and Compliance program by aligning activities to HITRUST, HIPAA, SOC 2, NIST, and ISO 27001 requirements. Qualifications

  • 1-3 years of relevant experience in information security, third party risk management,

GRC, or due diligence response.

  • Experience responding to customer security questionnaires and assessing vendor

security posture against frameworks (SOC 2, HIPAA, ISO 27001).

  • Working knowledge of security control domains: IAM, vulnerability management,

encryption, logging/monitoring, incident response, and data handling.

  • Familiarity with IT infrastructure (servers, firewalls, load balancers, databases), SaaS

architecture, and web applications.

  • Strong written and verbal communication skills, with the ability to explain technical

concepts to non-technical audiences.

  • Customer-centric mindset with experience collaborating with Sales teams and

customers.

  • Proficiency with Microsoft Office (Word, Excel, PowerPoint, Visio).
  • Bachelor’s degree (IT, Information Security, or Business Administration preferred).

Preferred Skills

  • Security+ or similar certification.
  • Familiarity with HITRUST, NIST, PCI DSS, and GDPR/CCPA.
  • Experience with Trust Center, questionnaire management, and continuous monitoring

platforms (SafeBase, Whistic, Vanta).

  • Familiarity with cloud provider assurance models (AWS/Azure/GCP shared

responsibility) and SaaS risk patterns.

About FinThrive FinThrive is advancing the healthcare economy. For the most recent information on FinThrive’s vision for healthcare revenue management visit finthrive.com/why-finthrive

Award-winning Culture of Customer-centricity and Reliability At FinThrive we’re proud of our agile and committed culture, which makes FinThrive an exceptional place to work. Explore our latest workplace recognitions at https://finthrive.com/careers#culture

Our Perks and Benefits FinThrive is committed to continually enhancing the colleague experience by actively seeking new perks and benefits.

· Professional development opportunities

· Term life, Accidental & Medical Insurance

· Meal and Transport arrangements

FinThrive’s Core Values and Expectations

· Demonstrate integrity and ethics in day-to-day tasks and decision-making, adhere to FinThrive’s core values of being Customer-Centric, Agile, Reliable, and Engaged, operate effectively in the FinThrive environment and the environment of the workgroup, maintain a focus on self-development and seek out continuous feedback and learning opportunities

· Support FinThrive’s Compliance Program by adhering to policies and procedures about HIPAA, GLBA, FCRA, and other laws applicable to FinThrive’s business practices; this includes becoming familiar with FinThrive’s Code of Ethics, attending training as required, notifying management or FinThrive’s Helpline when there is a compliance concern or incident, HIPAA-compliant handling of patient information, and demonstrable awareness of confidentiality obligations.

FinThrive is an Equal Opportunity Employer and ensures its employment decisions comply with principles embodied in Title VII, the Age Discrimination in Employment Act, the Rehabilitation Act of 1973, the Vietnam Veterans Readjustment Assistance Act of 1974, Executive Order 11246, Revised Order Number 4, and applicable state regulations.

© 2024 FinThrive. All rights reserved. The FinThrive name, products, associated trademarks, and logos are owned by FinThrive or related entities. RV092724TJO

Similar roles