PVH Senior Analyst, Vendor Risk & Cybersecurity Policy Management

Employment
Full-Time
Seniority
Senior
Posted
Sep 23, 2026

PVH is hiring a Senior Analyst for Vendor Risk & Cybersecurity Policy Management in India to manage third-party cyber risk and enterprise security policy.

Role & Responsibilities

  • Conduct cybersecurity risk assessments for prospective and existing third-party vendors, reviewing SOC reports, ISO certifications, penetration test summaries, and disaster recovery documentation
  • Evaluate vendor security posture, identify potential risks, document findings, and provide risk ratings with remediation recommendations
  • Partner with Procurement, Legal, Privacy, Compliance, and business stakeholders throughout vendor onboarding and renewal processes
  • Track remediation activities and monitor outstanding vendor risks through closure; support periodic reassessments of critical suppliers
  • Maintain third-party risk metrics and dashboards for management reporting
  • Maintain the enterprise cybersecurity policy, standards, and supporting guideline library; coordinate scheduled reviews and updates with policy owners
  • Ensure policies align with NIST CSF, ISO 27001, CIS Controls, PCI-DSS, SOX, GDPR, and applicable regulatory and privacy requirements
  • Track policy exceptions and support the risk acceptance process; manage policy publication, version control, approvals, and communications
  • Prepare dashboards and reporting on vendor assessments, remediation actions, policy compliance, exceptions, and third-party risk trends
  • Support risk committees and governance meetings through preparation of reports and presentations; maintain audit and regulatory documentation
  • Identify opportunities to improve vendor assessment and policy management processes through automation and workflow optimization
  • Stay informed of emerging cybersecurity threats, regulatory changes, and industry best practices

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or related discipline (or equivalent experience)
  • 2–5 years of experience in cybersecurity, IT risk, governance, compliance, or vendor risk management
  • Understanding of third-party risk management, cybersecurity fundamentals, information security governance, and risk assessment methodologies
  • Familiarity with NIST CSF, ISO 27001, and CIS Controls
  • Experience reviewing SOC reports, ISO certifications, and security questionnaires
  • Strong analytical, documentation, communication, and organizational skills
  • Risk Analysis, Critical Thinking, Written Communication, Stakeholder Management, Attention to Detail, Problem Solving, Collaboration, Business Acumen, Process Improvement, and Continuous Learning

Skills

Microsoft Excel Microsoft PowerPoint Microsoft Word Power BI ProcessUnity AuditBoard ServiceNow GRC platforms SOC 1/SOC 2 analysis ISO 27001 certification review Risk assessment methodologies AWS security concepts Azure security concepts GCP security concepts Documentation management Dashboard and reporting tools NIST CSF CIS Controls GDPR CCPA PCI-DSS SOX

Experience

2–5 years of professional experience in cybersecurity, IT risk, governance, compliance, or vendor risk management. Demonstrated experience reviewing SOC reports, ISO certifications, security questionnaires, and conducting third-party risk assessments. Preferred experience with GRC platforms (ProcessUnity, AuditBoard, ServiceNow), maintaining information security policies and standards, and supporting SOX, PCI DSS, or ISO audits.

Education

Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or related discipline, or equivalent professional experience demonstrating mastery of core cybersecurity and risk management concepts.

Workplace

The role is situated in India, India.

About Cerulean

Cerulean is the definitive career portal for the global luxury industry. We match exceptional professionals with exclusive opportunities at the world's most prestigious brands. From haute couture and fine watchmaking to prestige beauty, hospitality, and boutique retail, Cerulean centralises luxury employment to help you find the career for which you were destined.

Frequently Asked Questions

A.

The luxury industry is characterised by a diverse and nuanced nomenclature. Esteemed houses frequently employ proprietary terminology, and even within a single organisation like PVH, titles may vary across global markets to reflect local conventions. To ensure absolute clarity, Cerulean assigns a standardised, industry-coherent canonical title to every listing. However, it is worth noting that this role is functionally synonymous with «Cybersecurity Risk Analyst», «Vendor Risk Manager», «Information Security Policy Analyst», «Third-Party Risk Specialist», and other variations. Our sophisticated search architecture anticipates these variations, ensuring that inquiries using related terms will seamlessly yield the exact roles you desire.

PVH

PVH Senior Analyst, Vendor Risk & Cybersecurity Policy Management

India, India

Continue to the application.

Country and Language