Cybersecurity Manager
- Hiring from
- India
- Work type
- Hybrid
- Posted
- Oct 1, 2026
Thank you for considering a career at Ensemble Health Partners India!
Ensemble Health Partners - The single solution for a frictionless revenue cycle with the purpose of redefining the possible in healthcare by empowering people to be the difference. Our India Office is an extension of Ensemble’s team and culture designed to augment and enhance our talent and skill base in Revenue Cycle Management in addition to our long-standing presence in technology. Leveraging our platform of services, technology, business intelligence and analytics, our teams are creating and maintaining innovative products and systems to help our revenue cycle operators achieve the most efficient, ideal outcomes for our clients. Our teams are certified in revenue cycle best practices and are supporting end-to-end RCM operations. We are at the forefront of innovation using cutting-edge technology to drive meaningful impact in the Revenue Cycle Management landscape. As a leading player in the industry, we offer an environment that fosters growth, creativity, and collaboration, where your expertise will be valued, and your contributions will make a difference.
The Opportunity:
Job Title: Manager II App Sec, DG and Vendor Risk
Experience: 10- 14 Years
Location: Hyderabad (Hybrid)
Position Summary:
The Cybersecurity Manager – Third-Party Risk Management (TPRM) is responsible for the operational leadership, effectiveness, and continuous maturation of the organization's Third-Party Risk Management program. Working closely with the Director of TPRM, this role leads a team responsible for vendor risk assessments, contract security reviews, continuous monitoring, remediation governance, and risk reporting activities.
The Manager is accountable for team performance, assessment quality, risk-based decision making, stakeholder engagement, executive reporting, and successful execution of strategic initiatives. This role serves as a key partner to business, technology, legal, compliance, privacy, and procurement stakeholders to ensure vendor risks are identified, evaluated, and managed consistently across the organization.
The ideal candidate is an experienced people leader who thrives in a fast-paced environment, can effectively influence cross-functional stakeholders, and is passionate about building scalable, sustainable cybersecurity and risk management capabilities.
Roles & Responsibilities
- Team Leadership & Development
- Provide day-to-day leadership, guidance, and oversight for TPRM team members
- Coach, mentor, and develop team members through performance feedback, career development planning, training opportunities, and formal performance evaluations.
- Manage team capacity, workload prioritization, resource allocation, and operational challenges to ensure timely delivery of assessments, contract reviews, strategic initiatives, and departmental objectives.
- Accountable for team performance, service delivery metrics, quality standards, and achievement of operational goals.
- Lead recruiting, interviewing, onboarding, and performance management activities.
- Identify staffing, skillset, and resource needs to support current operations and future program growth.
- Foster a culture of accountability, collaboration, innovation, and continuous improvement.
- Third-Party Risk Management Operations
- Provide operational oversight and quality assurance for third-party risk assessments, contract security reviews, continuous monitoring activities, and risk evaluations, ensuring consistent application of established methodologies and quality standards.
- Own the operational health of the enterprise third-party portfolio by ensuring assessment service levels, continuous monitoring, remediation tracking, and executive visibility objectives are achieved.
- Serve as the primary escalation point for complex vendor risk decisions, including risk acceptances, exceptions, compensating controls, remediation plans, and vendor approval recommendations.
- Provide oversight for contract security reviews and ensure risk-based recommendations for vendor approvals, exceptions, and escalations.
- Review and approve high-risk assessment findings, risk ratings, remediation recommendations, and exception requests to ensure consistency with enterprise risk standards.
- Ensure vendor risk decisions and recommendations are documented, defensible, and aligned with enterprise risk tolerance.
- Collaborate with business stakeholders on critical vendor engagements and initiatives.
- Program Development & Governance
- Lead continuous maturation of the Third-Party Risk Management program through improvements to governance processes, operating models, methodologies, documentation standards, and automation capabilities.
- Develop, maintain, and improve cybersecurity policies, standards, procedures, and governance frameworks.
- Identify and implement automation opportunities to improve operational efficiency and program effectiveness.
- Serve as the primary point of contact for internal and external audit and regulatory requests related to TPRM controls and processes; ensure supporting evidence, documentation, and remediation status are maintained in an audit-ready state.
- Artificial Intelligence (AI) Governance
- Partner with enterprise stakeholders to incorporate AI-related cybersecurity, privacy, legal, compliance, and operational risk considerations into third-party risk management processes.
- Monitor emerging AI governance expectations and recommend enhancements to assessment methodologies, controls, and governance practices as appropriate.
- Define and maintain assessment criteria for AI-enabled third parties in partnership with Legal, Privacy, and Compliance.
- Strategic Project Leadership
- Lead strategic initiatives that improve Third-Party Risk Management capabilities, operational efficiency, program maturity, and risk visibility.
- Develop and execute program roadmaps, establish priorities, coordinate cross-functional stakeholders, remove delivery obstacles, and ensure successful execution of key initiatives.
- Lead implementation and optimization of supporting technologies, automation solutions, and reporting capabilities.
- Executive & Cross-Functional Partnership
- Serve as a trusted advisor to business leaders by providing practical guidance that enables informed business decisions while protecting the organization.
- Escalate significant vendor risks and emerging program issues to the Director of TPRM while recommending practical courses of action.
- Build trusted relationships with stakeholders across Cybersecurity, Legal, Procurement, Privacy, Compliance, Internal Audit, and Technology teams.
- Own end-to-end executive reporting for the TPRM program (dashboards, KPIs/KRIs, portfolio risk posture) and translate technical risk into business-relevant insights for leadership.
- Establish operational metrics that demonstrate program effectiveness, efficiency, and risk reduction.
- Present findings and strategic recommendations to leadership and the Director of TPRM, driving informed decision-making.
- Translate technical cybersecurity risks into business-focused insights and actionable recommendations.
Required Skills
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field, or equivalent combination of education and experience.
- Minimum 8 years of cybersecurity, risk management, governance, compliance, or third-party risk management experience.
- Minimum 2-3 years of direct people leadership experience.
- Experience leading enterprise Third-Party Risk Management programs or significant cybersecurity governance initiatives.
- Experience developing executive-level reporting, performance metrics, and strategic communications.
- Demonstrated experience leading teams responsible for complex vendor risk assessments and cybersecurity evaluations.
- Strong understanding of third-party risk management practices, cybersecurity controls, and risk assessment methodologies.
- Experience developing policies, standards, and governance processes within cybersecurity or risk management functions.
- Strong project management, organizational, and analytical skills.
- Excellent written, verbal, and presentation skills with the ability to communicate effectively to both technical and executive audiences.
- Ability to balance strategic planning with hands-on execution in a dynamic environment.
Preferred Certifications - One or more of the following certifications is preferred:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- CCSP (Certified Cloud Security Professional)
- CCSK (Certificate of Cloud Security Knowledge)
Why Choose Ensemble India?
People First, Last + Always
We believe in putting people at the heart of everything. Our culture is rooted in collaboration, growth and innovation—where your contributions are valued, your voice is heard and your potential is nurtured.
A Place to Thrive
Whether you're just starting out or looking to grow your career, Ensemble India is a place where you can do your best work and be your best self. We offer structured career paths, paid professional certifications, tuition reimbursement and mentorship opportunities to help you advance.
Comprehensive Total Rewards
We support the physical, emotional and financial well-being of you and your family. Our Total Rewards package include:
• Healthcare coverage for associates and their immediate families including parents
• Paid time off plans
• Retirement benefits
• Recognition and wellness programs
• Market competitive pay rates
Inclusive Culture
Our organization is deeply committed to fostering a positive environment and culture where we celebrate and reward merit and contribution and where every associate feels valued, included, and empowered to succeed.
Purpose-Driven Impact
We proudly partner with local communities through philanthropic initiatives—from school supply drives to health awareness campaigns—because giving back is part of who we are.
Ensemble Health Partners is an equal employment opportunity employer. It is our policy not to discriminate against any applicant or employee based on race, color, sex, sexual orientation, gender, gender identity, religion, national origin, age, disability, military or veteran status, genetic information or any other basis protected by applicable federal, state, or local laws. Ensemble Health Partners also prohibits harassment of applicants or employees based on any of these protected categories.
About Us
Ensemble Health Partners is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country.
Our India Office is an extension of Ensemble’s team and culture designed to augment and enhance our talent and skill base in Revenue Cycle Management in addition to our long-standing presence in technology. Leveraging our platform of services, technology, business intelligence and analytics, our teams are creating and maintaining innovative products and systems to help our revenue cycle operators achieve the most efficient, ideal outcomes for our clients.
Our teams are certified in revenue cycle best practices and are supporting end-to-end RCM operations. We are at the forefront of innovation using cutting-edge technology to drive meaningful impact in the Revenue Cycle Management landscape. As a leading player in the industry, we offer an environment that fosters growth, creativity, and collaboration, where your expertise will be valued, and your contributions will make a difference.