Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic
Meghna Rajpure

Meghna Rajpure

Third Party Risk Management
Mumbai,MH

Summary

Dynamic Third Party Risk Management and Information Security Audit Professional with over four years of experience conducting comprehensive vendor risk assessments across banking, financial services, and various industries. Proven ability to manage third-party risk evaluations, vendor onboarding, and due diligence processes while effectively assessing information security controls and identifying potential risks. Expertise in coordinating discussions among vendors and stakeholders, tracking remediation activities, and preparing insightful management presentations for stakeholder reviews. Recognized for mentoring junior team members and contributing to TPRM governance, with a strong focus on implementing security controls that safeguard information assets and ensure compliance with organizational policies.

Overview

4
4
Certifications
6
6
years of professional experience

Work History

Assistant Manager

KPMG, LLP, Financial Services Assurance
05.2026 - Current
  • Independently manage third-party risk assessments for vendors across banking, financial services, and non-banking industries, supporting the evaluation of vendor risk and information security controls.
  • Manage vendor onboarding and due diligence activities in line with applicable third-party risk management processes and requirements.
  • Review vendor assessment questionnaires (VAQs) and evaluate vendor responses against relevant information security and risk management controls.
  • Review and validate supporting evidence submitted by vendors to assess the implementation and effectiveness of applicable security controls, based on assessment requirements.
  • Conduct information security control assessments across access control, data protection and privacy, vulnerability management, incident management, encryption and key management, network security, asset management, change management, logging, and monitoring, among others.
  • Identify control gaps and risk-related observations, and coordinate with vendors and internal stakeholders to obtain clarification and supporting evidence.
  • Led vendor meetings and assessment discussions to communicate requirements, review evidence, resolve open items, and facilitate assessment progress.
  • Track remediation activities and outstanding issues, handle escalations, and coordinate follow-ups with relevant stakeholders.
  • Review vendor policies, procedures, and assessment updates for stakeholder reviews, covering assessment progress, open findings, and remediation-related information.
  • Prepare management decks and assessments updates for stakeholder reviews, covering region-wise assessment progress, open findings, information security MSA closures, and remediation-related information.
  • Mentor and train 3-5 junior team members on TPRM assessment processes, evidence review, and assessment documentation.
  • Contribute to TPRM reporting and governance activities, including assessment tracking, risk updates, and remediation monitoring.

Information Security Consulant

KPMG, LLP, Financial Services Assurance
10.2024 - 04.2026
  • Supported third-party risk assessments for vendors across various industries, evaluating information security controls, and assessing vendor risk.
  • Participated in vendor kick-off meetings to communicate assessment scope, timelines, evidence requirements, and assessment procedures.
  • Supported information security control walkthroughs with vendors to understand control implementation and assess responses.
  • Review and assess the information security annexure to evaluate vendor security requirements, identify potential control gaps, and support third-party risk assessments.
  • Track identified risks, remediation actions, and outstanding issues, supporting timely follow-up and closure of assessment findings.
  • Support the assessment of control applicability, identification of gaps, and documentation of risk-related observations.
  • Prepare comprehensive third-party risk management reports, documenting assessment findings, control gaps, and risk observations.

Training Officer

Teleperformance India
11.2023 - 09.2024
  • Hands-on experience in multiple areas of IT audits, control testing, internal audit, identifying control gaps and vulnerabilities, providing recommendations for remediations, and preparing comprehensive IT Audit Reports along with the team.
  • Conduct third-party security risk assessments for all the new vendors and annually for existing vendor relationships.
  • Perform pre-contract due diligence, such as scheduling kick-off calls with the vendor’s contact or security team for the risk assessment process, walkthroughs, and validation of the vendor’s technical controls, supporting onboarding and post-contract activities, ongoing monitoring activities, and offboarding operations.
  • Led the vulnerability management program, assessing final risk using an established matrix and timelines, and preparing detailed reports tailored to client specifications with AWS Inspector and Qualys.
  • Facilitated discussions with business units and vendors to address findings, and the remediation process.
  • Perform control testing for external clients, i.e. IT General Controls under Sarbanes-Oxley Section 404 (SOX compliance), ISO 27001:2022.

Trust and Safety Associate

Accenture India Pvt. Ltd.
01.2021 - 11.2023
  • Conduct comprehensive IT audits, focusing on tests of design and tests of operating effectiveness of internal controls, including performing walkthroughs, to complete the control testing plan.
  • Ensure that the third-party relationship adheres to the company's policies, and is compliant with regulatory guidelines and industry best practices.
  • Experience in conducting information technology assessments and risk management in accordance with established standards such as ISO 27001, etc.
  • Conducted information security and privacy awareness and training programs for employees across the organization using KnowBe4, enhancing the security culture.
  • Identified high and medium vulnerabilities from the assessment, and relayed them to the supplier/vendor for remediation, based on the agreed recommendations.
  • Managing third-party security teams and tier vendors based on data classification, data elements, and risk rating.
  • Reviewed existing agreements and contractual arrangements to identify and remediate challenges, supporting vendor due diligence processes for third-party risk management.
  • Conduct information security and privacy awareness and training programs for the employees across the organization using KnowBe4.

Education

Bachelor's of Management Studies -

St. Andrew's College of Arts, Commerce and Science
Mumbai
05-2020

Class XII - undefined

Narsee Monjee College
05-2017

Class X - undefined

St. Rock's High School
03-2015

Skills

ISO 27001

Third Party Risk Management

Vendor Risk Management

SOX 404

Internal Audit

Risk Identification and Management

Control testing

Evidence validation

External Audits

Vulnerability Management

Lead Point of Contact

Stakeholder management

Walkthroughs

Kick-off Meetings

Team Mentoring

TPRM Governance

OneTrust TPRM

Certification

Third Party Risk Management Expert by OneTrust,

Timeline

Assistant Manager

KPMG, LLP, Financial Services Assurance
05.2026 - Current

Information Security Consulant

KPMG, LLP, Financial Services Assurance
10.2024 - 04.2026

Training Officer

Teleperformance India
11.2023 - 09.2024

Trust and Safety Associate

Accenture India Pvt. Ltd.
01.2021 - 11.2023

Class X - undefined

St. Rock's High School

Class XII - undefined

Narsee Monjee College

Bachelor's of Management Studies -

St. Andrew's College of Arts, Commerce and Science
Meghna RajpureThird Party Risk Management