About this role
Fluence (Nasdaq: FLNC) is a global market leader delivering intelligent energy storage and optimization software for renewables and storage. Our solutions and operational services are helping to create a more resilient grid and unlock the full potential of renewable portfolios. With gigawatts of successful implementations across nearly 50 markets, we are transforming the way we power our world for a more sustainable future. For more information, please visit fluenceenergy.com .
Job Description:
Third Party Security Risk Analyst
Location: (Fluence GIC - Bangalore, India)
Reporting to: (Director, Product Security)
Fluence (Nasdaq: FLNC) is a global market leader delivering intelligent energy storage and optimization software for renewables and storage. Our solutions and operational services are helping to create a more resilient grid and unlock the full potential of renewable portfolios. With gigawatts of successful implementations across nearly 50 markets, we are transforming the way we power our world for a more sustainable future. For more information, please visit fluenceenergy.com .
Role Overview
The Third-Party Security Risk Analyst will support the identification, assessment, monitoring, and mitigation of cybersecurity risks associated with third-party vendors and suppliers. This role conducts risk assessments, supports compliance with security requirements, and collaborates with Global Procurement, Legal, Internal Audit, and other stakeholders to strengthen Fluence's third-party security risk management program.
Key Responsibilities:
The successful candidate will strengthen Fluence's third-party security risk management program by assessing new and current vendors continuously to rigorous security assessment that address cyber-physical, supply chain, and advanced trust scenarios. This position requires strong expertise in vendor risk management and regulatory compliance frameworks relevant to globalized regions.
Core Operations:
- Conduct security risk assessments for direct, indirect, logistics, and other suppliers and vendors.
- Support the development, implementation, and continuous improvement of third-party security risk management policies, standards, procedures, and assessment methods.
- Monitor third-party compliance with contractual and organizational security requirements and track identified issues through remediation or documented risk treatment
Cross-Functional Collaboration:
- Collaborate with Global Procurement, Legal, Internal Audit, business owners, and other internal teams to address and mitigate identified third-party risks.
- Review security-related clauses in vendor contracts and provide risk-based input to support negotiations and contracting decisions.
- Prepare clear reports and dashboards summarizing third-party risk activities, findings, remediation status, and key risk indicators for management review.
Security Advocacy:
- Maintain accurate third-party assessment records, evidence, risk decisions, and remediation documentation.
- Support ongoing monitoring of higher-risk vendors and reassess third parties when material changes, incidents, or new risks are identified.
- Stay current on industry trends, emerging threats, and regulatory changes affecting third-party and supply chain cybersecurity risk.
- Identify opportunities to automate assessment workflows, evidence collection, risk tracking, reporting, and dashboarding.
Required Qualifications
- Bachelor's degree in Information Security, Cybersecurity, Risk Management, Information Technology, or a related field. Equivalent relevant experience will be considered.
- Minimum of 5 years of experience in cybersecurity risk management, supplier security, vendor risk, audit, compliance, or a related field, with experience supporting third-party risk assessments.
- Strong understanding of cybersecurity risk management principles, security controls, and common assessment practices.
- Knowledge of relevant frameworks and standards such as NIST, ISO/IEC 27001, and IEC 62443 is preferred.
- Ability to analyze security documentation, identify control gaps, document risk clearly, and recommend practical remediation actions.
- Excellent analytical, problem-solving, written communication, and interpersonal skills.
- Ability to work collaboratively with technical teams, procurement, legal, audit, business stakeholders, and external vendors.
Preferred Qualifications
- Experience with third-party risk management platforms such as UpGuard, ServiceNow, Aravo, or Archer is preferred.
- Relevant certifications such as CRISC, CISSP, CISM, or comparable risk and security certifications are preferred.
- Experience developing reports, dashboards, workflow automation, or data-driven risk metrics is preferred.
- Experience with vendor risk management and principles for embedded components in OT environments.
Key Competencies
- Perform third party risk management of vendors continuously.
- Maintain vendor security assessment questionnaires to remain current with global trend in the energy sector.
- Prioritize security remediation with vendors to improved trust transparency.
- Manage multiple vendor assessments with JIRA kan-ban boards to ensure accountability.
Our Culture
At Fluence, our culture is the foundation that drives our ambitious growth strategy and fuels our mission to transform the future of energy. Our core cultural pillars empower us to innovate, collaborate, and lead with purpose, ensuring we continue to deliver unparalleled value to our customers and the world.
Unleash Voices
We believe every voice matters. We encourage openness, active listening, and decisive action to create a culture where everyone has the opportunity to contribute to our success. We foster an environment where diverse perspectives are heard and valued, driving innovation and progress.
Customer Fluent
Our customers are at the heart of everything we do. We’re committed to delivering exceptional value that exceeds expectations by understanding our customers' needs and adapting swiftly to meet them. Our deep focus on customer satisfaction drives us to continuously improve and innovate.
Infinite Impact
We are committed to creating the impossible. We push boundaries to deliver sustainable, game-changing solutions that shape a brighter, more energy-efficient future for all. Our team is passionate about making a lasting impact that will resonate for generations to come.
All In
We are all in for growth. Our teams are relentlessly focused on identifying and seizing opportunities that propel us forward. We embrace an ownership mindset, pushing ourselves and each other to accelerate progress and create lasting success.
