Supplier Due Diligence Analyst (ESG) & Cyber Security | Pune | Full-time
Vanderlande is seeking a proactive and analytical Supplier Risk & Due Diligence Analyst (ESG & Cyber Security) to support the global Supplier Sustainability & Risk function within Procurement.
As part of Vanderlande’s global procurement organization, you will play a key role in assessing supplier risks and ensuring our supply base operates in line with sustainability, compliance, and cyber security expectations. You will contribute to a resilient, responsible, and future-proof supplier ecosystem by supporting supplier due diligence, ESG assessments, third-party cyber security reviews, and ongoing supplier risk monitoring.
Our global procurement organization enables projects and business functions by maximizing value and minimizing risks through the procurement of goods and services in a smart, cost-effective, sustainable, and secure way.
What you will do
As a Supplier Risk & Due Diligence Analyst, you will support supplier qualification, onboarding, monitoring, reassessment, and remediation activities across multiple risk dimensions. You will work closely with Procurement, Sustainability, Legal, Compliance, Information Security, business stakeholders, and suppliers to evaluate and manage supplier-related risks throughout the supplier lifecycle and support risk management activities embedded within Vanderlande's Source-to-Pay (S2P) processes.
A key part of the role will be supporting the adoption and operational use of supplier risk and cyber security monitoring tools, including BitSight or other approved risk intelligence platforms, to assess third-party cyber exposure, identify risk indicators, and support timely follow-up actions.
Responsibilities
- Support execution of supplier due diligence activities as part of supplier onboarding, qualification, periodic reassessment, and ongoing monitoring processes.
- Conduct supplier risk assessments across ESG, cyber security, information security, financial stability, compliance, geopolitical, operational, and business continuity risk dimensions.
- Review supplier information, responses, supporting documentation, certifications, policies, and evidence to validate due diligence outcomes and identify potential risk indicators and information gaps.
- Review supplier cyber security documentation, including security questionnaires, ISO 27001 certifications, NIS2, SOC reports, data privacy indicators, business continuity documentation, and third-party cyber risk ratings.
- Support the implementation and operational use of BitSight or similar approved cyber risk intelligence platforms, including supplier monitoring, cyber risk score analysis, follow-up of identified risk indicators, and reporting to relevant stakeholders.
- Monitor supplier risk intelligence sources and identify emerging risks requiring escalation, mitigation, reassessment, or stakeholder review.
- Analyze supplier risk data and prepare clear insights, dashboards, reports, and management updates for procurement and governance forums.
- Review supplier documentation and due diligence evidence against established responsible sourcing, sustainability, compliance, and governance requirements, highlighting potential concerns and coordinating follow-up with relevant stakeholders
- Coordinate remediation activities with suppliers and internal stakeholders, ensuring actions are tracked, documented, and followed up within agreed timelines.
- Maintain accurate supplier risk records, assessment outcomes, documentation, dashboards, and reporting within approved systems and tools.
- Collaborate with Procurement, Sustainability, Legal, Compliance, Information Security, IT, and business teams to ensure an integrated supplier risk management approach.
- Contribute to continuous improvement of supplier due diligence, ESG, risk, and cyber security assessment processes, templates, tools, and governance routines.
- Ensure all activities are executed in compliance with company policies, governance standards, confidentiality requirements, and regulatory expectations.
What you bring
To succeed in this role, you bring a strong combination of analytical thinking, operational discipline, stakeholder collaboration, and risk awareness. You are comfortable working in a dynamic global environment and can translate supplier risk data into clear, actionable insights.
You should bring:
- Bachelor’s degree in supply chain management, Business Administration, Sustainability, Risk Management, Information Security, Finance, or a related discipline.
- 5–8 years of experience in supplier risk management, due diligence, procurement, sustainability, compliance, cyber security, audit, or a related field.
- Good understanding of supplier lifecycle management, third-party risk management, supplier onboarding, and supplier reassessment processes.
- Knowledge of ESG frameworks, responsible sourcing practices, sustainability regulations, and supply chain due diligence expectations.
- Understanding of cyber security and information security concepts, including third-party cyber risk, information security controls, ISO 27001, NIS2, SOC reports, data privacy, GDPR, business continuity, and disaster recovery.
- Experience with supplier risk, due diligence, compliance, ESG, or cyber risk monitoring platforms. Experience with BitSight or similar cyber risk intelligence platforms is preferred.
- Strong analytical skills and proficiency in Excel, Power BI, and other data analysis or reporting tools.
- Ability to assess supplier documentation, identify gaps, and translate findings into clear risk summaries and follow-up actions.
- Excellent communication and stakeholder management skills, with the ability to work across procurement, suppliers, technical teams, and global stakeholders.
- Strong organizational skills, attention to detail, and ability to manage multiple priorities effectively.
- Curiosity, continuous learning mindset, and willingness to adapt to evolving regulations, risk landscapes, and digital tools.
- Business fluency in English.
About Vanderlande:
Vanderlande makes automated systems that handle baggage at airports and sort parcels in logistics networks around the world. At airports, our technology manages the complete bag journey: from check-in and security screening through to the reclaim belt. In parcel logistics, our systems power the networks that get packages to customers' doors.
At Vanderlande, you will find the space to aspire, to grow, and to achieve something that matters, with people who bring out the best in each other.
Website: www.vanderlande.com
What we offer:
Working at Vanderlande comes with the support and space to grow, achieve, and enjoy the journey. Here is what that looks like in practice:
- Competitive Salary Package
- 30 days of annual leave (pro-rated from the start of the financial year), including:
- 22 paid leave days
- sick/casual leave days
- Applicable government holidays
- Flexible and hybrid working model that promotes work-life balance.
- Access to Vanderlande Academy and a wide range of learning and development programs to enhance your skills.
- Comprehensive medical insurance coverage, including parental coverage.
- Opportunities to participate in diverse Vanderlande communities, networks, and employee initiatives
- Opportunity to collaborate globally.
How we work
We work by three values: Every day better, we care, and Team play. In practice, this means we drive customer success, lead with transparency, celebrate what we achieve together, and do what we say.
Ready to apply?
Are you interested in this position? Apply directly via our careers page with your CV/Resume.
Diversity & inclusion
Vanderlande is an equal opportunity/affirmative action employer. Qualified applicants will be considered without regards to race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.


