TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management
EY
EY
EY is seeking a Senior Consultant to join its AI Third Party Risk Management team. This role offers an exceptional career opportunity within a global organization, fostering an inclusive culture and leveraging cutting-edge technology. You will contribute to building a better working world by enhancing client security and risk mitigation strategies.
This position focuses on AI Third Party Risk Consulting, requiring 4-8 years of experience. The role involves independently managing complex Third Party Security Assessment (TPSA) engagements. You will utilize deep expertise in TPRM frameworks, supply chain security, and risk lifecycle management, augmented by AI-enabled tools for vendor scoring and risk prediction.
Lead and execute Third Party Security Assessments (TPSA) for critical vendor portfolios. Conduct thorough vendor due diligence, including control gap analysis and regulatory compliance validation.
Manage the entire risk assessment lifecycle, from onboarding through periodic reviews and exit strategies. Design and refine assessment frameworks, questionnaires, and scoring rubrics aligned with industry standards like ISO 27001 and NIST CSF.
Analyze supply chain risks, identify nth-party dependencies, and assess critical vendor failure scenarios. Employ AI-enabled platforms for vendor risk scoring and threat identification. Use predictive modeling to forecast vendor risk trajectories and recommend proactive controls.
Collaborate with procurement, legal, and business teams to integrate TPRM controls. Prepare detailed risk reports and remediation recommendations for diverse audiences. Support the implementation of TPRM automation and AI-driven continuous monitoring.
Mentor junior analysts, ensuring high-quality risk evaluations across various industry sectors. Guide staff-level analysts and review their work for technical accuracy and completeness.
A Bachelor's degree in engineering, technology, business, or risk management is required. Relevant certifications such as CISSP, CISM, CRISC, or CTPRP are advantageous.
Possess 4-8 years of experience in third-party risk management, cyber risk, or information security consulting. Demonstrate proven experience in end-to-end Third-Party Security Assessments across various vendor types.
Exhibit in-depth knowledge of TPRM frameworks (NIST SP 800-161, ISO 27036) and supply chain risk management principles. Experience with AI in TPRM processes, including AI for assessor evaluation and risk mitigation planning, is essential.
Familiarity with AI governance and AI security related to third-party services is expected. Understanding how advanced AI concepts like Frontier AI and Mythos impact cybersecurity and third-party defenses is crucial.
Experience managing the full risk assessment lifecycle and conducting control gap analysis against standards like ISO 27001 and SOC 2. Proficiency with GRC platforms and data analytics tools like Power BI, Tableau, or Python is required.
Strong analytical, written, and presentation skills are necessary to communicate complex risk findings effectively to both technical and non-technical stakeholders.
EY Global Delivery Services ( EY GDS)
Management Consulting