TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management

EY

4–8 yrs Bengaluru Full Time Hybrid (office + remote)
EY logo
Posted : 1 week ago
Actively hiring

Job description

EY is seeking a Senior Consultant to join its AI Third Party Risk Management team. This role offers an exceptional career opportunity within a global organization, fostering an inclusive culture and leveraging cutting-edge technology. You will contribute to building a better working world by enhancing client security and risk mitigation strategies.

This position focuses on AI Third Party Risk Consulting, requiring 4-8 years of experience. The role involves independently managing complex Third Party Security Assessment (TPSA) engagements. You will utilize deep expertise in TPRM frameworks, supply chain security, and risk lifecycle management, augmented by AI-enabled tools for vendor scoring and risk prediction.

Responsibilities

Lead and execute Third Party Security Assessments (TPSA) for critical vendor portfolios. Conduct thorough vendor due diligence, including control gap analysis and regulatory compliance validation.

Manage the entire risk assessment lifecycle, from onboarding through periodic reviews and exit strategies. Design and refine assessment frameworks, questionnaires, and scoring rubrics aligned with industry standards like ISO 27001 and NIST CSF.

Analyze supply chain risks, identify nth-party dependencies, and assess critical vendor failure scenarios. Employ AI-enabled platforms for vendor risk scoring and threat identification. Use predictive modeling to forecast vendor risk trajectories and recommend proactive controls.

Collaborate with procurement, legal, and business teams to integrate TPRM controls. Prepare detailed risk reports and remediation recommendations for diverse audiences. Support the implementation of TPRM automation and AI-driven continuous monitoring.

Mentor junior analysts, ensuring high-quality risk evaluations across various industry sectors. Guide staff-level analysts and review their work for technical accuracy and completeness.

Qualifications

A Bachelor's degree in engineering, technology, business, or risk management is required. Relevant certifications such as CISSP, CISM, CRISC, or CTPRP are advantageous.

Possess 4-8 years of experience in third-party risk management, cyber risk, or information security consulting. Demonstrate proven experience in end-to-end Third-Party Security Assessments across various vendor types.

Exhibit in-depth knowledge of TPRM frameworks (NIST SP 800-161, ISO 27036) and supply chain risk management principles. Experience with AI in TPRM processes, including AI for assessor evaluation and risk mitigation planning, is essential.

Familiarity with AI governance and AI security related to third-party services is expected. Understanding how advanced AI concepts like Frontier AI and Mythos impact cybersecurity and third-party defenses is crucial.

Experience managing the full risk assessment lifecycle and conducting control gap analysis against standards like ISO 27001 and SOC 2. Proficiency with GRC platforms and data analytics tools like Power BI, Tableau, or Python is required.

Strong analytical, written, and presentation skills are necessary to communicate complex risk findings effectively to both technical and non-technical stakeholders.

Essential Skills

Third-Party Risk Management (TPRM)Supply Chain SecurityRisk Lifecycle ManagementAI-enabled ToolsVendor ScoringRisk PredictionControl MonitoringNIST SP 800-161ISO 27036Vendor TieringConcentration RiskDependency MappingAI in TPRMAI GovernanceAI SecurityAI AgentsFrontier AIMythosRisk IdentificationRisk RatingMitigation PlanningRemediation TrackingISO 27001SOC 2NIST CSFCIS ControlsPCI DSSGRC PlatformsAnalytical SkillsPresentation SkillsAI-enabled Vendor Risk Scoring ToolsExternal Threat Intelligence PlatformsPredictive ModellingVendor Risk PrioritizationBreach Likelihood ScoringAI-driven Control MonitoringMachine LearningGraph AINLP-based Document AnalysisData AnalyticsBI ToolsPower BITableauPythonPandasEthical AI

Good to Have

ISO 42001CISSPCISMCRISCISO 27001 Lead ImplementerCTPRPMicrosoft Certified: Azure AI Engineer Associate (AI-102)AWS Certified Machine Learning – SpecialtyGoogle Professional Machine Learning EngineerCertified Artificial Intelligence Practitioner (CAIP)ISACA Certified Data Privacy Solutions Engineer (CDPSE)

Highlights

  • Actively hiring

More Details

RoleTC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management
IndustryManagement Consulting, Financial Services
DepartmentRisk Management, Supply Chain Management
Employment TypeFull Time, Hybrid (office + remote)

About the Company

EY Global Delivery Services ( EY GDS) logo

EY Global Delivery Services ( EY GDS)

Management Consulting