T&T | Cyber CST | Consultant | Third Party Risk Management | Bengaluru | (Bengaluru, IN)
Deloitte
Deloitte
Join a leading firm dedicated to bolstering cybersecurity and asset protection. We focus on creating secure, vigilant, and resilient environments by integrating cyber risk management into strategic development, thereby optimizing information and technology risk management. Explore the world of Cyber | Deloitte to learn more about our innovative approaches.
This role is instrumental in supporting client engagements that span third-party risk assessments, comprehensive vendor due diligence, compliance evaluations, remediation tracking, and continuous monitoring. Cultivating strong client relationships and collaborating effectively with third-party stakeholders are key to delivering high-quality, well-documented outcomes. Fluency in English is essential, complemented by mandatory business proficiency in either Spanish or Portuguese for seamless communication across diverse international client bases and stakeholder groups.
The TPRM Consultant will be responsible for the full spectrum of Third-Party Risk Management activities. This includes supporting vendor onboarding, conducting inherent risk assessments, coordinating due diligence efforts, documenting risk reviews, performing periodic reassessments, and executing ongoing monitoring tasks. A significant part of the role involves conducting thorough vendor risk and compliance reviews, scrutinizing evidence, control documentation, and risk indicators across critical domains like information security, privacy, business continuity, and operational risk.
You will also be tasked with coordinating due diligence processes and remediation efforts. This entails tracking open actions, diligently following up with stakeholders, documenting risk decisions, validating remediation progress, and ensuring timely closure of identified findings. Preparing client-ready documentation, such as risk summaries, assessment notes, meeting trackers, and governance reports, is also a core responsibility. Engaging effectively with multilingual stakeholders, gathering essential information, clarifying requirements, and facilitating the timely delivery of TPRM outputs are crucial for success.
We are seeking candidates with a strong foundation in Third-Party Risk Management, supplier or vendor risk management, due diligence, risk assessments, issue management, risk acceptance, and ongoing monitoring. A solid understanding of key risk domains, including information security, data privacy, business continuity, operational risk, and regulatory compliance, is essential. The ability to review diverse documentation such as questionnaires, policies, and control evidence, and translate observations into clear risk narratives and actionable recommendations is paramount.
Exceptional stakeholder management and coordination skills are required to effectively engage with vendors, client teams, and internal stakeholders across different regions. Proficiency with Microsoft Excel, PowerPoint, and Word is expected, with experience in GRC/TPRM platforms being a significant advantage. Excellent written and verbal communication, keen attention to detail, strong analytical thinking, and an ownership mindset are vital for managing multiple deliverables within a dynamic consulting environment. Prior consulting experience or experience supporting global/regional TPRM programs is highly desirable.
Familiarity with the third-party lifecycle processes, from onboarding to offboarding, and exposure to common risk and control frameworks like ISO 27001, NIST, GDPR, and business continuity standards are beneficial. The capacity to collaborate effectively with business, risk, compliance, procurement, technology, and legal stakeholders in a matrixed environment is key. A Bachelor’s degree in a relevant discipline such as business, commerce, risk management, information systems, technology, or law is required. Relevant certifications are a plus.
Deloitte
Information Technology & Services