T&T | Cyber: CST | Deputy Manager | Third Party Risk Management | Bengaluru (Bengaluru, IN)

Deloitte

6+ yrs Bengaluru Full Time Work from office
Deloitte logo
Posted : today
Actively hiring

Job description

Join a leading cybersecurity team focused on safeguarding organizations and their critical assets. We champion a secure, vigilant, and resilient approach to cyber risk management, enabling clients to confidently pursue new opportunities. Integrate cyber risk considerations early in strategy development for effective information and technology risk mitigation. Learn more about the impactful work in Cyber | Deloitte.

As a Deputy Manager in Third-Party Risk Management (TPRM), you will play a key role in client engagements. This involves conducting comprehensive third-party risk assessments, thorough vendor due diligence, compliance reviews, and tracking remediation efforts. You will also oversee ongoing monitoring activities.

Building strong working relationships with client teams and external stakeholders is essential. The role demands the delivery of clear, meticulously documented, and high-quality outputs. Professional proficiency in English is required, along with a mandatory business proficiency in either Spanish or Portuguese to facilitate seamless communication across diverse global environments.

Responsibilities

Engage in end-to-end TPRM activities, from assisting with third-party onboarding and inherent risk assessments to coordinating due diligence and documenting risk reviews. Conduct periodic reassessments and manage ongoing monitoring processes.

Perform detailed vendor risk and compliance reviews by examining third-party responses, supporting evidence, control documentation, and risk indicators across various domains like information security, privacy, business continuity, financial health, and operational risk.

Coordinate due diligence processes and remediation tracking. This includes monitoring open actions, following up with stakeholders, documenting risk decisions, and validating remediation progress to ensure timely closure of findings.

Prepare polished, client-ready documentation such as risk summaries, assessment notes, meeting trackers, dashboards, status updates, governance reports, and audit-ready evidence packs.

Collaborate effectively with multilingual stakeholders, communicating clearly in English and either Spanish or Portuguese with client teams, vendors, and regional contacts to gather information, clarify requirements, and ensure the timely completion of TPRM deliverables.

Qualifications

Minimum of 6 years of relevant experience in Third-Party Risk Management (TPRM), supplier or vendor risk management, due diligence, risk assessments, issue management, risk acceptance, and ongoing monitoring. A strong understanding of key risk domains, including information security, data privacy, business continuity, operational risk, regulatory compliance, financial risk, and outsourcing or third-party governance is crucial.

Demonstrate proficiency in reviewing questionnaires, policies, procedures, control evidence, and third-party responses, translating observations into clear risk narratives and actionable recommendations. Excellent coordination skills are essential for following up with vendors, client teams, business owners, control owners, and risk stakeholders across different regions.

Possess working knowledge of Microsoft Excel, PowerPoint, and Word. Experience with GRC/TPRM platforms, workflow tools, or ticketing systems is a significant advantage. Essential professional skills include strong written and verbal communication, meticulous attention to detail, sharp analytical thinking, an ownership mindset, and the ability to manage multiple deliverables effectively within a fast-paced consulting environment.

Prior consulting experience or experience supporting global/regional TPRM programs is highly valued. Familiarity with common risk and control frameworks such as ISO 27001, SOC reports, NIST, GDPR, or privacy requirements, business continuity standards, and outsourcing governance expectations is beneficial. The ability to collaborate effectively with business, risk, compliance, procurement, technology, and legal stakeholders in a matrixed environment is key.

Educational background should include a Bachelor’s degree in business, Commerce, Risk Management, Information Systems, Technology, Law, or a related discipline. A Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or a related field is also suitable. Relevant certifications like ISO 27001 or ISO 22301 will be considered a strong plus.

Essential Skills

Third-Party Risk Management (TPRM)Vendor Risk ManagementDue DiligenceRisk AssessmentIssue ManagementRisk AcceptanceOngoing MonitoringInformation SecurityData PrivacyBusiness ContinuityOperational RiskRegulatory ComplianceFinancial RiskOutsourcing GovernanceQuestionnaire ReviewPolicy ReviewProcedure ReviewControl Evidence ReviewRisk Narrative DevelopmentActionable RecommendationsStakeholder ManagementCoordinationMicrosoft ExcelMicrosoft PowerPointMicrosoft WordGRC PlatformsTPRM PlatformsWorkflow ToolsTicketing SystemsWritten CommunicationVerbal CommunicationAttention to DetailAnalytical ThinkingOwnership MindsetMultitaskingConsulting EnvironmentThird-Party Lifecycle ProcessesOnboardingRisk TieringPeriodic ReviewsIssue TrackingTermination ControlsOffboarding ControlsISO 27001SOC ReportsNISTGDPRBusiness Continuity StandardsOutsourcing Governance ExpectationsMatrixed Environment Collaboration

Good to Have

GRC / TPRM platformsworkflow toolsticketing systemsISO 27001ISO 22301Certifications

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber: CST | Deputy Manager | Third Party Risk Management | Bengaluru (Bengaluru, IN)
IndustryCybersecurity, Information Technology & Services, Management Consulting
DepartmentRisk Management
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Cybersecurity

T&T | Cyber: CST | Deputy Manager | Third Party Risk Management | Bengaluru (Bengaluru, IN) at Deloitte | SkillMX | SkillMX