Deloitte Touche Tohmatsu India LLP invites online application for the post of Consultant in Third Party Risk Management.
Name of the Post: Consultant
Location: Bangaluru
Essential Qualification and Experience
- TPRM / vendor risk experience: Experience in Third-Party Risk Management, supplier or vendor risk management, due diligence, risk assessments, issue management, risk acceptance, and ongoing monitoring.
- Risk and compliance knowledge: Understanding of key risk domains, including information security, data privacy, business continuity, operational risk, regulatory compliance, financial risk, and outsourcing or third-party governance.
- Assessment and documentation skills: Ability to review questionnaires, policies, procedures, control evidence, and third-party responses, and translate observations into clear risk narratives and actionable recommendations.
- Stakeholder management: Strong coordination skills with the ability to follow up with vendors, client teams, business owners, control owners and risk stakeholders across regions.
- Tools and reporting: Working knowledge of Microsoft Excel, PowerPoint and Word; experience with GRC / TPRM platforms, workflow tools or ticketing systems will be an added advantage.
- Professional skills: Strong written and verbal communication, attention to detail, analytical thinking, ownership mindset, and the ability to manage multiple deliverables within a consulting environment.
- Prior consulting experience or experience supporting global / regional TPRM programs.
- Exposure to third-party lifecycle processes, including onboarding, risk tiering, due diligence, periodic reviews, issue tracking, and termination or offboarding controls.
- Familiarity with common risk and control frameworks, such as ISO 27001, SOC reports, NIST, GDPR or privacy requirements, business continuity standards, and outsourcing governance expectations.
- Ability to work with business, risk, compliance, procurement, technology and legal stakeholders in a matrixed environment.
- Bachelor's degree in business, Commerce, Risk Management, Information Systems, Technology, Law or a related discipline.
- Relevant certifications, such as ISO 27001, ISO 22301, or similar credentials, will be considered an added advantage.
- Prior experience in TPRM, vendor management, risk management, compliance, internal audit or consulting is preferred.
Roles & Responsibilities
- Support end-to-end TPRM activities – Assist with third-party onboarding, inherent risk assessments, due diligence coordination, risk review documentation, periodic reassessments, and ongoing monitoring activities.
- Conduct vendor risk and compliance reviews – Review third-party responses, supporting evidence, control documentation, and risk indicators across areas such as information security, privacy, business continuity, financial viability, compliance, and operational risk.
- Coordinate due diligence and remediation – Track open actions, follow up with stakeholders, document risk decisions, validate remediation progress, and support timely closure of findings in line with agreed timelines.
- Prepare client-ready documentation – Develop risk summaries, assessment notes, meeting trackers, dashboards, status updates, governance reports, and audit-ready evidence packs.
- Engage with multilingual stakeholders – Communicate effectively in English and Spanish or Portuguese with client teams, vendors, and regional stakeholders to gather information, clarify requirements, and support timely completion of TPRM deliverables.
How to apply?
- To apply online, click here
To Access Official Notification, click here