TPRM (Pune)

TPRM (Pune)

27 Sep
|
Deloitte Shared Services India
|
Pune

27 Sep

Deloitte Shared Services India

Pune

Role Overview

We are looking for a Consultant with hands-on experience in Cyber Third-Party Risk Management (TPRM), IT Risk Assessments, IT Audits, and Information Security.

The candidate will support client engagements involving third-party/vendor risk assessments, ISMS assessments, IT audits, information security risk assessments, compliance requirements, and control reviews. The role requires strong stakeholder management, analytical skills, documentation capabilities, and the ability to work with cross-functional and global teams.

Key Responsibilities

Cyber TPRM & Third-Party Risk

- Conduct Cyber Third-Party Risk / Vendor / Supplier Risk Assessments.
- Assess third-party security and privacy risks and identify applicable controls.
- Review vendor security controls, processes, policies, and supporting evidence.
- Evaluate third-party risks and document gaps, observations, and recommendations.
- Support implementation and enhancement of Third-Party Risk Management frameworks.
- Document information security risks, compensating controls, and remediation recommendations.

IT Risk & Audit

- Conduct risk assessments and audits across people, process, and technology.
- Support IT audits, ISMS assessments, and information security reviews.
- Identify control gaps, risks, observations, and opportunities for improvement.
- Review and assess policies, processes, procedures, and security standards.
- Prepare detailed assessment/audit reports, risk registers, and management presentations.

Compliance & Stakeholder Management





- Liaise with client teams across Compliance, Audit, Information Security, Risk, and Regulatory functions.
- Understand and document applicable regulatory and compliance requirements.
- Participate in client discussions, workshops, and stakeholder interviews.
- Effectively communicate findings, risks, recommendations, and remediation requirements.
- Manage stakeholder expectations and deliver assigned workstreams within timelines.

Mandatory Skills

- Cyber Third-Party Risk Management (TPRM)
- Vendor / Supplier Risk Management
- IT Risk Assessments / Information Security Risk
- IT Audit / ISMS Assessments
- Third-Party Security Assessments
- Knowledge of Data Protection & Privacy risks in third-party environments
- Understanding of TPRM control frameworks
- Risk, control, gap, and compliance assessments
- Robust documentation and report-writing skills
- Excellent verbal and written communication
- Ability to work with cross-functional and global stakeholders.

Additional / Preferred Skills

- ISO 22301 implementation or audit experience
- Infrastructure Security
- Application Security
- Cloud Security
- Information Risk Management
- ISO 27001
- Security control assessments
- Regulatory/compliance assessments

Preferred Certifications

- CISA
- CISSP
- CISM
- CEH
- ISO 27001
- CBCI / CBCP
- ISO 22301 Lead Implementer / Lead Auditor
- OSCP

Education Bachelors degree in Computer Science, Information Technology, Engineering, or a related field.

📌 TPRM (Pune)
🏢 Deloitte Shared Services India
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: tprm (pune) / pune

Subscribe to this job alert:

Get the latest job offers by email for: tprm (pune) / pune