Back to Job Portal
D

Consultant | Third Party Risk Management | Bengaluru | Cyber Strategy & Transformation

Deloitte · Bengaluru, India
Posted August 3, 2026 via Deloitte

Consultant | Third Party Risk Management | Bengaluru | Cyber Strategy & Transformation

• Job requisition ID : 109879 

• Location: Bengaluru

• Entity: Deloitte Touche Tohmatsu India LLP 

The Team  

Deloitte helps organizations manage risk with confidence by strengthening governance, compliance, operational resilience, and third-party oversight. Our Third-Party Risk Management (TPRM) services assist clients in identifying, assessing, monitoring, and mitigating risks associated with vendors, suppliers, service providers, and other external business relationships.

As part of this team, you will collaborate with clients and internal stakeholders to design and support practical, risk-based third-party programs aligned with regulatory expectations, operational resilience objectives, and effective vendor governance across the third-party lifecycle.

Your Work Profile 

As a TPRM Consultant, you will support client engagements focused on third-party risk assessments, vendor due diligence, compliance reviews, remediation tracking, and ongoing monitoring. You will be expected to establish strong working relationships with client teams and third-party stakeholders while delivering clear, well-documented, and high-quality outputs.

This role requires professional proficiency in English, along with mandatory business proficiency in Spanish or Portuguese, to support effective communication with clients and stakeholders across English-speaking and Latin American or Portuguese-speaking environments.

Support end-to-end TPRM activities – Assist with third-party onboarding, inherent risk assessments, due diligence coordination, risk review documentation, periodic reassessments, and ongoing monitoring activities.

Conduct vendor risk and compliance reviews – Review third-party responses, supporting evidence, control documentation, and risk indicators across areas such as information security, privacy, business continuity, financial viability, compliance, and operational risk.

Coordinate due diligence and remediation – Track open actions, follow up with stakeholders, document risk decisions, validate remediation progress, and support timely closure of findings in line with agreed timelines.

Prepare client-ready documentation – Develop risk summaries, assessment notes, meeting trackers, dashboards, status updates, governance reports, and audit-ready evidence packs.

Engage with multilingual stakeholders – Communicate effectively in English and Spanish or Portuguese with client teams, vendors, and regional stakeholders to gather information, clarify requirements, and support timely completion of TPRM deliverables.

Key Skills Required 

Languages: English professional proficiency; Spanish or Portuguese business proficiency is mandatory.

TPRM / vendor risk experience: Experience in Third-Party Risk Management, supplier or vendor risk management, due diligence, risk assessments, issue management, risk acceptance, and ongoing monitoring.

Risk and compliance knowledge: Understanding of key risk domains, including information security, data privacy, business continuity, operational risk, regulatory compliance, financial risk, and outsourcing or third-party governance.

Assessment and documentation skills: Ability to review questionnaires, policies, procedures, control evidence, and third-party responses, and translate observations into clear risk narratives and actionable recommendations.

Stakeholder management: Strong coordination skills with the ability to follow up with vendors, client teams, business owners, control owners and risk stakeholders across regions.

Tools and reporting: Working knowledge of Microsoft Excel, PowerPoint and Word; experience with GRC / TPRM platforms, workflow tools or ticketing systems will be an added advantage.

Professional skills: Strong written and verbal communication, attention to detail, analytical thinking, ownership mindset, and the ability to manage multiple deliverables within a consulting environment.

Prior consulting experience or experience supporting global / regional TPRM programs.

Exposure to third-party lifecycle processes, including onboarding, risk tiering, due diligence, periodic reviews, issue tracking, and termination or offboarding controls.

Familiarity with common risk and control frameworks, such as ISO 27001, SOC reports, NIST, GDPR or privacy requirements, business continuity standards, and outsourcing governance expectations.

Ability to work with business, risk, compliance, procurement, technology and legal stakeholders in a matrixed environment.

Bachelor’s degree in business, Commerce, Risk Management, Information Systems, Technology, Law or a related discipline.

Relevant certifications, such as ISO 27001, ISO 22301, or similar credentials, will be considered an added advantage.

Prior experience in TPRM, vendor management, risk management, compliance, internal audit or consulting is preferred.
Applying to this role?

Book a mock interview matched to your skills and get a written scorecard before the real thing.

Book interview prep