Source description
About the role
TC - CS - SRCR - TPCRM - Senior At EY, youll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And were counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. EY- Cyber Risk Compliance and Resilience TPCRM Senior As part of our EY Cyber Risk and Compliance Consulting (CRCR) team, you will contribute technically to Cyber Security client engagements and internal projects. The role involves managing Third-Party Cyber Risk Management (TPCRM) engagements, ensuring that our clients effectively identify, assess, and mitigate risks associated with third-party relationships. An important part of your role will be to actively establish, maintain, and strengthen internal and external relationships. The opportunity We are looking for TPCRM Senior with expertise in cyber security, risk management, and security controls testing concepts. This role offers a unique opportunity to contribute to the growth of our TPCRM service offering while upholding EYs commitment to quality and excellence. In line with EYs commitment to quality, you will confirm that work is of the highest quality as per EYs quality standards. You will help to create a positive learning culture, coach and counsel junior team members and help them to develop. As an influential member of the team, you will help to create a positive learning culture, coach and counsel junior team members and help them to develop. Your key responsibilities To assist in the delivery of third-party risk management engagements. This includes: Risk Assessment and Management: Conduct comprehensive risk assessments of third-party vendors to identify potential risks and vulnerabilities. Draft and explain risk mitigation strategies to minimize exposure to third-party risks. Policy Development and Compliance : Collaborate with stakeholders to develop or update third-party risk management policies and procedures. Ensure compliance with regulatory requirements and internal policies related to third-party engagements. Third Party Due Diligence: Oversee the third-party due diligence process, including cyber, privacy, resiliency and compliance assessments. Cross-Functional Collaboration: Work closely with various departments (e.g., Security, Legal, Compliance, IT) to ensure a holistic approach to third-party risk management. Explain Risk/Findings or other assessment related deliverables to client stakeholders. Facilitate communication and training on third-party risk management best practices across the organization. Reporting and Analytics : Prepare and present regular reports on third-party risk exposure and management activities to client senior leadership. Utilize data analytics to identify trends and areas for improvement in third-party risk management processes. Incident Management: Lead investigations into third-party incidents and breaches, ensuring appropriate corrective actions are taken. Maintain an incident response plan specific to third-party risks. Continuous Improvement: Stay informed about industry trends, emerging risks, and best practices in third-party risk management. Recommend enhancements to the third-party risk management framework based on evolving business needs and regulatory changes. Skills and attributes for success Cyber Security Skills: Around 5 years of experience with key components of Cyber Security including (but not limited to): Third Party Cyber Risk Management (End to end TPCRM lifecycle) Cyber Governance, Risk and Compliance Cyber Strategy & Transformation Business Continuity & Disaster Recovery Basic knowledge of general security concepts, including defence-in-depth, least privilege, security architecture and design, networking, architecture reviews, VAPT, IDS/IPS technologies, SIEM, and resiliency concepts such as business continuity and workplace safety. TPCRM Skills: Experience in client-facing roles, managing cyber security and resiliency-based third-party risk assessments from start to finish. Ability to lead third-party assessments, providing technical guidance to assessors and facilitating decision-making during evidence reviews. Analytical Skills: Strong ability to analyze complex data and risk factors to make informed decisions regarding third-party relationships. Attention to Detail: Meticulous attention to detail in assessing vendor documentation, contracts, and compliance requirements to ensure thorough evaluations. Communication Skills: Excellent verbal and written communication skills to effectively convey risk assessments and recommendations to stakeholders at all levels. Problem-Solving Abilities: Proactive and strategic thinker with a knack for identifying potential issues and developing effective solutions to mitigate risks. Interpersonal Skills: Strong relationship-building skills to foster TC - CS - SR
More at Ernst & Young LLP ( EY India )
Related open roles
Senior Cyber Resilience and Incident Response Specialist
Bangalore
Senior Cybersecurity Engineer - Sentinel SOAR
Bangalore
AI Architect and Manager - Identity and Access Management (IAM) Cybersecurity
Bangalore
Senior Consultant - Data Privacy and Cyber Security
India
Next-Gen SIEM Security Analyst
India
Senior Security Consultant - SOC with CrowdStrike Next-Gen SIEM/EDR Expertise
Bangalore