EY

TC-CS-SRCR-Senior-Supply Chain and Third-Party Risk Management

EY  •  Bengaluru, IN (Onsite)  •  13 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Senior Consultant – AI Third Party Risk Consultant

Experience: 4–8 Years

The Senior Consultant – AI Third Party Risk Consultant is responsible for independently managing Third Party Security Assessment (TPSA) engagements across complex vendor ecosystems. The role demands deep expertise in TPRM frameworks, supply chain security, and risk lifecycle management, combined with active use of AI-enabled tools for vendor scoring, risk prediction, and control monitoring. The Senior Consultant provides technical depth to assessment delivery, contributes to methodology design, and supports junior analysts in executing high-quality risk evaluations across diverse industry sectors.

Key Responsibilities

  • Lead and independently execute Third Party Security Assessments (TPSA) across critical, high-risk, and strategic vendor portfolios.
  • Conduct comprehensive vendor due diligence including control gap analysis, regulatory compliance validation, and risk-tiered scoring.
  • Manage the full risk assessment lifecycle — from vendor onboarding due diligence through periodic reviews, escalation management, and exit risk assessments.
  • Design and refine vendor risk questionnaires, assessment frameworks, and scoring rubrics aligned to industry standards (ISO 27001, NIST CSF, SOC 2, DORA).
  • Perform supply chain risk analysis by identifying nth-party dependencies, concentration risks, and critical vendor failure scenarios.
  • Apply AI-enabled vendor risk scoring platforms to prioritize assessments and identify emerging threats.
  • Leverage predictive modelling and AI-assisted analytics to forecast vendor risk trajectories and recommend proactive controls.
  • Collaborate with procurement, legal, and business stakeholders to embed TPRM controls into vendor contracting and onboarding processes.
  • Prepare detailed risk assessment reports, risk ratings, and remediation recommendations for both technical and executive audiences.
  • Support the implementation of TPRM automation workflows and AI-driven continuous monitoring capabilities.
  • Mentor and guide Staff-level analysts, reviewing work quality and providing technical guidance.

Education / Certifications

  • Bachelor’s degree in engineering, Technology, Business, Risk Management, or related disciplines.
  • Relevant certifications are advantageous (e.g., ISO 42001, CISSP, CISM, CRISC, ISO 27001 Lead Implementer, CTPRP, or equivalent).

AI & Cyber Certifications

  • Cyber Security Certifications (Required / Advantageous):
    • Certified Information Systems Security Professional (CISSP) – Broad cybersecurity expertise including risk management and third-party security.
    • Certified Information Security Manager (CISM) – Information security management and risk governance.
    • Certified in Risk and Information Systems Control (CRISC) – IT risk identification, assessment, and lifecycle management.
    • Certified Third Party Risk Professional (CTPRP) – Specialized certification in TPRM frameworks and vendor assessment practices.
    • ISO/IEC 27001 Lead Implementer – Designing and implementing ISMS controls in vendor assessment contexts.
  • AI & Data Certifications:
    • Microsoft Certified: Azure AI Engineer Associate (AI-102) – Designing and implementing AI solutions relevant to risk automation.
    • AWS Certified Machine Learning – Specialty – Understanding ML pipelines applicable to risk scoring models.
    • Google Professional Machine Learning Engineer – ML model development and deployment for risk analytics.
    • Certified Artificial Intelligence Practitioner (CAIP) – Applied AI concepts across business and risk domains.
    • ISACA Certified Data Privacy Solutions Engineer (CDPSE) – Data privacy risk and AI data governance.

Skills & Experience

Required Skills and Experience:

  • 4–8 years of experience in third-party risk management, cyber risk, or information security consulting.
  • Proven experience executing end-to-end Third-Party Security Assessments across diverse vendor types (cloud, IT, operational).
  • In-depth knowledge of TPRM frameworks including NIST SP 800-161, ISO 27036, and sector-specific regulatory requirements.
  • Strong understanding of supply chain risk management including vendor tiering, concentration risk, and dependency mapping.
  • Use of AI in TPRM processes. Like using AI for assessor evaluation, writing issue descriptions and risk mitigation plans
  • Understanding risk from third parties using AI to provide services to client. Looking into AI governance and AI security
  • Understanding risk from third parties using AI Agents to provide services to client. Looking into AI governance and AI security
  • Use of AI in TPRM processes. Like using AI Agents to build automations in TPRM processes
  • Understanding how things like Frontier AI and Mythos will change cybersecurity Lense and how third parties are protecting themselves from these modern threats
  • Experience managing the risk assessment lifecycle including risk identification, rating, mitigation planning, and remediation tracking.
  • Ability to conduct control gap analysis against ISO 27001, SOC 2, NIST CSF, CIS Controls, and PCI DSS.
  • Experience working with GRC platforms for workflow management and risk tracking.
  • Strong analytical, written, and presentation skills for technical and non-technical audiences.
  • Hands-on experience with AI-enabled vendor risk scoring tools and external threat intelligence platforms.
  • Exposure to predictive modelling techniques applied to vendor risk prioritization and breach likelihood scoring.
  • Understanding of AI-driven control monitoring frameworks and machine learning-improved continuous assessment cycles.
  • Familiarity with Graph AI concepts for mapping vendor networks and identifying supply chain concentration risks.
  • Awareness of NLP-based document analysis tools for automated questionnaire review and evidence validation.
  • Experience using data analytics and BI tools (Power BI, Tableau, Python) to build risk dashboards.
  • Knowledge of AI governance frameworks and ethical AI risk considerations relevant to vendor AI system assessments.

AI Tools Skillset

  • Vendor Intelligence & Risk Scoring Platforms:
    • BitSight / Security Scorecard / RiskRecon – Active use for real-time vendor cyber ratings, issue tracking, and continuous monitoring feeds.
    • Prevalent / ProcessUnity / OneTrust VRM – End-to-end vendor risk assessment workflows, questionnaire management, and risk scoring.
    • UpGuard – Vendor surface attack monitoring and data breach detection integrated into TPRM workflows.
  • AI-Enabled Assessment & Automation Tools:
    • Coupa Risk Assess / Ariba Risk – AI-assisted supplier risk evaluation and procurement-integrated due diligence.
    • Armorblox / Darktrace – Awareness of AI-driven anomaly detection applicable to vendor environment assessments.
    • ChatGPT / Microsoft Copilot for Risk – Drafting risk reports, summarizing vendor evidence, and accelerating assessment documentation.
  • GRC & Workflow Automation:
    • ServiceNow GRC / Archer – Risk workflow management, assessment tracking, and automated risk register maintenance.
    • Power Automate / Zapier – Automating vendor questionnaire distribution, evidence collection reminders, and reporting workflows.
  • Data Analytics & Visualization:
    • Microsoft Power BI / Tableau – Building vendor risk dashboards, heat maps, and trend analysis reports.
    • Excel Power Query / Python (Pandas) – Risk data cleansing, vendor scoring model inputs, and assessment data aggregation.

Leadership & Behavioral Expectations

  • Deliver assigned assessment modules with quality, accuracy, and timeliness.
  • Collaborate effectively with cross-functional teams including procurement, legal, IT, and business stakeholders.
  • Demonstrate learning agility and proactively expand skills in AI-enabled risk management.
  • Support continuous improvement of TPRM methodologies, templates, and automation initiatives.
  • Communicate risk findings clearly and constructively to vendor stakeholders and internal clients.
  • Show initiative in identifying process improvement opportunities and contributing to practice development.

EY | Building a better working world




EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.




Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.




Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

EY

About EY

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners.

Find out more about the EY global network: http://ey.com/en_gl/legal-statement

Industry
Consulting & Advisory
Company Size
10,000+ employees
Headquarters
London, GB
Year Founded
Unknown
Website
ey.com
Social Media