Cyber Third Party Risk Management – Associate Consultant | KPMG Global Services, Bangalore

September 17, 2025

Job Description


Summary

KPMG Global Services (KGS) is hiring a Cyber Third Party Risk Management Associate Consultant in Bangalore, Karnataka. This role is ideal for professionals with hands-on experience in information security governance, IT/IS risk assessments, privacy compliance, and third-party/vendor security assessments. Join KGS and contribute to assessing, monitoring, and enhancing cybersecurity risk management programs for global clients while working with cross-functional teams and leading consulting practices. Gain exposure to ISO 27001, NIST 800-53, PCI-DSS, and Business Continuity planning in a fast-paced professional services environment.


Job Details at a Glance

Job TitleCyber Third Party Risk Management – Associate Consultant
LocationBangalore, Karnataka, India
CompanyKPMG Global Services Pvt. Ltd.
Role TypeFull-Time
Reporting ToSenior Consultants / Assistant Manager
Shift/Work Hours9:00 AM – 5:30 PM IST
Experience Required4+ years in Information Security, IT Risk, or Compliance
Educational QualificationB.Tech/BE/Graduate
Skills & ToolsISO 27001, NIST 800-53, PCI-DSS, IT Risk Assessment, Vendor Security Assessment, Business Continuity, Disaster Recovery, CISA, CISSP, CISM, CIPP

Key Responsibilities

Cyber Risk Management & Assessments

  • Conduct IT/IS risk assessments and program reviews for client environments.
  • Perform vendor and third-party security assessments independently and remotely.
  • Evaluate information security governance, privacy compliance, and control frameworks for global clients.
  • Implement and review business continuity and disaster recovery plans.

Reporting & Documentation

  • Draft high-quality assessment reports and present findings to clients.
  • Conduct second-level quality review of reports prepared by peers and junior team members.
  • Ensure compliance with KPMG’s risk management and internal audit guidelines.

Client Engagement & Advisory

  • Participate in client presentations and proposal development.
  • Build and maintain strong client relationships.
  • Support execution and delivery of multiple engagements within KGS’s client portfolio.

Required Skills & Qualifications

  • 4+ years of experience in Information Security Governance, Privacy, Compliance, and Security Assessments.
  • Experience with ISO 27001, NIST 800-53, PCI-DSS, and related information security frameworks.
  • Hands-on expertise in IT/IS Risk Assessments, third-party/vendor audits, and program establishment.
  • Knowledge of BS ISO/IEC/SIG 27002:2005, BS 7799, BS 25999 domains including Risk Assessment, Security Policy, Asset Management, Access Control, and IS Incident Management.
  • Strong verbal and written communication skills in English.
  • Prior consulting experience with Big 4 or large enterprise clients is preferred.
  • Relevant certifications such as CISA, CISSP, CISM, CIPP, or ISO 27001 are advantageous.

Preferred Skills

  • Ability to work independently and proactively on remote assessments.
  • Strong analytical and problem-solving skills.
  • Familiarity with emerging trends in cybersecurity and risk management.
  • Team-oriented with the ability to mentor junior colleagues.

Why Join KPMG Global Services?

  • Work on high-impact cybersecurity and third-party risk engagements for global clients.
  • Gain exposure to leading information security frameworks, IT risk assessments, and privacy compliance programs.
  • Collaborate with a dynamic, cross-functional, and inclusive team.
  • Enhance your career growth with mentorship, learning opportunities, and international client exposure.

Apply Now

Kickstart your career as a Cyber Third Party Risk Management Associate Consultant at KPMG Global Services, Bangalore. Apply directly on the official KPMG Careers page to join a team delivering cutting-edge cybersecurity and IT risk solutions.