Job Description
Summary
Deloitte India is hiring an Assistant Manager – Third Party Risk Management (TPRM) for its Cyber Strategy & Transformation practice in Pune. This role is ideal for cybersecurity and IT risk professionals with experience in third-party/vendor risk assessments, ISMS, IT audits, and compliance. As part of Deloitte’s Risk Advisory Cyber team, you will work with clients to strengthen their information security, manage vendor risks, and build scalable risk management frameworks. Join Deloitte South Asia and accelerate your career in one of the world’s leading consulting organizations.
Job Details at a Glance
| Job Title | Assistant Manager – Third Party Risk Management |
|---|---|
| Company | Deloitte Touche Tohmatsu India LLP |
| Location | Pune, India (Work from Office) |
| Job ID | 77182 |
| Date Posted | Sep 18, 2025 |
| Department | Cyber Strategy & Transformation – Risk Advisory |
| Designation | Assistant Manager |
| Experience | 3+ years in Third Party Risk / IT Audit / Cybersecurity |
| Certifications | CISSP, CISA, CISM, CEH, ISO27001, CBCI, CBCP (preferred) |
| Education | B.Tech / B.E. or equivalent engineering degree |
Responsibilities
As an Assistant Manager – Third Party Risk Management at Deloitte, you will:
- Conduct ISMS and Third-Party Risk Assessments for global clients.
- Liaise with compliance teams, auditors, and regulators to document obligations.
- Perform IT audits across people, processes, and technology.
- Identify gaps, risks, and opportunities to improve policies, standards, and procedures.
- Document findings, recommendations, and compensating controls in audit/assessment reports.
- Define frameworks for vendor information security reviews and evaluations.
- Lead the assessment/audit lifecycle: planning, execution, reporting, and tracking.
- Collaborate with engagement teams to prepare deliverables and ensure quality reviews.
- Mentor and guide team members on complex cybersecurity and risk issues.
Skills & Qualifications
- Experience:
- 3+ years in Third Party Risk Management
- Strong exposure to IT audits, information risk management, cloud security
- Hands-on experience with ISO22301, ISO27001 frameworks
- Certifications (preferred):
- CBCI, CBCP, ISO22301 LI/LA
- CISSP, CISA, CISM, CEH, OSCP
- Knowledge Areas:
- Data protection & privacy risks in third-party ecosystems
- Vendor/supplier risk management frameworks
- Infrastructure & application security fundamentals
- Soft Skills:
- Excellent communication, documentation, and presentation skills
- Ability to work in cross-functional and global environments
- Strong stakeholder management and problem-solving ability
Why Deloitte?
At Deloitte, you will:
- Work with global clients on cutting-edge cyber and risk projects.
- Be part of a diverse, inclusive, and collaborative culture.
- Gain access to career mobility, leadership opportunities, and certifications.
- Experience a structured career growth path in Risk Advisory & Cybersecurity.
Apply Now
Take your cybersecurity career to the next level with Deloitte South Asia.
👉 Apply directly on Deloitte’s official careers page