Job Description
Summary
Deloitte India is hiring an Assistant Manager – Third-Party Risk Management (TPRM) in Delhi to strengthen enterprise cybersecurity and vendor risk frameworks. This role focuses on third-party risk assessment, vendor due diligence, IT audits, and regulatory compliance. The ideal candidate will have experience in ISO 27001, PCI DSS, GDPR, RBI guidelines, and cloud security assessments, driving risk mitigation strategies and improving operational resilience. This position offers an opportunity to shape TPRM programs, collaborate across business units, and ensure robust cybersecurity governance.
Job Details at a Glance
| Job Title | Assistant Manager – Third-Party Risk Management (TPRM) |
|---|---|
| Location | Delhi / Gurgaon, India |
| Designation | Assistant Manager |
| Entity | Deloitte Touche Tohmatsu India LLP |
| Experience Required | 3–5 years in TPRM, IT Audit, or Cybersecurity |
| Industry | Cybersecurity / IT Risk |
| Certifications | CISSP, CISA, CISM, ISO 27001, CBCI, CBCP, ISO22301 (preferred) |
| Tools/Platforms | GRC tools, Risk dashboards, Cloud Security platforms |
| Education | B.E / B.Tech / MBA in IT, Computer Science, or related fields |
| Work Mode | On-site (Gurgaon) |
Key Responsibilities
Third-Party Risk Assessment
- Perform TPRM processes, including due diligence, onboarding, and periodic reviews.
- Evaluate third-party controls for data protection, network security, access management, application security, and business continuity.
- Collaborate with Legal, IT Security, Procurement, and Business Units to ensure comprehensive risk coverage.
- Develop and maintain TPRM frameworks, policies, and procedures in line with industry standards and regulations.
Reporting & Governance
- Prepare risk reports, dashboards, and metrics for senior management and risk committees.
- Support Managers/Assistant Directors in audits, assessments, and quality reviews.
- Contribute to business development through RFPs, proposals, and new opportunities.
Process Improvement & Automation
- Identify automation opportunities in third-party assessments.
- Participate in risk assessments and short-term engagements independently.
- Conduct on-ground risk evaluations of people, processes, and technology.
Skills & Qualifications
- Experience: 3–5 years in third-party risk management, IT audits, and cloud security.
- Strong knowledge of ISO 27001, SOC 2, GDPR, PCI DSS, ISO 22301 compliance.
- Relevant certifications preferred: CISSP, CISA, CISM, CBCI/CBCP, ISO22301 LI/LA.
- Understanding of vendor/supplier risk management considerations.
- Knowledge of data protection & privacy risks for third-party vendors.
- Excellent communication, documentation, and presentation skills.
- Ability to work independently in local and global environments.
Career Growth & Development
- Gain exposure to global cybersecurity programs and third-party risk frameworks.
- Access Deloitte University programs for skill enhancement and leadership development.
- Opportunities to lead vendor risk assessments and influence cross-functional cybersecurity strategies.
- Engage in mentorship and collaborative projects across business units and geographies.
Apply Now
Take the next step as Assistant Manager – TPRM, Deloitte Delhi.
👉 Apply directly on Deloitte Careers