TC-CS-SRCR-Senior_Supply Chain and Third-Party Risk Management
EY
- Location
- Bengaluru, KA, IN, 560048 +8 more…
- Work model
- On-Site
- Level
- Mid
Skills
About this role
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Senior Consultant – AI Third Party Risk Consultant Experience: 4–8 Years Role Summary The Senior Consultant – AI Third Party Risk Consultant is responsible for independently managing Third Party Security Assessment (TPSA) engagements across complex vendor ecosystems. The role demands deep expertise in TPRM frameworks, supply chain security, and risk lifecycle management, combined with active use of AI-enabled tools for vendor scoring, risk prediction, and control monitoring. The Senior Consultant provides technical depth to assessment delivery, contributes to methodology design, and supports junior analysts in executing high-quality risk evaluations across diverse industry sectors. Key Responsibilities
Lead and independently execute Third Party Security Assessments (TPSA) across critical, high-risk, and strategic vendor portfolios. Conduct comprehensive vendor due diligence including control gap analysis, regulatory compliance validation, and risk-tiered scoring. Manage the full risk assessment lifecycle — from vendor onboarding due diligence through periodic reviews, escalation management, and exit risk assessments. Design and refine vendor risk questionnaires, assessment frameworks, and scoring rubrics aligned to industry standards (ISO 27001, NIST CSF, SOC 2, DORA). Perform supply chain risk analysis by identifying nth-party dependencies, concentration risks, and critical vendor failure scenarios. Apply AI-enabled vendor risk scoring platforms to prioritize assessments and identify emerging threats. Leverage predictive modelling and AI-assisted analytics to forecast vendor risk trajectories and recommend proactive controls. Collaborate with procurement, legal, and business stakeholders to embed TPRM controls into vendor contracting and onboarding processes. Prepare detailed risk assessment reports, risk ratings, and remediation recommendations for both technical and executive audiences. Support the implementation of TPRM automation workflows and AI-driven continuous monitoring capabilities. Mentor and guide Staff-level analysts, reviewing work quality and providing technical guidance.
Education / Certifications
Bachelor’s degree in engineering, Technology, Business, Risk Management, or related disciplines. Relevant certifications are advantageous (e.g., ISO 42001, CISSP, CISM, CRISC, ISO 27001 Lead Implementer, CTPRP, or equivalent).
AI & Cyber Certifications Cyber Security Certifications (Required / Advantageous):
Certified Information Systems Security Professional (CISSP) – Broad cybersecurity expertise including risk management and third-party security. Certified Information Security Manager (CISM) – Information security management and risk governance. Certified in Risk and Information Systems Control (CRISC) – IT risk identification, assessment, and lifecycle management. Certified Third Party Risk Professional (CTPRP) – Specialized certification in TPRM frameworks and vendor assessment practices. ISO/IEC 27001 Lead Implementer – Designing and implementing ISMS controls in vendor assessment contexts.
AI & Data Certifications
Microsoft Certified: Azure AI Engineer Associate (AI-102) – Designing and implementing AI solutions relevant to risk automation. AWS Certified Machine Learning – Specialty – Understanding ML pipelines applicable to risk scoring models. Google Professional Machine Learning Engineer – ML model development and deployment for risk analytics. Certified Artificial Intelligence Practitioner (CAIP) – Applied AI concepts across business and risk domains.