Cyber IT Risk Management_Third-Party Risk Management (TPRM)_Senior Soultion Delivery Lead
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte's Financial Risk Services could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber Risk Services team and support the transition to an executive-led cyber risk program that balances requirements to be secure, vigilant, and resilient in line with the risk appetite of the organization Work you'll do
When you join Cyber Risk Services as a Senior Consultant in Third-Party Risk Management (TPRM) Managed Services team, you will see how we work with some of the largest organizations in the world, across a variety of industries. Our client list includes eminent organizations across industries, e.g. technology, mining, media, pharmaceuticals, oil and gas, public sector and charities.
The work you perform will help you develop an understanding of:
- Support and manage the different third-party relationships an organization may have across different industries.
- Support and manage the drivers which affect behaviors of business partners, suppliers and customers.
- Support and manage the operational processes and controls required by an organization to effectively manage and monitor its third-party relationships.
TPRM offers a broad variety of solutions for our clients, e.g., designing and implementing cyber and broader third-party governance, risk management frameworks, and process flows, des developing third-party cyber control assessments, and considering how clients can leverage managed services to improve/enhance their TPRM program.
These are some examples of our common offerings, but in reality, because of the wide-ranging organizational impact that TPRM has, there is a great variety of solutions we offer to clients in the TPRM space. Responsibilities:
- Support the design and implementation TPRM to support our client's Third-Party Risk operating models
- Facilitate process walkthrough discussions to document end-to-end business processes and functional requirements
- Consider the application of legal and regulatory requirements to company's risk management practices.
- Design technology enhancement requirements to support third-party risk management processes.
- Track and communicate engagement performance and planning to Deloitte engagement management, ensuring project milestones remain on track and are completed timely
- Actively mentor and train team members on Third Party Risk Management processes, governance, and frameworks
- Work cross-functionally with team members to support and drive a collaborative team environment
- Create and design effective presentations as a means for communicating project and deliverable progress to clients
- Perform sophisticated data analyses to understand client's business and identify risk
- Execute advanced services and supervise staff in delivering basic services
- Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects
- Understand client's business environment and basic risk management approaches
- Demonstrate a general knowledge of market trends, competitor activities, Deloitte & Touche's products and service lines
- Actively participate in decision making with engagement management and seek to understand the broader impact of current decisions
- Generate innovative ideas and challenge the status quo
- Build and nurture positive working relationships with clients with the intention to exceed client expectations
- Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services
- Identify opportunities to improve engagement profitability
- Excellent potential for 1. playing lead role in designated tasks of the project team in gathering, organizing and analyzing data; 2. making major contributions in assuring products/deliverables meet contract/work plan; and 3. strong potential for growth and acceptance of additional responsibilities
- Applicants need the ability to adopt a pragmatic approach to dealing with situations where confidentiality is important or where our work is of a sensitive nature. Helping maintain our client's strong professional relationships is integral to our business.
How you'll grow
- 5 equal years' of experience within professional services or related roles within industry
- 5+ years of demonstrated experience with cyber risk management across the third-party engagement lifecycle (pre-contracting, contracting and post contracting) and an understanding of the associated organizational infrastructure (e.g. relevant internal controls, business processes, governance structures)
- 5+ years of experience in one or more of the following:
- Third party Cyber Assessment experience
- Third Party Risk Management tools and technology solutions (e.g. GRC enablement solutions, etc.)
- Third Party Risk Management market utilities (e.g. community models)
- Framework testing (e.g. Process UAT, design of testing scripts and testing plans, etc.)
- Business process and organizational design (e.g. process mapping, workflows, governance structures across the three lines of defense, process and enterprise level RACIs)
- Procurement / supply chain process assessment and design (and other third- party engagement processes not typically within procurement remit, e.g. distributor relationships)
- Experience in change management and/or managed service solution design and implementation a plus
- Preferred: BA/BS in Business Administration, Supply Chain, Accounting/Finance, Engineering, Computer Science, Information Management Systems or related fields
- Willingness to travel 80% of the time (Monday - Thursday) on a weekly base.
- Preferred: Previous Consulting or Big 4 experience
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
At Deloitte, our professional development plan focuses on helping people at every level of their career to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career. Benefits
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Deloitte's culture
Our positive and supportive culture encourages our people to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them to be healthy, centered, confident, and aware. We offer well-being programs and are continuously looking for new ways to maintain a culture where our people excel and lead healthy, happy lives. Corporate citizenship
Deloitte is led by a purpose: to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our people and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Deloitte's impact on the world. Recruiter tips
We want job seekers exploring opportunities at Deloitte to feel prepared and confident. To help you with your interview, we suggest that you do your research: know some background about the organization and the business area you're applying to. Check out recruiting tips from Deloitte professionals.
As used in this posting, "Deloitte Advisory" means Deloitte & Touche LLP, which provides audit and enterprise risk services; Deloitte Financial Advisory Services LLP, which provides forensic, dispute, and other consulting services; and its affiliate, Deloitte Transactions and Business Analytics LLP, which provides a wide range of advisory and analytics services. Deloitte Transactions and Business Analytics LLP is not a certified public accounting firm. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. These entities are separate subsidiaries of Deloitte LLP.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Deloitte will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws. See notices of various ban-the-box laws where available. https://www2.deloitte.com/us/en/pages/careers/articles/ban-the-box-notices.html
Requisition code: E20NATARSCBE032