EY

GMS-Senior-MS-RSS

Join EY in Bengaluru as a Senior in Third-Party Risk Management. Leverage ServiceNow for TPRM engagements. 4-8 years of risk management experience required.

ServiceNow Role Type:
Department - JobBoardly X Webflow Template
Implementer
ServiceNow Modules:
Department - JobBoardly X Webflow Template
Governance, Risk, and Compliance
Department - JobBoardly X Webflow Template
IT Service Management
Department - JobBoardly X Webflow Template
Incident Management
Department - JobBoardly X Webflow Template
Third-Party Risk Management
ServiceNow Certifications (nice to have):
Department - JobBoardly X Webflow Template
Certified Implementation Specialist - Third-Party Risk Management

Job description

Date - JobBoardly X Webflow Template
Posted on:
 
June 10, 2025

Join EY as a Senior with expertise in Third-Party Risk Management to lead and work closely with the manager in the delivery of Third-Party Risk Management (TPRM) engagements.

Requirements

  • 4 to 8 years of demonstrated experience with Risk Management across the Third-Party engagement lifecycle (pre-contracting, contracting, and post contracting) and an understanding of the associated organizational infrastructure (e.g., relevant internal controls, business processes, governance structures).
  • Strong understanding of the TPRM framework, Risk Management, Information Security practices.
  • Demonstrate a good understanding of the Contract Risk Review management process.
  • Hands-on exposure to TPRM tools and technology solutions (e.g., GRC enablement solutions, such as Process Unity, Prevalent, Archer, ServiceNow, etc.).
  • Demonstrated knowledge of standards such as ISO 27001/2, ISO 22301, ISO 27018, PCI – DSS, HITRUST, etc.
  • Good knowledge of privacy regulations such as GDPR, CCPA, etc.
  • Good knowledge of regulations such as FISMA, HIPAA, Reg SCI, MAS, etc.
  • Good knowledge of TCP/IP, concepts of OSI layer and protocols, networking and security concepts, Physical & Environmental Security, Asset Security and Identity & Access Management.
  • Good knowledge of OS (Windows / Linux) security, Database security, IT infrastructure (switches, routers, firewalls, IDS, IPS, etc.), Security architecture design, and review.
  • Good familiarity with OWASP, and Secure SDLC standards/frameworks, anti-virus solutions (e.g., Symantec, McAfee, etc.).
  • Good experience in LAN/WAN architectures and reviews.
  • Good knowledge of incident management, disaster recovery, and business continuity management, cryptography.
  • Good to have prior Big-4 experience.
  • Good to have certifications - CISSP, CISA, CISM, CTPRP, CIPP, ISO 27001 Lead Auditor or Lead Implementer

Benefits

  • Support, coaching, and feedback from some of the most engaging colleagues around
  • Opportunities to develop new skills and progress your career
  • The freedom and flexibility to handle your role in a way that’s right for you

Requirements Summary

4-8 years of experience in Risk Management, strong understanding of TPRM framework, hands-on exposure to TPRM tools and technology solutions, and good knowledge of privacy regulations and standards