Search by job, company or skills

Third-Party Risk Management (TPRM)

Early Applicant
  • Posted 18 hours ago
  • Be among the first 10 applicants

Job Description

About KPMG in India

KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.

Role Purpose:

The Analyst/ Associate Consultant supports delivery of enterprise-wide Third-Party Risk Management (TPRM) engagements, focusing on execution support across the end-to-end vendor lifecycle. The role emphasizes foundational cyber/ information security risk knowledge, documentation quality, communication clarity, and learning agility. Prior deep TPRM experience is not mandatory.

Key Responsibilities:

Support execution of end-to-end TPRM lifecycle activities, including vendor onboarding risk assessments, periodic vendor reviews, continuous monitoring activities.

Assist in risk identification, risk assessment, and basic risk scoring across information security risk, operational risk, business continuity risk.

Review and analyze third-party artifacts, such as security policies and procedures, ISO certifications and SOC reports, vendor documentation and questionnaires.

Support risk issue tracking, remediation follow-ups, and closure documentation

Assist in development and maintenance of TPRM policies and procedures, risk assessment documentation, risk registers and reports.

Coordinate with internal stakeholders and vendors to follow up on information requests, support assessment timelines, clarify risk-related queries.

Knowledge & Experience Requirements - Mandatory

2–4 years of hands-on experience in TPRM/ vendor risk management/ cybersecurity/ information security risk

Strong understanding of risk assessment, risk management, risk monitoring, and risk mitigation concepts

Practical experience with due diligence, vendor onboarding, and third-party lifecycle management

Understanding of cybersecurity and information security risk management

Experience reviewing ISO 27001, SOC reports, policies, and control documentation

Good understanding of regulatory compliance expectations and their impact on third-party risk

Strong stakeholder communication and documentation skills

Knowledge & Experience Requirements - Preferred

Experience with vendor relationship management and continuous monitoring

Exposure to contract risk management, SLAs, and performance metrics

Experience with key risk indicators (KRIs), risk scoring modules, and process improvement

Exposure to business continuity planning, operational risk, and procurement risk management

Experience in regulated industries (BFSI, fintech, healthcare, etc.)

Education:

Bachelor's degree in Engineering, IT, Computer Science, or related discipline

Post-graduation highly preferred

Certifications (Preferred, not mandatory)

ISO 27001 Lead Auditor/ Lead Implementer

CTPRM, CISA, CISM, CISSP, CRISC, CCSP, CRM or equivalent

Any mid-level cyber/ risk/ governance certification

Equal employment opportunity information

KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152935057

Similar Jobs

Bengaluru, India

Skills:

security plus Information SecurityCismIt AuditSecurity frameworksCompliance certificationsThird-Party Risk ManagementCisaVendor risk assessment methodologiesPenetration testsGRC platformsCisspSOC reportsCRISC

Bengaluru, India

Skills:

security plus Information SecurityCismIt AuditSecurity frameworksCompliance certificationsCisaThird-Party Risk ManagementVendor risk assessment methodologiesPenetration testsGRC platformsCisspSOC reportsCRISC

Beware of Scammers

We don’t charge money for job offers