About this role
<p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt"><strong>Are you ready to unleash your potential?</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">At Deloitte, our purpose is to make an impact that matters for our clients, our people, and the communities we serve. </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">We believe we have a responsibility to be a force for good, and WorldImpact is our portfolio of initiatives focused on making a tangible impact on society’s biggest challenges and creating a better future. We strive to advise clients on how to deliver purpose-led growth and embed more equitable, inclusive as well as sustainable business practices. </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Hence, we seek talented individuals driven to excel and innovate, working together to achieve our shared goals. </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">We are committed to creating positive work experiences that foster a culture of respect and inclusion, where diverse perspectives are celebrated, and everyone is recognised for their contributions.</span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Ready to unleash your potential with us? Join the winning team now!</span></p> <p><span style="font-size:14.0pt"><strong>Work You Will Do</strong></span></p> <p><span style="font-size:14.0pt">As a <strong>GRC Technology Consultant</strong>, you will be part of our Governance, Risk, and Compliance (GRC) team, supporting the delivery of <strong>technology-enabled risk transformation projects</strong>. In this role, you will perform a <strong>functional consultant capacity</strong> by gathering business requirements, contributing to the design, implementation, and enhancement of the <strong>Third Party Risk Management (TPRM) module</strong> within our GRC platform.</span></p> <p><span style="font-size:14.0pt">You will act as a bridge between business stakeholders, risk management teams, and the system implementation team, ensuring effective design, testing, and deployment of TPRM functionalities. Your work will align with established risk management frameworks, regulatory requirements, and industry best practices to enable a robust and sustainable risk management environment.</span></p> <p> </p> <p><span style="font-size:14.0pt"><strong>Key Responsibilities</strong></span></p> <p><span style="font-size:14.0pt">• Gather business and regulatory requirements from stakeholders.</span></p> <p><span style="font-size:14.0pt">• Provide advisory on Operational Risk Management to support good design of system functionality to ensure design aligning with relevant regulatory requirement and good practice.</span></p> <p><span style="font-size:14.0pt">o Third Party Risk Management Framework</span></p> <p><span style="font-size:14.0pt">o Third Party Risk Management Workflow from end to end including classification based on Bank of Thailand requirement or relevant regulation, Due Diligence & Risk Assessment, Monitoring & Ongoing, Termination & Offboarding Process, and Reporting for internal purpose and regulatory report. </span></p> <p><span style="font-size:14.0pt">o Third Party Risk Indicators</span></p> <p><span style="font-size:14.0pt">o Third Party and Vendor Inventory</span></p> <p><span style="font-size:14.0pt">o Third Party Risk and Control Inventory</span></p> <p><span style="font-size:14.0pt">o Third Party Risk Dashboard</span></p> <p><span style="font-size:14.0pt">• Translate requirements into system specifications and user stories.</span></p> <p><span style="font-size:14.0pt">• Prepare documentation including Requirement Traceability Matrix (RTM), Functional Specification Document (FSD), and process flows.</span></p> <p><span style="font-size:14.0pt">• Support design, configuration, and integration of the TPRM module within the GRC platform.</span></p> <p><span style="font-size:14.0pt">• Develop and execute test cases and UAT scripts for TPRM module.</span></p> <p><span style="font-size:14.0pt">• Support accuracy and completeness of data migration and system outputs.</span></p> <p><span style="font-size:14.0pt">• Document test results, track defects, and support resolution.</span></p> <p><span style="font-size:14.0pt">• Create training materials such as manuals, quick guides, and e-learning modules.</span></p> <p><span style="font-size:14.0pt">• Deliver user training sessions and provide adoption support.</span></p> <p><span style="font-size:14.0pt"><strong>Qualifications</strong></span></p> <p><span style="font-size:14.0pt">• Bachelor’s or master’s degree in business administration, Risk Management, Finance, Information Systems, or related field.</span></p> <p><span style="font-size:14.0pt"><em>For Senior Consultant Level</em></span></p> <p><span style="font-size:14.0pt">• 5–8 years of experience in GRC, Internal Audit, or Risk Advisory, preferably in the financial services sector.</span></p> <p><span style="font-size:14.0pt">• Strong knowledge of ORM frameworks (COSO ORM, ISO 31000) and regulatory standards (Basel II/III, BOT including requirement for IT Third-Party and Business Partner).</span></p> <p><span style="font-size:14.0pt">• Experience with GRC platforms (RSA Archer, SAP GRC, MetricStream, or equivalent) is a plus.</span></p> <p><span style="font-size:14.0pt">• Archer Certified Administrator (Specialist/Expert), ServiceNow CIS (Risk & Compliance), or equivalent certification is a plus.</span></p> <p><span style="font-size:14.0pt">• Proficiency in business analysis, documentation, and stakeholder facilitation.</span></p> <p><span style="font-size:14.0pt">• Strong problem-solving, analytical, and communication skills.</span></p> <p><span style="font-size:14.0pt">• Professional certifications such as GRC, CISA, CRISC, CISM, CISSP are highly desirable.</span></p> <p><span style="font-size:14.0pt">Technical Skills</span></p> <p><span style="font-size:14.0pt">• Exposure to GRC/IRM platforms such as Archer, ServiceNow, or MetricStream.</span></p> <p><span style="font-size:14.0pt">• Understanding of workflows, reporting, and dashboard.</span></p> <p><span style="font-size:14.0pt">• Proficiency in Microsoft Excel and PowerPoint for analysis and reporting.</span></p> <p><span style="font-size:14.0pt">Soft Skills</span></p> <p><span style="font-size:14.0pt">• Analytical and detail-oriented mindset with the ability to work on multiple projects simultaneously.</span></p> <p><span style="font-size:14.0pt">• Strong written and verbal communication, able to engage both technical and business stakeholders.</span></p> <p><span style="font-size:14.0pt">• Team-oriented with a willingness to learn and adapt to dynamic client environments.</span></p> <p><span style="font-size:14.0pt">• Ability to work in structured consulting environments with deadlines and deliverables.</span></p> <p><span style="font-size:14.0pt"><strong>Industry Focus: FSI</strong></span></p> <p><span style="font-size:14.0pt">Exposure to banking, asset management, digital asset, insurance, and financial services risk and compliance processes. Understanding of significant risk and compliance domain for specific industry.<strong> </strong></span></p> <p style="margin:0.0in;font-size:10.0pt;font-family:Aptos, sans-serif"> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt"><strong>Due to volume of applications, we regret only shortlisted candidates will be notified.</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt"><strong>Please note that Deloitte will never reach out to you directly via messaging platforms to offer you employment opportunities or request for money or your personal information. Kindly apply for roles that you are interested in via this official Deloitte website.</strong></span></p>