About this role
<p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. </span></span></p> <p> </p> <p> </p> <p> </p> <p> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Senior Consultant – AI Third Party Risk Consultant</strong></span></p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Experience: 4–8 Years</strong></span></p> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Role Summary</strong></span></p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">The Senior Consultant – AI Third Party Risk Consultant is responsible for independently managing Third Party Security Assessment (TPSA) engagements across complex vendor ecosystems. The role demands deep expertise in TPRM frameworks, supply chain security, and risk lifecycle management, combined with active use of AI-enabled tools for vendor scoring, risk prediction, and control monitoring. The Senior Consultant provides technical depth to assessment delivery, contributes to methodology design, and supports junior analysts in executing high-quality risk evaluations across diverse industry sectors.</span></p> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Key Responsibilities</strong></span></p> <ul> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Lead and independently execute Third Party Security Assessments (TPSA) across critical, high-risk, and strategic vendor portfolios.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Conduct comprehensive vendor due diligence including control gap analysis, regulatory compliance validation, and risk-tiered scoring.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Manage the full risk assessment lifecycle — from vendor onboarding due diligence through periodic reviews, escalation management, and exit risk assessments.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Design and refine vendor risk questionnaires, assessment frameworks, and scoring rubrics aligned to industry standards (ISO 27001, NIST CSF, SOC 2, DORA).</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Perform supply chain risk analysis by identifying nth-party dependencies, concentration risks, and critical vendor failure scenarios.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Apply AI-enabled vendor risk scoring platforms to prioritize assessments and identify emerging threats.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Leverage predictive modelling and AI-assisted analytics to forecast vendor risk trajectories and recommend proactive controls.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Collaborate with procurement, legal, and business stakeholders to embed TPRM controls into vendor contracting and onboarding processes.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Prepare detailed risk assessment reports, risk ratings, and remediation recommendations for both technical and executive audiences.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Support the implementation of TPRM automation workflows and AI-driven continuous monitoring capabilities.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Mentor and guide Staff-level analysts, reviewing work quality and providing technical guidance.</span></li> </ul> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Education / Certifications</span></strong></p> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Bachelor’s degree in engineering, Technology, Business, Risk Management, or related disciplines.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Relevant certifications are advantageous (e.g., ISO 42001, CISSP, CISM, CRISC, ISO 27001 Lead Implementer, CTPRP, or equivalent).</span></li> </ul> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">AI & Cyber Certifications</span></strong></p> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Cyber Security Certifications (Required / Advantageous):</span></strong> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Certified Information Systems Security Professional (CISSP) – Broad cybersecurity expertise including risk management and third-party security.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Certified Information Security Manager (CISM) – Information security management and risk governance.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Certified in Risk and Information Systems Control (CRISC) – IT risk identification, assessment, and lifecycle management.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Certified Third Party Risk Professional (CTPRP) – Specialized certification in TPRM frameworks and vendor assessment practices.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">ISO/IEC 27001 Lead Implementer – Designing and implementing ISMS controls in vendor assessment contexts.</span></li> </ul> </li> </ul> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">AI & Data Certifications:</span></strong> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Microsoft Certified: Azure AI Engineer Associate (AI-102) – Designing and implementing AI solutions relevant to risk automation.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">AWS Certified Machine Learning – Specialty – Understanding ML pipelines applicable to risk scoring models.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Google Professional Machine Learning Engineer – ML model development and deployment for risk analytics.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Certified Artificial Intelligence Practitioner (CAIP) – Applied AI concepts across business and risk domains.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">ISACA Certified Data Privacy Solutions Engineer (CDPSE) – Data privacy risk and AI data governance.</span></li> </ul> </li> </ul> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Skills & Experience</span></strong></p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Required Skills and Experience:</span></strong></p> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">4–8 years of experience in third-party risk management, cyber risk, or information security consulting.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Proven experience executing end-to-end Third-Party Security Assessments across diverse vendor types (cloud, IT, operational).</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">In-depth knowledge of TPRM frameworks including NIST SP 800-161, ISO 27036, and sector-specific regulatory requirements.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Strong understanding of supply chain risk management including vendor tiering, concentration risk, and dependency mapping.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Use of AI in TPRM processes. Like using AI for assessor evaluation, writing issue descriptions and risk mitigation plans</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Understanding risk from third parties using AI to provide services to client. Looking into AI governance and AI security</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Understanding risk from third parties using AI Agents to provide services to client. Looking into AI governance and AI security</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Use of AI in TPRM processes. Like using AI Agents to build automations in TPRM processes</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Understanding how things like Frontier AI and Mythos will change cybersecurity Lense and how third parties are protecting themselves from these modern threats</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience managing the risk assessment lifecycle including risk identification, rating, mitigation planning, and remediation tracking.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Ability to conduct control gap analysis against ISO 27001, SOC 2, NIST CSF, CIS Controls, and PCI DSS.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience working with GRC platforms for workflow management and risk tracking.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Strong analytical, written, and presentation skills for technical and non-technical audiences.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Hands-on experience with AI-enabled vendor risk scoring tools and external threat intelligence platforms.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Exposure to predictive modelling techniques applied to vendor risk prioritization and breach likelihood scoring.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Understanding of AI-driven control monitoring frameworks and machine learning-improved continuous assessment cycles.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Familiarity with Graph AI concepts for mapping vendor networks and identifying supply chain concentration risks.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Awareness of NLP-based document analysis tools for automated questionnaire review and evidence validation.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience using data analytics and BI tools (Power BI, Tableau, Python) to build risk dashboards.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Knowledge of AI governance frameworks and ethical AI risk considerations relevant to vendor AI system assessments.</span></li> </ul> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">AI Tools Skillset</span></strong></p> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Vendor Intelligence & Risk Scoring Platforms:</span></strong> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">BitSight / Security Scorecard / RiskRecon – Active use for real-time vendor cyber ratings, issue tracking, and continuous monitoring feeds.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Prevalent / ProcessUnity / OneTrust VRM – End-to-end vendor risk assessment workflows, questionnaire management, and risk scoring.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">UpGuard – Vendor surface attack monitoring and data breach detection integrated into TPRM workflows.</span></li> </ul> </li> </ul> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">AI-Enabled Assessment & Automation Tools:</span></strong> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Coupa Risk Assess / Ariba Risk – AI-assisted supplier risk evaluation and procurement-integrated due diligence.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Armorblox / Darktrace – Awareness of AI-driven anomaly detection applicable to vendor environment assessments.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">ChatGPT / Microsoft Copilot for Risk – Drafting risk reports, summarizing vendor evidence, and accelerating assessment documentation.</span></li> </ul> </li> </ul> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">GRC & Workflow Automation:</span></strong> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">ServiceNow GRC / Archer – Risk workflow management, assessment tracking, and automated risk register maintenance.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Power Automate / Zapier – Automating vendor questionnaire distribution, evidence collection reminders, and reporting workflows.</span></li> </ul> </li> </ul> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Data Analytics & Visualization:</span></strong> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Microsoft Power BI / Tableau – Building vendor risk dashboards, heat maps, and trend analysis reports.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Excel Power Query / Python (Pandas) – Risk data cleansing, vendor scoring model inputs, and assessment data aggregation.</span></li> </ul> </li> </ul> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 0.0in 0.25in;font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Leadership & Behavioral Expectations</span></strong></p> <ul> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Deliver assigned assessment modules with quality, accuracy, and timeliness.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Collaborate effectively with cross-functional teams including procurement, legal, IT, and business stakeholders.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Demonstrate learning agility and proactively expand skills in AI-enabled risk management.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Support continuous improvement of TPRM methodologies, templates, and automation initiatives.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Communicate risk findings clearly and constructively to vendor stakeholders and internal clients.</span></li> <li style="font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Show initiative in identifying process improvement opportunities and contributing to practice development.</span></li> </ul><p> </p> <p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"><b>EY | Building a better working world </b></span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. </span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. </span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. </span></span></p>