Third Party Risk Management (TPRM) Manager - Cyber Risk & Resilience
Ernst & Young · Bengaluru/Bangalore, Karnataka
Ernst & Young · Bengaluru/Bangalore, Karnataka
FS-RISK CONSULTING-TPRM-Manager At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. FS TPRM - Manager: At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. About Global Delivery Services Global Delivery Services refers to EY's worldwide network of service delivery centers. The GDS team plays an important role in EY's strategy by ensuring effective support to EY's growth agenda. Our journey started in 2002 with approximately 200 people. Today we stand at 80,000 professionals in ten locations around the world. We operate in Argentina, China, Hungary, India, Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom. Client service is focused on providing Consulting, Assurance, Tax, Strategy \& Transactions, and Knowledge support to our clients around the world. The teams enable account teams worldwide to provide seamless, high-quality, value-added support, helping deliver exceptional client service. Enablement Services provides cost-effective, high-skilled, and innovative services to support EY's global and local enablement teams. Markets, BMC, AWS, Finance and Accounting, Risk Management, Procurement, People Shared Services, IT Service Delivery and IT Global Infrastructure services, are among the services offered by Enablement Services. Our innovation specialists serve the GDS Client Service and Enablement Services teams, along with Service Lines, Core Business Services and Sectors. The team brings the desired environment, technologies and skilled teams together for facilitation, rapid prototyping and innovative thinking. The competencies offered include analytics, digital, user experience, mobile technology, infrastructure, Microsoft technologies and open innovation. The Opportunity The Manager in the Digital Risk \& Resilience Advisory team will lead and oversee global cyber risk, transformation, and operational resilience engagements. The Manager will manage senior client relationships, ensure high quality delivery, guide large multidisciplinary teams, and contribute to business growth through thought leadership and solution development. Your Key Responsibilities Client Responsibilities: Lead end to end delivery of multiple cyber risk, cybersecurity, and resilience engagements, ensuring adherence to EY methodologies and quality standards. Own and manage senior level client relationships; deliver impactful, timely, and value driven outcomes. Demonstrate deep subject matter expertise across cybersecurity strategy, cyber risk management, operational resilience, information security governance, and regulatory expectations. Advise clients on cyber resilience, business continuity, disaster recovery, incident response readiness, and crisis management capabilities. Represent EY in senior stakeholder discussions, cyber risk workshops, resilience simulations, and executive level presentations. Identify business development opportunities across cyber risk, security transformation, and resilience services; contribute to proposals, solutioning, and go to market initiatives. Review, challenge, and approve deliverables prepared by seniors and staff to ensure technical accuracy and executive readiness. Oversee engagement financials, utilization, delivery timelines, and resource planning across global teams. Stay aligned with evolving cyber threats, resilience best practices, industry trends, and regulatory developments. People Responsibilities: Manage performance, development, mentoring, and career progression of cyber risk and resilience team members. Drive a strong quality culture, technical excellence, and compliance with EY delivery standards. Lead training, hiring, onboarding, and cyber capability building initiatives (technical, regulatory, and leadership). Foster a collaborative, high performance environment that encourages innovation and continuous improvement. Skills and attributes for success Mandatory skills: Advanced knowledge of cybersecurity, cyber risk management, information security governance, and operational resilience frameworks. Strong understanding of AI/ML security, Zero Trust architectures, cyber resilience, security architecture, cloud security, API security, and digital platform risks. Deep experience in threat modeling, secure SDLC, OWASP Top 10, vulnerability management, LAN/WAN reviews, OS and database security, IAM, cryptography, and endpoint security. Strong understanding of incident response, cyber recovery, business continuity management (BCM), disaster recovery (DR), and crisis management. Solid knowledge of regulatory and industry frameworks such as HIPAA, FISMA, MAS, NIST CSF, NIST 800‑53/61/92, ISO 27001/22301, PCI DSS, and HITRUST. Excellent stakeholder communication, executive‑level reporting, program governance, and project management skills. Mandatory Certifications (one or more): CISM, CISSP, CRISC, CISA, ISO 27001 Lead Auditor, or equivalent cyber/resilience certifications. Experience 10 years of experience in cybersecurity, cyber risk advisory, IT risk, information security, or operational resilience roles. Proven experience leading large cyber security or resilience programs and managing global, cross functional delivery teams. Experience engaging with CISO, CIO, CRO, and senior risk and technology leadership. Preferred skills: Strong domain experience in BFSI or other regulated sectors Experience designing or operating enterprise wide cyber risk management or cyber resilience programs. Exposure to resilience testing, scenario based cyber simulations, and regulatory examina