The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
Third-Party Risk Management * Supplier Due Diligence * Risk Assessment & Analysis * Control Effectiveness Reviews * Cybersecurity & Information Security Risk * Compliance & Governance * Stakeholder ...
Third-Party Risk Management * Supplier Due Diligence * Risk Assessment & Analysis * Control Effectiveness Reviews * Cybersecurity & Information Security Risk * Compliance & Governance * Stakeholder ...
Principal Program Manager
Reston, VA · On-site
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
Principal Program Manager
Reston, VA · On-site
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
Principal Program Manager
Reston, VA · On-site
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
Principal Program Manager
Reston, VA · On-site
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
Enterprise Risk Analyst
Manassas, VA · On-site
$45.66/hr
... and third parties to facilitate enterprise risk analysis Ability to obtain and maintain a Public ... GRC) Experience with Assessment and Authorization (A&A) and eMASS Experience with Excel and Visio ...
Enterprise Risk Analyst
Manassas, VA · On-site
$45.66/hr
... and third parties to facilitate enterprise risk analysis Ability to obtain and maintain a Public ... GRC) Experience with Assessment and Authorization (A&A) and eMASS Experience with Excel and Visio ...
Enterprise Risk Analyst
Manassas, VA · On-site
$64.47/hr
... and third parties to facilitate enterprise risk analysis Ability to obtain and maintain a Public ... GRC) Experience with Assessment and Authorization (A&A) and eMASS Experience with Excel and Visio ...
Enterprise Risk Analyst
Manassas, VA · On-site
$64.47/hr
... and third parties to facilitate enterprise risk analysis Ability to obtain and maintain a Public ... GRC) Experience with Assessment and Authorization (A&A) and eMASS Experience with Excel and Visio ...
Enterprise Risk Analyst
VA · On-site
$56.52/hr
Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis ... Experience with Governance, Risk, and Compliance (GRC) * Experience with Assessment and ...
Enterprise Risk Analyst
VA · On-site
$56.52/hr
Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis ... Experience with Governance, Risk, and Compliance (GRC) * Experience with Assessment and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
Work within the Logic Manager (GRC) platform * Support metrics and reporting focused on issues and ... Experience in working with all levels of staff, management, stakeholders, and third parties
Work within the Logic Manager (GRC) platform * Support metrics and reporting focused on issues and ... Experience in working with all levels of staff, management, stakeholders, and third parties
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
Information Security Analyst (Risk & Compliance)
Richmond, VA · On-site
$70K - $100K/yr
Support PFG's Third Party Risk Management Program, assessing third parties for inherent and ... impact analysis, designing and implementing Business Continuity/Disaster Recovery plans • ...
New
Information Security Analyst (Risk & Compliance)
Richmond, VA · On-site
$70K - $100K/yr
Support PFG's Third Party Risk Management Program, assessing third parties for inherent and ... impact analysis, designing and implementing Business Continuity/Disaster Recovery plans • ...
New
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ... Business analysis skills including requirements gathering, process mapping, gap analysis, and ...
Quick apply
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ... Business analysis skills including requirements gathering, process mapping, gap analysis, and ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ... Business analysis skills including requirements gathering, process mapping, gap analysis, and ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ... Business analysis skills including requirements gathering, process mapping, gap analysis, and ...
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ... Business analysis skills including requirements gathering, process mapping, gap analysis, and ...
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ... Business analysis skills including requirements gathering, process mapping, gap analysis, and ...
Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ... Experience in Governance, Risk & Compliance (GRC) programs * Knowledge of third-party risk ...
Quick apply
Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ... Experience in Governance, Risk & Compliance (GRC) programs * Knowledge of third-party risk ...
Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ... Experience in Governance, Risk & Compliance (GRC) programs * Knowledge of third-party risk ...
Quick apply
Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ... Experience in Governance, Risk & Compliance (GRC) programs * Knowledge of third-party risk ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Grc Third Party Risk Analyst information
What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?
What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?
What is a GRC Third Party Risk Analyst?
What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?
| Aspect | Grc Third Party Risk Analyst | Grc Vendor Risk Analyst |
|---|---|---|
| Certifications | Certifications like CRISC, CISA often preferred | Same certifications commonly required |
| Work Environment | Focuses on third-party relationships and risk assessments | Primarily evaluates vendor-specific risks and compliance |
| Industry Usage | Used across finance, healthcare, and tech sectors | Commonly found in industries with extensive vendor networks |
The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

Full-time
Re-posted 20 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.
At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.
Recruiting for this role ends on May 31, 2027
Work you'll doThe Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.
Responsibilities include:
- Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
- Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
- Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
- Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
- Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
- Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.
A successful candidate would possess these skills:
- Strong communicator with the ability to tailor messages for technical and non-technical audiences.
- Collaborative relationship builder who works effectively across functions and levels to drive alignment.
- Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams.
- Confident facilitator who influences without authority and helps move issues to resolution.
The Team
Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients.
Qualifications
Required:
- Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
- Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
- 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
- Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
- Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
- Limited immigration sponsorship may be available.
- Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
- One of the following active accreditations obtained:
- Licensed CPA in state of practice/primary office if eligible to sit for the CPA
- If not CPA eligible:
- Licensed Attorney
- Enrolled Agent
- CBAP - Certified Business Analysis Professional
- Certified in Risk and Information System Controls (CRISC)
- Microsoft Azure
- Project Management Professional (PMP)
Preferred:
- Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes.
- Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences.
- Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels.
- Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs.
- Experience supporting business process improvement, transformation, or technology-enabled change initiatives.
- Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.
At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.
Recruiting for this role ends on May 31, 2027
Work you'll doThe Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.
Responsibilities include:
- Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
- Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
- Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
- Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
- Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
- Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.
A successful candidate would possess these skills:
- Strong communicator with the ability to tailor messages for technical and non-technical audiences.
- Collaborative relationship builder who works effectively across functions and levels to drive alignment.
- Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams.
- Confident facilitator who influences without authority and helps move issues to resolution.
The Team
Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients.
Qualifications
Required:
- Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
- Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
- 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
- Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
- Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
- Limited immigration sponsorship may be available.
- Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
- One of the following active accreditations obtained:
- Licensed CPA in state of practice/primary office if eligible to sit for the CPA
- If not CPA eligible:
- Licensed Attorney
- Enrolled Agent
- CBAP - Certified Business Analysis Professional
- Certified in Risk and Information System Controls (CRISC)
- Microsoft Azure
- Project Management Professional (PMP)
Preferred:
- Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes.
- Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences.
- Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels.
- Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs.
- Experience supporting business process improvement, transformation, or technology-enabled change initiatives.
- Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.