Third-Party Risk Management, Senior Consultant

Cyber Risk | Cyber & Strategic Risk
Same job available in 12 locations

Position Summary

Position Summary

When you join the Deloitte Advisory Extended Enterprise Risk Management (EERM) practice, you will see how we work with some of the largest organizations in the world, across a variety of industries, to assist organizations in the development and operation of third-party programs, whether related to vendors, customers, suppliers, licensees or partners. Our client list includes eminent organizations across industries, e.g. technology, mining, media, pharmaceuticals, oil and gas, public sector and charities.

The work you perform will help you develop an understanding of:

  • the different third-party relationships an organization may have across different industries;
  • the drivers which affect behaviors of business partners, suppliers and customers; and
  • the operational processes and controls required by an organization to effectively manage and monitor its third-party relationships.

 Our EERM portfolios of services includes a broad variety of solutions for our clients, including

  • designing and implementing broad third-party governance and risk management frameworks/processes,
  • developing third-party risk and control assessments,
  • creating strategies related to operational and financial compliance
  • assisting with third party management technology (e.g., GRC solutions)
  • supporting clients in execution of their third-party programs through such things as royalty inspections, most favored nation/customer compliance inspections, software compliance and more.

Given the ever increasing size and complexity of third-party ecosystems, our clients are increasing leveraging our firm’s expertise to implement and operate a wide variety of third party solutions designed to mitigate risks and drive more value in third party relationships.


Support the design and implementation of third-party risk operating models and technology platforms, identifying, evaluating, and providing solutions to evaluate complex business and technology risks

Design policies and procedures that support the successful implementation of third-party risk management operating models

Perform analysis to identify contract compliance issues such as those related to software entltlement analysis or royalty compliance and cost recovery

Facilitate process walkthrough discussions to document end-to-end business processes and functional requirements

Consider the application of legal and regulatory requirements to company’s risk management practices.

Design technology enhancement requirements to support third-party risk management processes.

Participate and lead client projects around designing, building, testing, integrating, and implementing third party tools/platforms (such as ServiceNow, Coupa Risk, Archer, Aravo etc) to help develop practical solutions

Participate and lead client projects around configuring and enhancing Software Asset Management (SAM), SaaS / Cloud Management and Software License Compliance tools (such as ServiceNow, Productiv, Flexera, Big Fix Inventory, IBM License Metric etc) to help develop accurate reportings.

Work and consult with client technical/functional teams to design and implement solutions enhancements to optimize performance

Drive execution of third-party compliance/software inspections (virtual or onsite)

Track and communicate engagement performance and planning to Deloitte engagement management, ensuring project milestones remain on track and are completed timely

Create architecture PoV documents to describe the architecture types (app, data, integration, security), purposes, guiding principles, preferred architecture patterns, related technologies, and role

Apply smart automation and digital solutions, including Robotic Process Automation (RPA) and Artificial Intelligence (AI)

Perform sophisticated data analyses to understand client’s business and identify risk

Understand client’s business environment and basic risk management approaches

Demonstrate a general knowledge of market trends, competitor activities, Deloitte & Touche’s products and service lines

Generate innovative ideas and challenge the status quo

Build and nurture positive working relationships with clients with the intention to exceed client expectations

Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services

Identify opportunities to improve engagement profitability

Excellent potential for 1. playing lead role in designated tasks of the project team in gathering, organizing and analyzing data; 2. making major contributions in assuring products/deliverables meet contract/work plan; and 3. strong potential for growth and acceptance of additional responsibilities

Applicants need the ability to adopt a pragmatic approach to dealing with situations where confidentiality is important or where our work is of a sensitive nature. Helping maintain our client’s strong professional relationships is integral to our business


  • 3+ years’ experience within professional services or related roles within industry
  • 3+ years of demonstrated experience with risk management across the third-party engagement lifecycle (pre-contracting, contracting and post contracting) and an understanding of the associated organizational infrastructure (e.g. relevant internal controls, business processes, governance structures)
  • 3+ years of experience in one or more of the following:
    • - Business process and organizational design (e.g. process mapping, workflows, governance structures across the three lines of defense, process and enterprise level RACIs)
    • - Procurement / supply chain process assessment and design (and other third- party engagement processes not typically within procurement remit, e.g. distributor relationships)
    • - Third party assessment experience, including things such as compliance inspections, IRQ, current state assessments, and other
    • - Third Party Risk Management tools and technology solutions (e.g. GRC enablement solutions, etc.)
    • - Third Party Risk Management market utilities (e.g. community models)
    • - Framework testing (e.g. Process UAT, design of testing scripts and testing plans, etc.)
    • Software compliance, entitlement models (perpetual, term, SaaS), install / usage discovery and metering, and license optimization across multiple software vendors
  • Demonstrated solid functional and technical knowledge of the various TPRM tools program components and be able to resolve both functional and technical issues
  • Experience in change management and/or managed service solution design and implementation a plus 
  • BA/BS in Business Administration, Supply Chain, Accounting/Finance, Engineering, Computer Science, Information Management Systems or related fields
  • Strong written and verbal communication skills
  • Ability to travel up to 50% (While up to 50% travel is a requirement of the role, due to COVID-19, non-essential travel has been suspended until further notice)
  • Limited immigration sponsorship may be available

For individuals assigned and/or hired to work in Colorado, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to the State of Colorado and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and delivery model. We would not anticipate that the individual hired into this role would land at or near the top end of the range, but such a decision will be dependent on the facts and circumstances of each case. A reasonable estimate of the range is $114,600 to $125,000.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.        

Our people and culture

Our diverse, equitable, and inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our client most complex challenges. This makes Deloitte one of the most rewarding places to work. Learn more about our inclusive culture.

Professional development

From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career. Learn more about our commitment to developing our people.

As used in this posting, "Deloitte Advisory" means Deloitte & Touche LLP, which provides audit and enterprise risk services; Deloitte Financial Advisory Services LLP, which provides forensic, dispute, and other consulting services; and its affiliate, Deloitte Transactions and Business Analytics LLP, which provides a wide range of advisory and analytics services. Deloitte Transactions and Business Analytics LLP is not a certified public accounting firm. Please see for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. These entities are separate subsidiaries of Deloitte LLP.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Requisition code: 13987


Caution against fraudulent job offers!

We have been informed of instances where jobseekers are led to believe of fictitious job opportunities with Deloitte US (“Deloitte”). In one or more such cases, false promises of actual or potential selection, or initiation or completion of the recruitment formalities appear to have been or are being made. Some jobseekers appear to have been asked to pay money to specified bank accounts of individuals or entities as a condition of their selection for a ‘job’ with Deloitte. These individuals or entities are in no way connected with Deloitte and do not represent or otherwise act on behalf of Deloitte.

We would like to clarify that:

  • At Deloitte, ethics and integrity are fundamental and not negotiable.
  • We are against corruption and neither offer bribes nor accept them, nor induce or permit any other party to make or receive bribes on our behalf.
  • We have not authorized any party or person to collect any money from jobseekers in any form whatsoever for promises of getting jobs in Deloitte.
  • We consider candidates on merit and that we provide an equal opportunity to eligible applicants.
  • No one other than designated Deloitte personnel (e.g., a Deloitte recruiter or Deloitte hiring partner) is permitted to extend any job offer from Deloitte.

Anyone who at any time has made or makes any payment to any party in exchange for promises of job or selection for a job with Deloitte or any matter related to this (including those for ‘registration’, ‘verification’ or ‘security deposit’) or otherwise engages with any such person who has made or makes fraudulent promises or offers, does so (or has done so) entirely at their own risk. Deloitte takes no responsibility or liability for any such unauthorized or fraudulent actions or engagements. We encourage jobseekers to exercise caution.