Apply now »

TC-CS-SRCR-Manager-Supply Chain and Third-Party Risk Management

Location:  Bengaluru
Other locations:  Anywhere in Country
Salary: Competitive
Date:  Sep 3, 2026

Job description

Requisition ID:  1723206

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Manager – AI Third Party Risk Analytics & Monitoring Lead

 

 

Experience: 8–12 Years

 

 

Role Summary

 

The Manager – AI Third Party Risk Analytics & Monitoring Lead is responsible for leading the analytics and continuous monitoring capabilities within the Third Party Risk Management (TPRM) practice. The role combines deep expertise in vendor risk management and supply chain security with advanced AI-enabled analytics competencies including predictive modelling, AI-driven scoring, and Graph AI for vendor ecosystem intelligence. The Manager owns the development and operationalization of risk monitoring frameworks, manages a team of risk analysts, and serves as the analytics subject matter expert for TPRM engagements.

 

 

Key Responsibilities

 

  • Lead the design and implementation of AI-powered TPRM continuous monitoring frameworks, including automated vendor risk alerting and real-time dashboard capabilities.
  • Develop and manage AI-enabled vendor risk scoring models that incorporate external threat intelligence, financial health data, and control assessment outcomes.
  • Apply predictive modelling techniques to forecast vendor risk trajectories, breach probabilities, and supply chain disruption scenarios.
  • Deploy Graph AI methodologies to map complex vendor ecosystems, identify nth-party dependencies, and visualize supply chain concentration risks.
  • Oversee end-to-end third party risk assessment lifecycle management across critical and strategic vendor portfolios.
  • Lead supply chain risk analytics, including identifying systemic risks across geographies, sectors, and technology stacks.
  • Manage vendor due diligence processes, ensuring consistency of assessment methodology, scoring, and reporting standards.
  • Collaborate with procurement, IT, legal, and business units to integrate TPRM monitoring outputs into vendor governance decisions.
  • Develop executive-ready risk reports, risk heat maps, and KRI/KPI dashboards for senior leadership and board-level reporting.
  • Lead a team of Senior Consultants and Analysts, providing mentoring, quality oversight, and performance management.
  • Contribute to TPRM practice development through thought leadership, tool evaluation, and methodology innovation.

 

 

Education / Certifications

 

  • Bachelor’s degree in engineering, Technology, Business, Risk Management, or related disciplines.
  • Relevant certifications are advantageous (e.g., ISO 42001, CISSP, CISM, CRISC, CTPRP, ISO 27001 Lead Implementer, PMP, or equivalent).

 

 

AI & Cyber Certifications

 

Cyber Security Certifications (Required / Advantageous):

 

  • Certified Information Systems Security Professional (CISSP) – Advanced cybersecurity, risk, and supply chain security knowledge.
  • Certified in Risk and Information Systems Control (CRISC) – IT risk management lifecycle, KRIs, and risk monitoring.
  • Certified Third Party Risk Professional (CTPRP) – Industry-recognized TPRM expertise and assessment methodology.
  • Certified Information Security Manager (CISM) – Security governance, risk management, and program development.
  • Project Management Professional (PMP) – Program delivery, resource management, and stakeholder engagement.

 

 

AI & Data Science Certifications (Required / Advantageous):

 

  • Microsoft Certified: Azure Data Scientist Associate – Building and deploying predictive models for risk analytics.
  • AWS Certified Machine Learning – Specialty – ML model development, training, and deployment for risk scoring.
  • Google Professional Data Engineer – Data pipeline design for risk analytics and monitoring platforms.
  • Databricks Certified Associate Developer for Apache Spark – Large-scale risk data processing and analytics.
  • Graph Database Certification (Neo4j Certified Professional) – Graph AI implementation for vendor ecosystem mapping and supply chain risk analysis.

 

 

Skills & Experience

 

 

Required Skills:

 

  • 8–12 years of experience in TPRM, cyber risk, or information security, with at least 3 years in a leadership or management role.
  • Deep expertise in TPRM frameworks including NIST SP 800-161, ISO 27036, and regulatory TPRM requirements.
  • Proven experience managing vendor risk assessment lifecycles at scale including onboarding, periodic review, and exit management.
  • Strong knowledge of supply chain risk including multi-tier vendor governance, concentration risk, and geopolitical overlays.
  • Use of AI in TPRM processes. Like using AI for assessor evaluation, writing issue descriptions and risk mitigation plans
  • Understanding risk from third parties using AI to provide services to client. Looking into AI governance and AI security
  • Understanding risk from third parties using AI Agents to provide services to client. Looking into AI governance and AI security
  • Use of AI in TPRM processes. Like using AI Agents to build automations in TPRM processes
  • Understanding how things like Frontier AI and Mythos will change cybersecurity Lense and how third parties are protecting themselves from these modern threat
  • Experience with cyber risk management frameworks and regulatory standards (DORA, CPS 234, MAS TRM, GDPR).
  • Demonstrated ability to build and manage TPRM programs across complex, multi-entity environments.
  • Excellent stakeholder management, executive communication, and team leadership skills.
  • Hands-on experience building AI-enabled vendor risk scoring models incorporating structured and unstructured data sources.
  • Practical experience with predictive modelling (regression, classification, time-series) applied to vendor risk forecasting.
  • Experience deploying Graph AI frameworks for supply chain risk mapping and network analysis.
  • Expertise in AI-driven continuous monitoring platforms and automated control testing tools.
  • Proficiency in data analytics and visualization tools (Python, R, Power BI, Tableau) for risk intelligence.
  • Understanding of machine learning model governance, explainability requirements, and AI risk management standards.

 

 

AI Tools Skillset

 

  • AI-Powered TPRM & Vendor Intelligence Platforms:
    • Prevalent TPRM Platform – AI-powered vendor risk scoring, automated assessments, and continuous monitoring with ML-based risk signals.
    • ProcessUnity / OneTrust VRM – AI-assisted vendor risk workflows, real-time alerting, and automated vendor profile enrichment.
    • BitSight / SecurityScorecard – Continuous AI-driven vendor cyber ratings, attack surface monitoring, and predictive risk scoring.
  • Graph AI & Network Analysis Tools:
    • Neo4j Graph Database – Building vendor relationship graphs, nth-party dependency mapping, and supply chain concentration risk visualization.
    • Amazon Neptune / Azure Cosmos DB (Gremlin) – Cloud-native graph analytics for large-scale vendor ecosystem intelligence.
    • Linkurious / yFiles – Graph visualization platforms for supply chain risk network analysis and stakeholder reporting.
  • Predictive Analytics & Machine Learning Platforms:
    • Python (scikit-learn, XGBoost, LightGBM) – Building vendor breach probability models, risk scoring engines, and anomaly detection pipelines.
    • Azure Machine Learning / AWS SageMaker – Deploying and managing predictive risk models at scale within TPRM monitoring workflows.
    • Databricks – Large-scale risk data processing, feature engineering, and ML model training for vendor risk analytics.
  • Dashboarding & Risk Intelligence:
    • Power BI / Tableau – Executive TPRM dashboards, vendor risk heat maps, KRI/KPI monitoring, and board-level supply chain risk reporting.
    • Splunk – Integrating security event data with TPRM monitoring for real-time vendor security intelligence.

 

 

Behavioral Expectations

 

  • Own delivery, quality, and stakeholder engagement across all managed TPRM analytics workstreams.
  • Translate TPRM strategy into execution plans and measurable risk reduction outcomes.
  • Lead and mentor team members, ensuring consistency, quality, and professional development.
  • Drive adoption of AI-led automation and data-driven decision-making within the TPRM function.
  • Foster a culture of continuous improvement, innovation, and intellectual curiosity.
  • Communicate complex risk analytics insights to non-technical stakeholders clearly and actionably.
  • Build trusted relationships with internal clients, senior leadership, and external partners.

 

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Apply now »