Crowe
Website:
crowe.com
Job details:
Your Journey at Crowe Starts Here:
At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you’re trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That’s why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services. Join us at Crowe and embark on a career where you can help shape the future of our industry.
Job Description:
What It Means To Be a Consultant At Crowe
Consulting is a dynamic business focused on solving problems for our clients and serving our core markets through innovative solutions. As technology and AI continue to reshape the consulting landscape, we are looking for individuals who are curious, adaptable, and eager to learn. At Crowe, consultants are expected to build both technical and transferable skills, think critically, and use technology to solve real business problems. In this role, you will continuously learn, collaborate across teams, and explore how tools, including emerging AI capabilities, can improve efficiency, insights, and client outcomes.
In management at Crowe, you play a pivotal role in leading teams, guiding project execution, and deepening client relationships. You are expected to contribute to account planning, identify opportunities to add value, and ensure high-quality delivery. As your responsibilities expand, you take on broader account ownership, balancing project leadership with growing involvement in client strategy and solution development.
Success in this role comes from a growth mindset, strong communication skills, advanced critical thinking, and the ability to navigate new challenges with confidence.
Crowe is seeking an experienced
Third Party Risk Manager to join our growing Cybersecurity and Risk Consulting team in India. In this role, you will lead and deliver Third-Party Risk Management (TPRM) engagements for global clients, helping organizations identify, assess, and manage cybersecurity and operational risks across their vendor ecosystems.
You will work closely with clients, vendors, and cross-functional teams to execute risk assessments, strengthen third-party governance programs, and drive high-quality project delivery. This is an excellent opportunity for a cybersecurity professional who enjoys working in a dynamic consulting environment while mentoring teams and building trusted client relationships.
Responsibilities
Third-Party Risk Management & Client Delivery
- Lead Third-Party Risk Management (TPRM) and Vendor Risk Management (VRM) engagements for global clients.
- Conduct cybersecurity risk assessments using Crowe methodologies and industry-recognized frameworks.
- Evaluate vendor security controls, governance practices, and overall cybersecurity maturity.
- Assess technical and compliance documentation, including:
- SOC 2 Type II reports
- Penetration Testing reports
- Vulnerability Assessment reports
- PCI DSS assessments
- Other independent assurance reports
- Support and enhance cybersecurity programs aligned with the NIST Risk Management Framework (RMF), Assessment & Authorization (A&A), and related governance processes.
- Develop vendor risk profiles and assess country, regulatory, and outsourcing risks.
- Prepare high-quality assessment reports, executive summaries, and client deliverables.
- Manage multiple client engagements, ensuring projects are delivered on time, within scope, and in accordance with Crowe's quality standards.
- Provide regular project updates and effectively manage client expectations throughout the engagement lifecycle.
- Build strong relationships with clients, vendors, and internal stakeholders while serving as a trusted advisor.
- Identify opportunities to improve methodologies, operational efficiency, and service delivery.
Leadership & Team Development
- Lead, coach, and mentor team members, fostering collaboration and professional growth.
- Promote a culture of quality, integrity, and continuous improvement.
- Participate in organizational initiatives, knowledge sharing, and capability development.
- Support the development and implementation of new methodologies, tools, and best practices.
Basic Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- 7+ years of experience in Information Security, Cybersecurity Risk Management, Third-Party Risk Management, or Vendor Risk Management.
- Experience leading teams of four or more professionals.
- Strong experience conducting cybersecurity and third-party risk assessments.
- Hands-on experience reviewing security assurance reports such as SOC 2, penetration testing, vulnerability assessment, and PCI DSS reports.
- Strong knowledge of cybersecurity frameworks and standards, including ISO 27001, NIST, PCI DSS, ISO 22301, and privacy frameworks.
- Solid understanding of:
- Network Security
- Cloud Security
- Application Security
- IT General Controls
- Data Privacy
- Cryptography
- Business Continuity and Disaster Recovery
- Incident Management
- Experience with vendor risk profiling, outsourcing risks, and regulatory requirements.
- Excellent analytical, problem-solving, written, and verbal communication skills.
- Strong auditing and stakeholder management capabilities.
- Ability to manage multiple priorities and deliver high-quality work in a fast-paced consulting environment.
- Willingness to travel as required.
Preferred Qualifications
- Experience conducting onsite vendor security audits.
- Professional certifications such as:
- CISA
- CISSP
- CISM
- CCSP
- ISO 27001 Lead Auditor
- CTPRA
- Cloud platform certifications (AWS, Azure, or Google Cloud)
- Knowledge of governance, risk, compliance (GRC), and privacy regulations.
- Familiarity with Secure Software Development Lifecycle (Secure SDLC) practices and frameworks.
- Experience working with global clients in a consulting or professional services environment.
- Demonstrated ability to drive process improvements and contribute to the development of cybersecurity methodologies and best practices.
We expect the candidate to uphold Crowe’s values of Care, Trust, Courage, and Stewardship. These values define who we are. We expect all of our people to act ethically and with integrity at all times.
Our Benefits:
At Crowe, we know that great people are what makes a great firm. We value our people and offer employees a comprehensive benefits package. Learn more about what working at Crowe can mean for you!
How You Can Grow:
We will nurture your talent in an inclusive culture that values diversity. You will have the chance to meet on a consistent basis with your Career Coach that will guide you in your career goals and aspirations. Learn more about where talent can prosper!
More about Crowe:
Crowe Capability Center – India, operating under the legal entity C3 India Delivery Centre LLP (formerly known as Crowe Horwath IT Services LLP) is a wholly owned subsidiary of Crowe LLP (U.S.A.), a public accounting, consulting and technology firm with offices around the world. Crowe LLP is an independent member firm of Crowe Global, one of the largest global accounting networks in the world. The network consists of more than 200 independent accounting and advisory firms in more than 130 countries around the world.
Crowe does not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a pre-existing agreement signed by both parties covering the submission will be considered the property of Crowe, and free of charge.
We are committed to a merit-based hiring process, evaluating all candidates consistently using objective, job-related criteria such as relevant experience, demonstrated skills, measurable impact, and alignment with the role’s responsibilities, and making employment decisions in a fair and inclusive manner free from discrimination.
Click on Apply to know more.