Deloitte
Manager, Third-Party Risk Management PMO, Quality Risk & Security, Enabling Functions – 12 Month Secondment/FTC

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Connect to your Industry
As Deloitte UK’s reliance on third parties continues to grow, effective third-party risk management is increasingly critical to protecting the firm from financial, operational, regulatory and reputational risk. Regulators and clients are placing greater scrutiny on how organisations manage their extended supply chain, including the extent to which third parties meet relevant regulatory, contractual and policy requirements.
This role sits within Deloitte’s second line of defence and plays a key part in managing the firm’s Third-Party Risk Management (TPRM) capability. The TPRM programme helps the business identify, assess and manage the risks that arise when Deloitte procures or uses third-party goods and services, whether to support the firm’s operations or the delivery of client engagements.
You will play a pivotal role in helping the business make informed, risk-based decisions about third-party relationships and in strengthening how associated risks are understood, governed and managed across the firm.
Connect to your career at Deloitte
Deloitte drives progress. Using our vast range of expertise, we help our clients' become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.
What brings us all together at Deloitte? It’s how we approach the thousands of decisions we make every day. How we behave, our beliefs and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other, foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most.
Connect to your opportunity
This is a high-impact opportunity to help safeguard Deloitte UK’s Third-Party risk landscape at a time of increasing regulatory scrutiny, growing reliance on external suppliers and continued focus on operational resilience across the supply chain during a period of transformation.
The role is a 12-month fixed-term Manager position within the Third-Party Risk Management team in Quality, Risk and Security (QRS), leading on key strategic priorities for FY27, including design and implementation of a significant priority to strengthen the management of technology and information security risks across our supply chain.
This role will support our continued ability to work with clients across regulated industries including government and public services. You will play a key role in translating evolving regulatory, client and security expectations into a practical proportionate and sustainable approach to managing third party risk.
You will work closely with stakeholders across the business, Extended Enterprise, QRS SMEs and Managed Service teams to support effective delivery, clear governance and continuous improvement across the TPRM programme.
Key Responsibilities:
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
- Leading the design and implementation of strategic supply chain and resilience projects translating organisations, regulatory and client expectations into practical delivery within the wider TPRM context.
- Supporting Quality Risk and Security Subject Matter Experts to translate their individual team priorities into the requirements of TPRM Programme.
- Own the end-to-end delivery of complex cross-functional projects including managing scope, milestones, dependencies, risks and issues.
- Define and document business and functions requirements for process, controls, data, reporting and supporting technology.
- Leading discussions and negotiations with external providers that can be leveraged to support TPRM processes.
- Drive continuous improvement and automation opportunities to improve the efficiency, consistency and scalability of the TPRM Programme.
- Leading conversations with regulators, clients and internal stakeholders with requests for assurances across our TPRM Programme.
- Provide oversight of Managed Service, ensuring service quality, effective ways of working and alignment with Deloitte’s TPRM standards.
- Act as a key escalation point for TPRM-related matters, providing clear risk judgement, practical guidance and timely resolution of issues.
- Engage and collaborate with stakeholders at all levels across the business, QRM, Risk, Procurement, Vendor Management and third parties to support effective third-party risk management outcomes.
- Support junior TPRM team members, the Managed Service and the Assistant Manager, providing direction, coaching and oversight to enable effective delivery and continuous improvement.
Connect to your skills and professional experience
Essential:
- Strong and proven ability to lead on projects, manage competing priorities and deliver high-quality outputs in a fast-paced environment.
- Proven experience in risk management, ideally within a regulated, professional/financial services or complex corporate environment.
- Strong understanding of third-party risk management frameworks, good practice and associated governance, oversight and assurance activities.
- Working knowledge of key third-party risk domains, including information and data security, financial crime, business continuity, operational resilience, ESG, and contractual risk.
- Ability to apply sound risk judgement, identify material issues and determine when escalation to senior stakeholders is needed.
- Experience developing, implementing or enhancing risk and control frameworks, processes, policies or governance arrangements.
- Strong stakeholder management skills, with the ability to influence, challenge and advise senior stakeholders, practitioners and third parties.
- Excellent written and verbal communication skills, with the ability to explain risk concepts clearly and pragmatically to both technical and non-technical audiences.
- Strong analytical skills, with the ability to interpret information, draw clear conclusions and translate insight into practical action.
- Collaborative and delivery-focused approach, with the ability to build strong working relationships across teams, functions and geographies.
- Ability to operate effectively in ambiguity, balancing risk, commerciality and proportionality when making recommendations.
- Commitment to continuous improvement, with a rigorous, responsive and outcome-focused approach to delivery.
- Experience supporting, coaching or guiding junior colleagues, helping to build capability and maintain delivery quality.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable:
- Experience in third-party risk management, procurement, information security, outsourcing, operational resilience or internal risk management.
- Experience designing, implementing or improving tools, dashboards, workflows or reporting to support third-party risk management.
- Experience operating in a matrixed, distributed or international team environment, including working with managed service delivery models.
- Familiarity with professional services, Big 4 or partnership environments.
- Understanding of emerging third-party risk themes, including ESG, nth party risk, critical third parties, supplier resilience and regulatory change.
Connect to your business - Enabling Functions
Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact. Come join us.
National Quality and Risk Management
We ensure we manage our business with integrity. This includes developing and managing assurance and business risk frameworks, anti-money laundering, addressing any potential conflicts of interest amongst clients and maintaining our independence from them, ensuring we’re compliant and managing the security of our people.
Personal independence
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints (e.g., in relation to any financial interests and employment relationships). This can mean that you and your "Immediate Family Members" are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm, and also prohibitions on certain employment relationships (e.g., you are not permitted to hold a secondary employment role with SEC audit clients of the firm whilst being employed by the firm). The recruitment team will provide further details as you progress through the recruitment process, or you can contact the Independence team upon request.
Connect with your colleagues
"Deloitte’s a large, complex and fast-paced organisation but it’s open to new ideas. Everyone is encouraged to show initiative and challenge the norm.” -Lisa, Enabling Functions
For a full job description, please visit our online Deloitte Careers portal.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location