We're looking for a TPRM Consultant with strong Governance, Risk, and Compliance (GRC) experience to support vendor oversight and information security compliance initiatives, including ISO 27001 audit readiness and ISMS certification. This consultant will build and operate its vendor/third-party risk management program on an ongoing, hourly contract basis. This is a project-based engagement focused on strengthening vendor risk management practices and preparing the organization for certification.
Job Responsibilities
Develop and build an end-to-end TPRM Program - onboarding, risk assessments, performance monitoring, and offboarding
Support ISO 27001 audit readiness activities, including gap assessments and remediation tracking as needed.
Assess third-party/vendor risk exposure and ensure compliance with security and regulatory requirements.
Coordinate with internal stakeholders (IT, Legal, Security, Procurement) to align the TPRM Program with existing frameworks
Develop and build the vendor risk registers, compliance trackers, and audit documentation as the single source of truth, keeping it current and audit-ready
Support internal and external audits, liaising with certification bodies as needed
Design the TPRM policy, procedure, and risk-tiering methodology (critical/high/medium/low based on data access, business impact, and regulatory exposure)
Build vendor risk assessment templates (SIG/CAIQ-aligned questionnaires, DPIA triggers for vendors processing personal data)
Establish the vendor inventory/register and define onboarding, monitoring, and offboarding workflows
Recommend standard security/privacy contract clauses and Data Processing Agreement (DPA) templates for Legal and Procurement to adopt
Own and execute the full vendor risk assessment lifecycle across all tiers on the defined cadence (e.g., annual for critical, biennial for lower risk)
Continuously monitor vendor risk posture (security ratings platforms, incident tracking, contract or scope changes) and reassess as needed
Coordinate with Legal/Procurement on contract renewals, DPA updates, and sub processor changes
Support internal and external audits (ISO 27001, customer security reviews) with TPRM evidence and documentation
Prepare and present vendor risk metrics, top risks, and program status to leadership/risk committee on a regular cadence (e.g., monthly or quarterly)
Provide guidance and light training to internal stakeholders (Procurement, business owners) on TPRM policy and process
Develop the SOP for managing vendor offboarding, including secure data return/destruction confirmation and access revocation tracking
Periodically refine the program (policy updates, template improvements, tooling optimization) as the vendor landscape and regulatory environment evolve
Reduce weekly hours once the vendor register is complete and the first full assessment cycle has closed, in agreement with the organization
Qualifications
Proven experience in Vendor/Third-Party Risk Management
Solid background in GRC frameworks and practices
Experience preparing organizations for ISMS certification and Hands-on experience with ISO 27001 auditing (internal or external)
Familiarity with risk assessment methodologies and compliance reporting
Strong stakeholder management and cross-functional coordination skills
Strong working knowledge of ISO 27001, SOC 2, NIST CSF/800-53, GDPR (Art. 28, 32), and CCPA
Hands-on experience reviewing SOC 2 reports, ISO certificates, penetration test results, and vendor security questionnaires (SIG, CAIQ)
Experience drafting or advising on DPAs, security addenda, and sub-processor clauses
Comfortable operating as the embedded/de facto TPRM function — proactive, autonomous, and reliable on a recurring cadence rather than a one-time deliverable
Strong written and verbal communication skills, including presenting to executive stakeholders
Available for a sustained, ongoing commitment: 15–20 hours/week during the build phase, reducing thereafter
IT Services and IT Consulting and Software Development
What We Offer
About the Company
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Upload your Profile Picture
Accepted Formats: jpg, png
Upto 2MB in size
Your application for TPRM Consultant
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!