Third-Party Risk Management (TPRM) Consultant
TsaaroMalad West, Mumbai
it-jobs
Job Description
Join Tsaaro as a Cyber GRC & Third-Party Risk Management (TPRM) Consultant Drive Cyber Resilience. Build Trust. Deliver Impact. Are you passionate about helping organizations strengthen their cyber governance, manage third-party risks, and achieve compliance with global security standards? At Tsaaro, we go beyond compliance, we help organizations build resilient governance, risk, and compliance (GRC) programs that enable secure business growth. We are looking for a Cyber GRC & Third-Party Risk Management (TPRM) Consultant who thrives in consulting environments, enjoys solving complex security challenges, and can deliver practical, risk-based solutions to clients. About Tsaaro At Tsaaro, privacy and cybersecurity are at the heart of everything we do. Our team of privacy consultants and cybersecurity specialists collaborates to help organizations build robust governance frameworks, strengthen security programs, and manage evolving cyber risks. Our consulting approach focuses on delivering practical, business-aligned solutions that help clients strengthen security posture, manage vendor risks, achieve compliance, and build long-term resilience. Your Role: Cyber GRC & Third-Party Risk Management (TPRM) Consultant As a Consultant, you will work closely with clients to establish governance frameworks, assess cyber risks, conduct third-party risk assessments, and support compliance initiatives across multiple regulatory and industry standards. Key Responsibilities - Conduct end-to-end Third-Party Risk Management (TPRM) assessments across vendors, suppliers, and service providers. - Perform vendor security reviews, due diligence assessments, and security questionnaires. - Evaluate third-party cybersecurity controls and identify risks, gaps, and mitigation strategies. - Develop and implement Third-Party Risk Management frameworks, policies, and procedures. - Support clients in implementing Governance, Risk & Compliance (GRC) programs aligned with business objectives. - Perform cyber risk assessments, control maturity assessments, and compliance gap analyses. - Assist clients in implementing and maintaining ISO 27001, ISO 27701, NIST CSF, CIS Controls, and other security frameworks. - Support audit readiness initiatives including internal audits, control testing, and evidence collection. - Develop risk registers, risk treatment plans, and executive reports. - Collaborate with cross-functional teams to improve governance processes and strengthen organizational cyber resilience. - Contribute to cybersecurity consulting engagements involving policy development, control implementation, and regulatory compliance. - Provide recommendations for continuous improvement in vendor risk governance and cybersecurity practices. Requirements - 2–4+ years of experience in Cyber GRC, Third-Party Risk Management (TPRM), Information Security, or Cybersecurity Consulting. - Strong understanding of Third-Party Risk Management methodologies and vendor risk assessment processes. - Hands-on experience conducting vendor security assessments and reviewing security controls. - Working knowledge of ISO 27001, ISO 27701, NIST CSF, CIS Controls, SOC 2, or similar security frameworks. - Familiarity with governance, risk management, compliance processes, and cybersecurity regulations. - Experience with risk assessments, audit support, policy development, and control implementation. - Excellent analytical, documentation, stakeholder management, and client communication skills. - Professional certifications such as ISO 27001 Lead Implementer/Lead Auditor, CRISC, CISA, CISM, Security+, or similar are preferred. - A collaborative, solution-oriented mindset with the ability to manage multiple client engagements. Benefits Why Join Tsaaro? - Work with one of India's fastest-growing privacy and cybersecurity consulting firms. - Gain exposure to global clients across diverse industries. - Work on strategic Cyber GRC and Third-Party Risk Management engagements. - Accelerate your career with mentorship and leadership opportunities. - Hybrid work flexibility. - Continuous learning support through certifications and professional development programs. From the Tsaaro Team "At Tsaaro, we believe cybersecurity is built on strong governance, informed risk decisions, and trusted partnerships. If you're excited about helping organizations strengthen their cyber resilience while working on meaningful consulting engagements, we'd love to have you on our team." Ready to Advance Your Cyber GRC Career? Apply now and become part of Tsaaro's mission to build secure, resilient, and compliant organizations.
Get AI-Matched to This Job
Upload your resume and our AI will score how well you match this and thousands of similar roles.