TPRM Consultant - Makati, Philippines

DysrupIT Pty

Manila

On-site

PHP 2,066,000 - 2,893,000

Part time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

DysrupIT Pty in Manila is seeking a TPRM Consultant with strong GRC experience to lead vendor risk management on an hourly, project-based engagement focused on ISO 27001 readiness and ISMS certification. You will build and operate the TPRM program, onboard vendors, perform risk assessments, maintain risk registers, and support audits with documentation.

The role requires 15–20 hours per week during the build phase, with scope to reduce later, and collaboration across IT, Legal, Security, and

Qualifications

  • Proven experience in vendor/third-party risk management.
  • Strong knowledge of GRC frameworks and practices.
  • Hands-on ISO 27001 auditing experience (internal or external).
  • Familiarity with risk assessment methodologies and compliance reporting.
  • Excellent stakeholder management and cross-functional coordination.
  • Available for 15–20 hours/week during build phase.
  • Ability to operate autonomously on a recurring cadence.

Responsibilities

  • Develop end-to-end TPRM program including onboarding, risk assessments, monitoring, and offboarding.
  • Support ISO 27001 audit readiness and remediation tracking.
  • Assess third-party risk exposure and ensure regulatory compliance.
  • Coordinate with IT, Legal, Security, and Procurement to align with frameworks.
  • Build vendor risk registers, compliance trackers, and audit documentation.
  • Support audits with TPRM evidence and documentation.
  • Design TPRM policy, procedures, and risk-tiering.
  • Create templates for SIG/CAIQ questionnaires and DPIA triggers.
  • Establish vendor inventory and onboarding/offboarding workflows.
  • Recommend DPA clauses and data processing agreement templates.
  • Manage full vendor risk assessment lifecycle across tiers.
  • Monitor vendor risk posture and reassess as needed.
  • Coordinate contract renewals and DPA updates.
  • Present vendor risk metrics to leadership monthly/quarterly.
  • Provide guidance/training to procurement and business owners.
  • Develop SOP for offboarding including data return and access revocation.
  • Refine program with policy updates and tooling improvements.
  • Reduce weekly hours after first cycle closes.

Skills

Vendor/Third-Party Risk Management
GRC frameworks
ISO 27001 auditing
Stakeholder management
Regulatory compliance

Job description

JOB SUMMARY

We're looking for a TPRM Consultant with strong Governance, Risk, and Compliance (GRC) experience to support vendor oversight and information security compliance initiatives, including ISO 27001 audit readiness and ISMS certification. This consultant will build and operate its vendor/third-party risk management program on an ongoing, hourly contract basis. This is a project-based engagement focused on strengthening vendor risk management practices and preparing the organization for certification.

JOB RESPONSIBILITIES
  • Develop and build an end-to-end TPRM Program - onboarding, risk assessments, performance monitoring, and offboarding
  • Support ISO 27001 audit readiness activities, including gap assessments and remediation tracking as needed.
  • Assess third-party/vendor risk exposure and ensure compliance with security and regulatory requirements.
  • Coordinate with internal stakeholders (IT, Legal, Security, Procurement) to align the TPRM Program with existing frameworks
  • Develop and build the vendor risk registers, compliance trackers, and audit documentation as the single source of truth, keeping it current and audit-ready
  • Support internal and external audits, liaising with certification bodies as needed
  • Design the TPRM policy, procedure, and risk-tiering methodology (critical/high/medium/low based on data access, business impact, and regulatory exposure)
  • Build vendor risk assessment templates (SIG/CAIQ-aligned questionnaires, DPIA triggers for vendors processing personal data)
  • Establish the vendor inventory/register and define onboarding, monitoring, and offboarding workflows
  • Recommend standard security/privacy contract clauses and Data Processing Agreement (DPA) templates for Legal and Procurement to adopt
  • Own and execute the full vendor risk assessment lifecycle across all tiers on the defined cadence (e.g., annual for critical, biennial for lower risk)
  • Continuously monitor vendor risk posture (security ratings platforms, incident tracking, contract or scope changes) and reassess as needed
  • Coordinate with Legal/Procurement on contract renewals, DPA updates, and sub processor changes
  • Support internal and external audits (ISO 27001, customer security reviews) with TPRM evidence and documentation
  • Prepare and present vendor risk metrics, top risks, and program status to leadership/risk committee on a regular cadence (e.g., monthly or quarterly)
  • Provide guidance and light training to internal stakeholders (Procurement, business owners) on TPRM policy and process
  • Develop the SOP for managing vendor offboarding, including secure data return/destruction confirmation and access revocation tracking
  • Periodically refine the program (policy updates, template improvements, tooling optimization) as the vendor landscape and regulatory environment evolve
  • Reduce weekly hours once the vendor register is complete and the first full assessment cycle has closed, in agreement with the organization
QUALIFICATIONS
  • Proven experience in Vendor/Third-Party Risk Management
  • Solid background in GRC frameworks and practices
  • Experience preparing organizations for ISMS certification and Hands-on experience with ISO 27001 auditing (internal or external)
  • Familiarity with risk assessment methodologies and compliance reporting
  • Strong stakeholder management and cross-functional coordination skills
  • Strong working knowledge of ISO 27001, SOC 2, NIST CSF/800-53, GDPR (Art. 28, 32), and CCPA
  • Hands-on experience reviewing SOC 2 reports, ISO certificates, penetration test results, and vendor security questionnaires (SIG, CAIQ)
  • Experience drafting or advising on DPAs, security addenda, and sub-processor clauses
  • Comfortable operating as the embedded/de facto TPRM function — proactive, autonomous, and reliable on a recurring cadence rather than a one-time deliverable
  • Strong written and verbal communication skills, including presenting to executive stakeholders
  • Available for a sustained, ongoing commitment: 15–20 hours/week during the build phase, reducing thereafter
NICE TO HAVE:
  • Certifications: CTPRP (Certified Third-Party Risk Professional), CISSP, CISA, CRISC, or CIPP/E
  • Prior experience serving as an embedded or fractional TPRM/GRC consultant for one or more organizations concurrently
  • Familiarity with security ratings platforms (BitSight, Security Scorecard, UpGuard)
  • Industry vertical experience matching the organization (financial services, healthcare, SaaS, etc.)
  • Experience mentoring and eventually transitioning the function to an internal hire, as needed
  • ISO 27001 Lead Auditor / Lead Implementer certification
  • Experience in tech/IT services or BPO industry
  • Exposure to other frameworks (SOC 2, NIST, GDPR)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

TPRM & ISO 27001 Readiness Lead
TPRM & ISO 27001 Readiness Lead

DysrupIT Pty • Manila

On-site
PHP 2,066,000 - 2,893,000
Third Party Vendor Analyst
Third Party Vendor Analyst

GR8 Global Philippines • Philippines

On-site
PHP 600,000 - 900,000
Vendor Risk Analyst | 6-Month Contract | Fixed Night Shift | TP MCKINLEY
Vendor Risk Analyst | 6-Month Contract | Fixed Night Shift | TP MCKINLEY

Teleperformance • Taguig

On-site
PHP 420,000 - 660,000
Consultant at Deloitte Touche Tohmatsu India LLP, Bengaluru
Consultant at Deloitte Touche Tohmatsu India LLP, Bengaluru

Lexful Legal • Hinoba-an

On-site
PHP 600,000 - 1,000,000
Third-Party Risk Manager
Third-Party Risk Manager

NightOwl Consulting • Quezon City

On-site
PHP 1,339,200 - 1,785,600
Above market salary
HMO on Day 1
Performance-based Incentives
Third-Party Risk Manager
Third-Party Risk Manager

NightOwl Consulting Philippines Inc. • Philippines

On-site
PHP 1,339,200 - 1,785,600
Above market salary
HMO on Day 1
Government benefits
+4
Vendor Risk Analyst - Third Party
Vendor Risk Analyst - Third Party

Manpower (Philippines) • Metro Manila

On-site
PHP 600,000 - 900,000
Senior TPRM Manager: Drive Vendor Excellence
Senior TPRM Manager: Drive Vendor Excellence

NightOwl Consulting Philippines Inc. • Philippines

On-site
PHP 1,339,200 - 1,785,600
Above market salary
HMO on Day 1
Government benefits
+4
TPRM Cybersecurity Consultant: Risk & Remediation Lead
TPRM Cybersecurity Consultant: Risk & Remediation Lead

NTT Philippines Solutions Inc. • Makati

On-site
PHP 900,000 - 1,300,000
Vendor Risk & TPRM Program Lead
Vendor Risk & TPRM Program Lead

NightOwl Consulting • Quezon City

On-site
PHP 1,339,200 - 1,785,600
Above market salary
HMO on Day 1
Performance-based Incentives