TPRM & ISO 27001 Readiness Lead

DysrupIT Pty

Manila

On-site

PHP 2,066,000 - 2,893,000

Part time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

DysrupIT Pty in Manila is seeking a TPRM Consultant with strong GRC experience to lead vendor risk management on an hourly, project-based engagement focused on ISO 27001 readiness and ISMS certification. You will build and operate the TPRM program, onboard vendors, perform risk assessments, maintain risk registers, and support audits with documentation.

The role requires 15–20 hours per week during the build phase, with scope to reduce later, and collaboration across IT, Legal, Security, and

Qualifications

  • Proven experience in vendor/third-party risk management.
  • Strong knowledge of GRC frameworks and practices.
  • Hands-on ISO 27001 auditing experience (internal or external).
  • Familiarity with risk assessment methodologies and compliance reporting.
  • Excellent stakeholder management and cross-functional coordination.
  • Available for 15–20 hours/week during build phase.
  • Ability to operate autonomously on a recurring cadence.

Responsibilities

  • Develop end-to-end TPRM program including onboarding, risk assessments, monitoring, and offboarding.
  • Support ISO 27001 audit readiness and remediation tracking.
  • Assess third-party risk exposure and ensure regulatory compliance.
  • Coordinate with IT, Legal, Security, and Procurement to align with frameworks.
  • Build vendor risk registers, compliance trackers, and audit documentation.
  • Support audits with TPRM evidence and documentation.
  • Design TPRM policy, procedures, and risk-tiering.
  • Create templates for SIG/CAIQ questionnaires and DPIA triggers.
  • Establish vendor inventory and onboarding/offboarding workflows.
  • Recommend DPA clauses and data processing agreement templates.
  • Manage full vendor risk assessment lifecycle across tiers.
  • Monitor vendor risk posture and reassess as needed.
  • Coordinate contract renewals and DPA updates.
  • Present vendor risk metrics to leadership monthly/quarterly.
  • Provide guidance/training to procurement and business owners.
  • Develop SOP for offboarding including data return and access revocation.
  • Refine program with policy updates and tooling improvements.
  • Reduce weekly hours after first cycle closes.

Skills

Vendor/Third-Party Risk Management
GRC frameworks
ISO 27001 auditing
Stakeholder management
Regulatory compliance

Job description

DysrupIT Pty in Manila is seeking a TPRM Consultant with strong GRC experience to lead vendor risk management on an hourly, project-based engagement focused on ISO 27001 readiness and ISMS certification. You will build and operate the TPRM program, onboard vendors, perform risk assessments, maintain risk registers, and support audits with documentation.

The role requires 15–20 hours per week during the build phase, with scope to reduce later, and collaboration across IT, Legal, Security, and

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

TPRM Consultant - Makati, Philippines
TPRM Consultant - Makati, Philippines

DysrupIT Pty • Manila

On-site
PHP 2,066,000 - 2,893,000
TPRM Cybersecurity Consultant: Risk & Remediation Lead
TPRM Cybersecurity Consultant: Risk & Remediation Lead

NTT Philippines Solutions Inc. • Makati

On-site
PHP 900,000 - 1,300,000
Consultant at Deloitte Touche Tohmatsu India LLP, Bengaluru
Consultant at Deloitte Touche Tohmatsu India LLP, Bengaluru

Lexful Legal • Hinoba-an

On-site
PHP 600,000 - 1,000,000
Senior TPRM Manager: Drive Vendor Excellence
Senior TPRM Manager: Drive Vendor Excellence

NightOwl Consulting Philippines Inc. • Philippines

On-site
PHP 1,339,200 - 1,785,600
Above market salary
HMO on Day 1
Government benefits
+4
Third-Party Risk & Trust Center Analyst
Third-Party Risk & Trust Center Analyst

RELX • Quezon City

On-site
PHP 900,000 - 1,300,000
Competitive benefits
Senior Consultant - Third Party Risk Management (TPRM)
Senior Consultant - Third Party Risk Management (TPRM)

TymblHub • Hinoba-an

On-site
PHP 1,200,000 - 1,800,000
Vendor Risk & TPRM Program Lead
Vendor Risk & TPRM Program Lead

NightOwl Consulting • Quezon City

On-site
PHP 1,339,200 - 1,785,600
Above market salary
HMO on Day 1
Performance-based Incentives
IT Manager: Digital Transformation & ISO27001
IT Manager: Digital Transformation & ISO27001

HRTX • Philippines

On-site
PHP 1,000,000 - 1,800,000
Senior GRC Analyst - ISO27001 Risk & Audit Lead | Hybrid & Equity
Senior GRC Analyst - ISO27001 Risk & Audit Lead | Hybrid & Equity

Audinate • Philippines

Hybrid
PHP 900,000 - 1,500,000
Flexible working (2 days in office)
Home office support
Volunteering leave
+2
Vendor Risk Analyst | 6-Month Contract | Fixed Night Shift | TP MCKINLEY
Vendor Risk Analyst | 6-Month Contract | Fixed Night Shift | TP MCKINLEY

Teleperformance • Taguig

On-site
PHP 420,000 - 660,000