Job Summary
Join Tsaaro as a Cyber GRC & Third-Party Risk Management (TPRM) Consultant. Drive Cyber Resilience. Build Trust. Deliver Impact. Are you passionate about helping organizations strengthen their cyber governance, manage third-party risks, and achieve compliance with global security standards?
At Tsaaro, we go beyond compliance, we help organizations build resilient governance, risk, and compliance (GRC) programs that enable secure business growth. We are looking for a Cyber GRC & Third-Party Risk Management (TPRM) Consultant who thrives in consulting environments, enjoys solving complex security challenges, and can deliver practical, risk-based solutions to clients.
Your Role: Cyber GRC & Third-Party Risk Management (TPRM) Consultant
As a Consultant, you will work closely with clients to establish governance frameworks, assess cyber risks, conduct third-party risk assessments, and support compliance initiatives across multiple regulatory and industry standards.
Key Responsibilities
- Conduct end-to-end Third-Party Risk Management (TPRM) assessments across vendors, suppliers, and service providers.
- Perform vendor security reviews, due diligence assessments, and security questionnaires.
- Evaluate third-party cybersecurity controls and identify risks, gaps, and mitigation strategies.
- Develop and implement Third-Party Risk Management frameworks, policies, and procedures.
- Support clients in implementing Governance, Risk & Compliance (GRC) programs aligned with business objectives.
- Perform cyber risk assessments, control maturity assessments, and compliance gap analyses.
- Assist clients in implementing and maintaining ISO 27001, ISO 27701, NIST CSF, CIS Controls, and other security frameworks.
- Support audit readiness initiatives including internal audits,
control testing, and evidence collection.
- Develop risk registers, risk treatment plans, and executive reports.
- Collaborate with cross-functional teams to improve governance processes and strengthen organizational cyber resilience.
- Contribute to cybersecurity consulting engagements involving policy development, control implementation, and regulatory compliance.
- Provide recommendations for continuous improvement in vendor risk governance and cybersecurity practices.
Requirements
- 24+ years of experience in Cyber GRC, Third-Party Risk Management (TPRM), Information Security, or Cybersecurity Consulting.
- Strong understanding of Third-Party Risk Management methodologies and vendor risk assessment processes.
- Hands-on experience conducting vendor security assessments and reviewing security controls.
- Working knowledge of ISO 27001, ISO 27701, NIST CSF, CIS Controls, SOC 2, or similar security frameworks.
- Familiarity with governance, risk management, compliance processes, and cybersecurity regulations.
- Experience with risk assessments, audit support, policy development, and control implementation.
- Excellent analytical, documentation, stakeholder management, and client communication skills.
- Professional certifications such as ISO 27001 Lead Implementer/Lead Auditor, CRISC, CISA, CISM, Security+, or similar are preferred.
- A team-oriented, solution-oriented mindset with the ability to manage multiple client engagements.
Job Type
Full time
Location
Malad West, Maharashtra, India
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Data Protection Analyst (Pune)
🏢 Tsaaro
📍 Pune