Tsaaro Consulting Logo

Tsaaro Consulting

Third-Party Risk Management (TPRM) Consultant

Posted Yesterday
Be an Early Applicant
In-Office
Malad West, Mumbai Suburban, Maharashtra
Mid level
In-Office
Malad West, Mumbai Suburban, Maharashtra
Mid level
Conduct third-party risk assessments, vendor security reviews, cyber risk and control maturity assessments, and compliance gap analyses. Develop TPRM frameworks, policies, risk registers, and treatment plans while supporting GRC programs aligned with ISO 27001, ISO 27701, NIST CSF, CIS Controls, and SOC 2. Assist with audit readiness, control testing, evidence collection, and executive reporting. Advise clients on cybersecurity governance, regulatory compliance, vendor risk mitigation, and continuous improvement across multiple consulting engagements.
The summary above was generated by AI

Join Tsaaro as a Cyber GRC & Third-Party Risk Management (TPRM) Consultant

Drive Cyber Resilience. Build Trust. Deliver Impact.

Are you passionate about helping organizations strengthen their cyber governance, manage third-party risks, and achieve compliance with global security standards?

At Tsaaro, we go beyond compliance, we help organizations build resilient governance, risk, and compliance (GRC) programs that enable secure business growth. We are looking for a Cyber GRC & Third-Party Risk Management (TPRM) Consultant who thrives in consulting environments, enjoys solving complex security challenges, and can deliver practical, risk-based solutions to clients.

About Tsaaro

At Tsaaro, privacy and cybersecurity are at the heart of everything we do. Our team of privacy consultants and cybersecurity specialists collaborates to help organizations build robust governance frameworks, strengthen security programs, and manage evolving cyber risks.

Our consulting approach focuses on delivering practical, business-aligned solutions that help clients strengthen security posture, manage vendor risks, achieve compliance, and build long-term resilience.

Your Role: Cyber GRC & Third-Party Risk Management (TPRM) Consultant

As a Consultant, you will work closely with clients to establish governance frameworks, assess cyber risks, conduct third-party risk assessments, and support compliance initiatives across multiple regulatory and industry standards.

Key Responsibilities

  • Conduct end-to-end Third-Party Risk Management (TPRM) assessments across vendors, suppliers, and service providers.
  • Perform vendor security reviews, due diligence assessments, and security questionnaires.
  • Evaluate third-party cybersecurity controls and identify risks, gaps, and mitigation strategies.
  • Develop and implement Third-Party Risk Management frameworks, policies, and procedures.
  • Support clients in implementing Governance, Risk & Compliance (GRC) programs aligned with business objectives.
  • Perform cyber risk assessments, control maturity assessments, and compliance gap analyses.
  • Assist clients in implementing and maintaining ISO 27001, ISO 27701, NIST CSF, CIS Controls, and other security frameworks.
  • Support audit readiness initiatives including internal audits, control testing, and evidence collection.
  • Develop risk registers, risk treatment plans, and executive reports.
  • Collaborate with cross-functional teams to improve governance processes and strengthen organizational cyber resilience.
  • Contribute to cybersecurity consulting engagements involving policy development, control implementation, and regulatory compliance.
  • Provide recommendations for continuous improvement in vendor risk governance and cybersecurity practices.

Requirements
  • 2–4+ years of experience in Cyber GRC, Third-Party Risk Management (TPRM), Information Security, or Cybersecurity Consulting.
  • Strong understanding of Third-Party Risk Management methodologies and vendor risk assessment processes.
  • Hands-on experience conducting vendor security assessments and reviewing security controls.
  • Working knowledge of ISO 27001, ISO 27701, NIST CSF, CIS Controls, SOC 2, or similar security frameworks.
  • Familiarity with governance, risk management, compliance processes, and cybersecurity regulations.
  • Experience with risk assessments, audit support, policy development, and control implementation.
  • Excellent analytical, documentation, stakeholder management, and client communication skills.
  • Professional certifications such as ISO 27001 Lead Implementer/Lead Auditor, CRISC, CISA, CISM, Security+, or similar are preferred.
  • A collaborative, solution-oriented mindset with the ability to manage multiple client engagements.

Benefits

Why Join Tsaaro?

  • Work with one of India's fastest-growing privacy and cybersecurity consulting firms.
  • Gain exposure to global clients across diverse industries.
  • Work on strategic Cyber GRC and Third-Party Risk Management engagements.
  • Accelerate your career with mentorship and leadership opportunities.
  • Hybrid work flexibility.
  • Continuous learning support through certifications and professional development programs.

From the Tsaaro Team

"At Tsaaro, we believe cybersecurity is built on strong governance, informed risk decisions, and trusted partnerships. If you're excited about helping organizations strengthen their cyber resilience while working on meaningful consulting engagements, we'd love to have you on our team."

Ready to Advance Your Cyber GRC Career?

Apply now and become part of Tsaaro's mission to build secure, resilient, and compliant organizations.


Similar Jobs

12 Minutes Ago
Hybrid
Senior level
Senior level
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Lead and execute internal audits across financial, operational, and compliance areas. Perform process walkthroughs, control testing, evaluate control design and operating effectiveness, report findings, and work with stakeholders to improve controls and efficiency. Collaborate with audit leadership and operate across functions and regions to deliver the annual audit plan.
Senior level
Fintech • Software • Financial Services
Manage middle- and back-office fund services, including trade affirmations, position, cash, P&L, equity swap, and NAV reconciliations. Book corporate actions, options, accruals, expenses, stock borrow, and swap financing activity. Resolve reconciliation breaks through communication with clients, fund administrators, and trading counterparties. Support hedge fund and financial product accounting processes while independently prioritizing multiple tasks across APAC and EMEA shifts.
Top Skills: ExcelMicrosoft Word
An Hour Ago
Hybrid
Pune, Maharashtra, IND
Senior level
Senior level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
Leads a global Kubernetes platform engineering team, setting the platform roadmap and overseeing enterprise-scale infrastructure health, security, compliance, automation, observability, and scalability. Partners with FinOps, Finance, DevOps, and product leaders to manage budgets, forecast growth, optimize cloud resources, reduce operational toil, and align platform performance with business value. Develops engineering talent and drives organizational adoption of Infrastructure as Code and automated CI/CD practices.
Top Skills: Amazon EksCi/CdGoogle GkeInfrastructure As CodeKarpenterKubernetesScaleops

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account