
TPRM Consultant
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in Philippines.
• Create and establish a comprehensive TPRM Program, including onboarding, risk assessments, performance monitoring, and offboarding.
• Assist with ISO 27001 audit preparedness activities, such as gap assessments and tracking remediation efforts as required.
• Evaluate the risk exposure of third-party vendors and ensure adherence to security and regulatory standards.
• Collaborate with internal teams (IT, Legal, Security, Procurement) to ensure the TPRM Program is aligned with existing frameworks.
• Develop and maintain vendor risk registers, compliance trackers, and audit documentation, serving as the definitive source of truth that is always current and ready for audits.
• Facilitate internal and external audits, coordinating with certification bodies as necessary.
• Design the TPRM policy, procedures, and risk-tiering methodology (critical/high/medium/low based on data access, business impact, and regulatory exposure).
• Create vendor risk assessment templates, including SIG/CAIQ-aligned questionnaires and DPIA triggers for vendors handling personal data.
• Establish a vendor inventory/register and outline workflows for onboarding, monitoring, and offboarding.
• Suggest standard security/privacy contract clauses and Data Processing Agreement (DPA) templates for Legal and Procurement to implement.
• Oversee and implement the complete vendor risk assessment lifecycle across all tiers on a defined schedule (e.g., annually for critical, biennially for lower risk).
• Continuously assess the vendor risk posture (using security ratings platforms, incident tracking, and changes in contracts or scopes) and re-evaluate as necessary.
• Coordinate with Legal and Procurement regarding contract renewals, DPA updates, and changes to sub-processors.
• Provide support for internal and external audits (ISO 27001, customer security reviews) by supplying TPRM evidence and documentation.
• Prepare and present metrics on vendor risk, highlighting top risks and program status to leadership and the risk committee on a regular basis (e.g., monthly or quarterly).
• Offer guidance and basic training to internal stakeholders (Procurement, business owners) on TPRM policies and processes.
• Develop standard operating procedures for managing vendor offboarding, including secure data return/destruction confirmation and tracking of access revocation.
• Regularly refine the program (updating policies, improving templates, optimizing tools) in response to changes in the vendor landscape and regulatory environment.
• Decrease weekly hours once the vendor register is completed and the first full assessment cycle has been finalized, in agreement with the organization.
• Demonstrated experience in Vendor/Third-Party Risk Management.
• Strong background in Governance, Risk, and Compliance (GRC) frameworks and practices.
• Experience in preparing organizations for Information Security Management System (ISMS) certification.
• Practical experience with ISO 27001 auditing, whether internal or external.
• Familiarity with risk assessment methodologies and compliance reporting.
• Excellent stakeholder management and coordination skills across functions.
• In-depth knowledge of ISO 27001, SOC 2, NIST CSF/800-53, GDPR (Art. 28, 32), and CCPA.
• Hands-on experience reviewing SOC 2 reports, ISO certificates, penetration testing results, and vendor security questionnaires (SIG, CAIQ).
• Experience in drafting or advising on Data Processing Agreements (DPAs), security addenda, and clauses for sub-processors.
• Comfortable functioning as the embedded/de facto TPRM function—proactive, independent, and dependable on an ongoing basis rather than as a one-off task.
• Strong written and verbal communication skills, including the ability to present to executive stakeholders.
• Committed to a sustained, ongoing engagement: 15–20 hours per week during the build phase, with a reduction thereafter.
• None specified
ToxStrategies, a BlueRidge Life Sciences Company
Outreach
Get handpicked remote jobs straight to your inbox weekly.