
51 - 200 employees
Founded 2016
🏢 Enterprise
☁️ SaaS
🔒 Cybersecurity
Enterprise • SaaS • Cybersecurity
DysrupIT is a global cloud services and IT solutions firm that helps organizations adopt cloud technologies and transition to as-a-Service business models. The company provides enterprise cloud, managed services, application engineering, cybersecurity, and data analytics & information management, serving SMBs through multinational enterprises with Microsoft and other cloud platforms. DysrupIT also emphasizes community impact, talent development, and long-term partnerships to deliver secure, scalable, and business-aligned technology outcomes.
🕒 July 5
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
Founded 2016
🏢 Enterprise
☁️ SaaS
🔒 Cybersecurity
Enterprise • SaaS • Cybersecurity
DysrupIT is a global cloud services and IT solutions firm that helps organizations adopt cloud technologies and transition to as-a-Service business models. The company provides enterprise cloud, managed services, application engineering, cybersecurity, and data analytics & information management, serving SMBs through multinational enterprises with Microsoft and other cloud platforms. DysrupIT also emphasizes community impact, talent development, and long-term partnerships to deliver secure, scalable, and business-aligned technology outcomes.
• Develop and build an end-to-end TPRM program covering onboarding, risk assessments, performance monitoring, and offboarding • Support ISO 27001 audit readiness, including gap assessments and remediation tracking • Assess third-party/vendor risk exposure and compliance with security and regulatory requirements • Coordinate with IT, Legal, Security, Procurement, and other internal stakeholders • Build and maintain vendor risk registers, compliance trackers, and audit documentation • Support internal and external audits, including liaison with certification bodies • Design TPRM policies, procedures, and risk-tiering methodology • Build vendor risk assessment templates, including SIG/CAIQ-aligned questionnaires and DPIA triggers • Establish vendor inventory/register and onboarding, monitoring, and offboarding workflows • Recommend security/privacy contract clauses and DPA templates for Legal and Procurement • Own the full vendor risk assessment lifecycle across all risk tiers • Monitor vendor risk posture through security ratings, incident tracking, and contract or scope changes • Coordinate contract renewals, DPA updates, and sub-processor changes with Legal and Procurement • Provide TPRM evidence and documentation for ISO 27001 and customer security reviews • Present vendor risk metrics, top risks, and program status to leadership/risk committee • Provide guidance and light training to Procurement and business owners • Develop vendor offboarding SOPs covering secure data return/destruction and access revocation • Refine policies, templates, and tooling as the vendor landscape and regulatory environment evolve
• Proven experience in Vendor/Third-Party Risk Management • Solid background in GRC frameworks and practices • Experience preparing organizations for ISMS certification • Hands-on experience with ISO 27001 auditing (internal or external) • Familiarity with risk assessment methodologies and compliance reporting • Strong stakeholder management and cross-functional coordination skills • Strong working knowledge of ISO 27001, SOC 2, NIST CSF/800-53, GDPR (Art. 28, 32), and CCPA • Hands-on experience reviewing SOC 2 reports, ISO certificates, penetration test results, and vendor security questionnaires (SIG, CAIQ) • Experience drafting or advising on DPAs, security addenda, and sub-processor clauses • Comfortable operating as the embedded/de facto TPRM function — proactive, autonomous, and reliable on a recurring cadence rather than a one-time deliverable • Strong written and verbal communication skills, including presenting to executive stakeholders • Available for a sustained, ongoing commitment: 15–20 hours/week during the build phase, reducing thereafter • Nice to have: CTPRP, CISSP, CISA, CRISC, or CIPP/E certifications • Nice to have: Prior experience serving as an embedded or fractional TPRM/GRC consultant • Nice to have: Familiarity with BitSight, SecurityScorecard, or UpGuard • Nice to have: Industry vertical experience in financial services, healthcare, SaaS, or similar • Nice to have: Experience mentoring and transitioning the function to an internal hire • Nice to have: ISO 27001 Lead Auditor / Lead Implementer certification • Nice to have: Experience in tech/IT services or BPO industry • Nice to have: Exposure to SOC 2, NIST, GDPR
• Part-time, project-based engagement on an ongoing hourly contract basis • 15–20 hours/week during the build phase, reducing thereafter by agreement • Flexible reduction of weekly hours once the vendor register is complete and the first full assessment cycle has closed
Apply Now