TPRM Consultant

Job type:Contract
Town/City:Berlin
Region:Berlin
Sector:Cyber Security
Client Company Type:In-House
Job ref:10802
Post Date:September 29, 2026

About the Role

TPRM Consultant

The Opportunity

Tired of spending months building frameworks before you get to do the actual work? This interim assignment skips that part.

The third-party risk programme is already built. What it needs now is someone to run it: working through the review pipeline, keeping the partner base under watch and tightening up how things run day to day.

You'll own your caseload from day one, with little day-to-day direction. Your impact shows quickly, and your judgement shapes how the process works, not just what goes through it.

Hands-on technical security skills aren't required. This is a risk and governance role, so your assessment experience is what counts.

The work is largely remote, with four days a month on site.

The Role

  • Own the third-party risk pipeline, taking vendor and partner reviews from start to finish.
  • Assess each third party's financial resilience, governance arrangements and security posture.
  • Monitor existing partners on an ongoing basis and escalate any change in their risk profile.
  • Write clear, well-evidenced findings reports for internal stakeholders.
  • Raise the quality and consistency of assessment records.
  • Spot bottlenecks in current workflows and recommend or introduce practical fixes.

The Company

Our client runs an established third-party risk programme with the framework already in place. They need an experienced specialist to keep delivery moving and cover a gap in the team.

There's genuine appetite for improvement. If you see a better way of doing something, you'll have room to put it into practice, and the mostly remote setup gives you control over how you manage your week.

What You'll Need

  • A background in risk and governance.
  • Proven experience delivering vendor or third-party risk reviews end to end, covering financial, governance and security criteria.
  • Experience documenting findings and recommendations for internal stakeholders.

How to Apply

If this sounds like your next assignment, get in touch with the MAM Gruppe team. Your CV doesn't need to be up to date. Send what you have, or just give us a call.

More Jobs from this Recruiter

Berlin , Berlin

TPRM Consultant

TPRM Consultant The Opportunity Tired of spending months building frameworks before you get to do the actual work? This interim assignment skips that part. The third-party risk programme is already built. What it needs now is someone to run it: working through the review pipeline, keeping the partner base under watch and tightening up how things run day to day. You'll own your caseload from day one, with little day-to-day direction. Your impact shows quickly, and your judgement shapes how the process works, not just what goes through it. Hands-on technical security skills aren't required. This is a risk and governance role, so your assessment experience is what counts. The work is largely remote, with four days a month on site. The Role Own the third-party risk pipeline, taking vendor and partner reviews from start to finish. Assess each third party's financial resilience, governance arrangements and security posture. Monitor existing partners on an ongoing basis and escalate any change in their risk profile. Write clear, well-evidenced findings reports for internal stakeholders. Raise the quality and consistency of assessment records. Spot bottlenecks in current workflows and recommend or introduce practical fixes. The Company Our client runs an established third-party risk programme with the framework already in place. They need an experienced specialist to keep delivery moving and cover a gap in the team. There's genuine appetite for improvement. If you see a better way of doing something, you'll have room to put it into practice, and the mostly remote setup gives you control over how you manage your week. What You'll Need A background in risk and governance. Proven experience delivering vendor or third-party risk reviews end to end, covering financial, governance and security criteria. Experience documenting findings and recommendations for internal stakeholders. How to Apply If this sounds like your next assignment, get in touch with the MAM Gruppe team. Your CV doesn't need to be up to date. Send what you have, or just give us a call.
Learn More
Berlin, Berlin

DevSecOps Engineer / Threat Hunter

DevSecOps Engineer / Threat Hunter The Opportunity Most security roles make you choose. Build the platform, or hunt on it. This one gives you both. You'll own a Google SecOps environment end to end, and you'll have the mandate to go looking for the activity nobody else has spotted. What you find won't sit in a report. It becomes detection logic that stops the next attempt. The organisation is actively investing in its security operations. That means your work shapes how detection is done here, rather than simply maintaining what someone else built. The Role Own the Google SecOps platform end to end: onboard new data sources, configure parsers and data models, and close gaps in telemetry quality. Turn your knowledge of adversary techniques into detection rules and use cases, reviewing them regularly to keep noise down. Set the agenda for proactive threat hunting, building hypotheses and following suspicious activity wherever it leads across the estate. Feed what you learn from every hunt back into the detection library. Work alongside SOC colleagues to raise the maturity of detection and response across the organisation. The split matters. Engineering time keeps the data trustworthy. Hunting time keeps you sharp. Each one makes the other better. The Company You'll join a well-established organisation that has made a deliberate decision to get ahead of attackers rather than react to them. This role sits at the centre of that effort. The remit is practical and hands-on, within an existing security operations team. You'll have colleagues to work with, a platform you're trusted to run, and a clear line between your work and the organisation's defensive posture. What You'll Need Hands-on engineering experience with Google SecOps (formerly Chronicle), including ingestion, parsing and data normalisation. Hypothesis-driven threat hunting experience, grounded in a detailed understanding of adversary behaviour and using MITRE ATT&CK as a working reference. The ability to assess log sources and telemetry for completeness and reliability. A practical approach to writing and tuning detection logic that keeps alert volumes meaningful without leaving blind spots. How to Apply If this sounds like the role you've been waiting for, get in touch with the MAM Gruppe team for a confidential conversation. Your CV doesn't need to be up to date. Send what you have, or just give us a call.
Learn More

Latest Blogs

View all blogs