Third Party Risk Manager, REMOTE

  • Professional experience in Third Party Risk Management, cybersecurity risk, supplier risk, GRC, technology risk, or a related area.
  • Good understanding of third party cybersecurity risks and their potential impact on business operations, data protection, resilience, and regulatory compliance.
  • Knowledge of relevant cybersecurity frameworks, standards, and regulations, such as NIST CSF, ISO 27001, ISO 27036, DORA, NIS2, or equivalent.
  • Experience coordinating risk assessments, remediation activities, issue tracking, or third party monitoring processes.
  • Ability to work effectively with Procurement, Legal, Cybersecurity, IT, business stakeholders, and external partners.
  • Strong stakeholder management and influencing skills in complex, international, or matrix-based environments.
  • Experience with operational program coordination and cross-functional collaboration.
  • Ability to work with KPIs, dashboards, service indicators, and management reporting.
  • Strong analytical and problem-solving skills, with a focus on continuous process improvement.
  • Ability to translate risk and governance requirements into clear, practical guidance.
  • Structured, proactive, and independent working style.
  • Strong written and verbal English communication skills.

About the Role

We are looking for an experienced Third Party Risk & Governance Manager to support the development, implementation, and continuous improvement of cybersecurity risk management processes covering suppliers, service providers, partners, and other external parties.

The role combines third party cyber risk management, governance, stakeholder coordination, operational oversight, and process improvement. You will work with Cybersecurity, Procurement, Legal, IT, business teams, and external partners to ensure that third party risks are identified, assessed, monitored, and addressed consistently throughout the relationship lifecycle.

,[Support the implementation and ongoing development of third party cybersecurity risk management processes., Coordinate third party risk assessments, classification activities, risk reviews, and remediation follow-up., Work with internal stakeholders to ensure consistent application of risk management requirements and security standards., Build effective relationships with Cybersecurity, Procurement, Legal, IT, business teams, and external partners., Support operational activities related to third party onboarding, assessment, monitoring, and risk treatment., Track identified risks, findings, remediation plans, exceptions, and outstanding actions., Monitor program effectiveness using KPIs, dashboards, progress reports, and management updates., Ensure that high-risk third parties and services receive appropriate attention and oversight., Identify process gaps, operational bottlenecks, and opportunities to improve efficiency, scalability, and risk visibility., Develop and maintain procedures, guidance materials, reporting standards, and governance documentation., Support risk escalation and decision-making related to third party cybersecurity exposure., Coordinate activities delivered by internal teams and external service providers., Translate governance requirements into practical actions that can be understood and applied by different stakeholder groups., Promote a consistent, risk-based approach to third party cybersecurity management.] Requirements: Third Party Risk Management, Cybersecurity Risk, Cybersecurity, Supplier Risk, Technology risk, NIST CSF, ISO 270001, ISO 27036, DORA, NIS2, Procurement, Legal, Stakeholder management, KPI, Analytical skills, Problem-Solving, Communication skills
Data publikacji: 2026-07-28
APLIKUJ