- Undertaking thorough risk assessments and checks on third-party vendors and suppliers and identifying potential data privacy, cybersecurity or financial health related risks and determine the impact of these risks on the business
- Monitoring the compliance with policies, procedures and requirements, governing the implementing of the TPRM Framework and policies including ones relating to onboarding and offboarding, whilst also supporting the development of exit plans for the potential needs in cases of contract termination
- Overseeing third-party performance and compliance against contractual obligations, including SLAs and controls, as well as tracking potential and ongoing third-party risks, whilst providing regular reported updates to senior management and maintaining all information required on a database of third-party risk assessments and performance metrics
- Ensuring compliance with regulations such as DORA and GDPR as well as industry standards, by conducting regular audits and assessments and collaborating with the legal teams to ensure that all vendor contracts include relevant information and narrative about risk and security clauses
- Appropriately investigating third-party related incidents and updating the incident response plans as needed in relation to this
- Supporting third-party vendors to address risks that have been identified and ensure appropriate action has been taken, ensuring that risk mitigation strategies have been implemented and that any critical risks are escalated
- Acting as a key point of contact and liaison for third-party vendors and stakeholders to ensure that affective communication is maintained regarding risks at all times
- Experience gained from within a fully regulated industry
- Specific knowledge and experience of third-party risk management frameworks and best practices
- Substantial experience conducting risk assessments and audits on suppliers, vendors and partners
- Have knowledge of regulations and industry standards such as GDPR, DORA and ISO 27001
- Knowledge of information security
- Any relevant qualifications related to risk management and information security