Senior Third-Party Risk Management Consultant
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior consultant assessing and managing third-party vendor risks across cybersecurity, compliance, privacy, and resilience. Strengthening TPRM frameworks, monitoring, remediation, and executive reporting.
Responsibilities:
- Assess and manage risks across the full vendor lifecycle, from onboarding and due diligence through ongoing monitoring and offboarding
- Evaluate third-party cybersecurity, technology, operational, privacy, compliance, and resilience risks
- Track findings and remediation and strengthen TPRM frameworks and reporting
- Support planning and execution of Third-Party Risk Management engagements in alignment with project objectives, methodologies, and delivery timelines
- Conduct inherent and residual risk assessments for third parties, vendors, service providers, partners, and outsourced services
- Perform risk-based due diligence reviews for new and existing third-party engagements
- Evaluate third-party security controls, governance practices, and compliance posture against customer requirements, regulatory obligations, and industry standards
- Review vendor assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports
- Facilitate vendor risk assessments throughout onboarding, periodic reassessments, contract renewals, significant changes, and offboarding
- Identify and assess risks associated with cloud services, managed services, SaaS platforms, telecommunications providers, and strategic technology partners
- Evaluate concentration, dependency, fourth-party, and critical supplier risks
- Collaborate with procurement, legal, cybersecurity, compliance, privacy, and business stakeholders
- Develop and maintain third-party risk registers, assessment records, risk exceptions, remediation plans, and governance documentation
- Track findings, remediation actions, and risk treatment plans
- Facilitate third-party risk acceptance and exception processes
- Perform ongoing monitoring of critical and high-risk vendors
- Assess third-party business continuity, disaster recovery, and operational resilience capabilities
- Review contractual security and risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification requirements
- Support development and enhancement of TPRM frameworks, methodologies, procedures, standards, and assessment templates
- Analyze vendor risk trends, assessment outcomes, and risk exposures
- Prepare management reports, dashboards, risk metrics, and executive presentations
- Promote awareness and adoption of TPRM requirements
- Ensure alignment with customer policies, regulatory requirements, and industry frameworks related to vendor risk management, cybersecurity, operational resilience, and supply chain security
- Work closely with procurement, legal, cybersecurity, compliance, and business teams to support informed vendor decisions
Requirements:
- 8–10 years of experience
- Fluency in Arabic and English, written and spoken
- Strong experience in third-party risk management (TPRM), including vendor due diligence, inherent and residual risk assessments, and risk-based reviews throughout the vendor lifecycle
- Experience assessing cybersecurity, technology, operational, compliance, privacy, and business continuity risks associated with third parties
- Ability to evaluate vendor security controls using assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports
- Experience managing vendor risk registers, findings, remediation plans, risk acceptance, and exceptions
- Knowledge of risks associated with cloud services, SaaS platforms, managed services, and other technology providers, including concentration and fourth-party risk
- Experience assessing third-party business continuity, disaster recovery, and operational resilience capabilities
- Familiarity with contractual risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification
- Experience developing or improving TPRM frameworks, procedures, assessment methodologies, and reporting
- Knowledge of applicable NCA controls, privacy requirements, cybersecurity standards, and vendor risk regulations
Benefits:
- 2-year project engagement
- Access to the Global Consulting Bootcamp
- Access to the MC Club











