Third-Party Risk Management Analyst
Location: Hybrid work model - 2 days per week from the Warsaw office or 1 day per month for Candidates based outside Warsaw
Availability: ASAP / within 1 month
Contract Type: B2B via Experis
About the Role:
We are looking for a Third-Party Risk Management Analyst to join a global team responsible for conducting vendor risk assessments and security reviews as part of the organization's Third-Party Risk Management (TPRM) program. You will support the onboarding and ongoing monitoring of vendors by performing risk-based due diligence, evaluating security controls, and identifying potential risks across the supplier ecosystem.
This role is ideal for professionals with experience in vendor reviews, information security assessments, and third-party risk management, preferably within a financial services environment.
Responsibilities:
Vendor Risk Assessments & Due Diligence
Conduct risk-based due diligence and security reviews of prospective and existing vendors
Perform cybersecurity and information security assessments using established frameworks and methodologies
Evaluate suppliers’ security controls, policies, governance practices, and overall risk posture
Assess risks across multiple domains, including information security, data privacy, operational resilience, and business continuity
Assign and document risk ratings, findings, and recommendations in accordance with TPRM standards
Risk Identification & Remediation
Identify control gaps, vulnerabilities, and areas of elevated risk
Review vendor responses and supporting documentation
Track remediation activities and collaborate with suppliers to address identified issues
Escalate high-risk findings in line with established governance processes
Ongoing Monitoring
Support ongoing monitoring of third-party risk throughout the vendor lifecycle
Participate in periodic reassessments of vendors based on risk tiering and business requirements
Monitor changes in vendor risk profiles and emerging security threats
Stakeholder Collaboration
Partner with Procurement, Information Security, Legal, Compliance, and business stakeholders
Provide risk-based recommendations to support onboarding and vendor management decisions
Present assessment outcomes clearly to both technical and non-technical audiences
Documentation & Governance
Maintain accurate assessment records and supporting evidence
Ensure compliance with internal policies, regulatory requirements, and industry standards
Support audits and reviews by providing relevant risk and assessment documentation
Requirements:
3–5 years of experience in Third-Party Risk Management, Vendor Risk Management, Information Security, Cybersecurity, IT Risk, or a related field
Hands-on experience conducting vendor reviews, supplier due diligence, and third-party risk assessments
Previous experience within a financial institution, banking, financial services, or fintech environment
Experience performing information security or cybersecurity reviews of vendors
Strong understanding of risk assessment methodologies and security controls
Excellent analytical and problem-solving skills
Ability to assess risks and provide practical, risk-based recommendations
Strong communication and stakeholder management skills
Ability to work effectively in a global environment
Nice to Have:
Relevant certifications such as:
CTPRP (Certified Third Party Risk Professional)
Other Risk Assessment certifications
Familiarity with frameworks and standards such as NIST, ISO 27001, SOC 2, DORA, or similar
What We Offer:
Participation in a global Third-Party Risk Management function
Exposure to a high-volume and mature vendor risk environment
Multisport card
Private healthcare (Medicover)
Access to an e-learning platform
Group life insurance
Hybrid working model with occasional meetings aligned to US time zones
Opportunity to work with international stakeholders and teams worldwide