Third-Party Risk Management Analyst

Open 17d

Location: Hybrid work model - 2 days per week from the Warsaw office or 1 day per month for Candidates based outside Warsaw
Availability: ASAP / within 1 month
Contract Type: B2B via Experis

About the Role:

We are looking for a Third-Party Risk Management Analyst to join a global team responsible for conducting vendor risk assessments and security reviews as part of the organization's Third-Party Risk Management (TPRM) program. You will support the onboarding and ongoing monitoring of vendors by performing risk-based due diligence, evaluating security controls, and identifying potential risks across the supplier ecosystem.
This role is ideal for professionals with experience in vendor reviews, information security assessments, and third-party risk management, preferably within a financial services environment.

Responsibilities:

Vendor Risk Assessments & Due Diligence

  • Conduct risk-based due diligence and security reviews of prospective and existing vendors

  • Perform cybersecurity and information security assessments using established frameworks and methodologies

  • Evaluate suppliers’ security controls, policies, governance practices, and overall risk posture

  • Assess risks across multiple domains, including information security, data privacy, operational resilience, and business continuity

  • Assign and document risk ratings, findings, and recommendations in accordance with TPRM standards


Risk Identification & Remediation

  • Identify control gaps, vulnerabilities, and areas of elevated risk

  • Review vendor responses and supporting documentation

  • Track remediation activities and collaborate with suppliers to address identified issues

  • Escalate high-risk findings in line with established governance processes


Ongoing Monitoring

  • Support ongoing monitoring of third-party risk throughout the vendor lifecycle

  • Participate in periodic reassessments of vendors based on risk tiering and business requirements

  • Monitor changes in vendor risk profiles and emerging security threats


Stakeholder Collaboration

  • Partner with Procurement, Information Security, Legal, Compliance, and business stakeholders

  • Provide risk-based recommendations to support onboarding and vendor management decisions

  • Present assessment outcomes clearly to both technical and non-technical audiences


Documentation & Governance

  • Maintain accurate assessment records and supporting evidence

  • Ensure compliance with internal policies, regulatory requirements, and industry standards

  • Support audits and reviews by providing relevant risk and assessment documentation


Requirements:

  • 3–5 years of experience in Third-Party Risk Management, Vendor Risk Management, Information Security, Cybersecurity, IT Risk, or a related field

  • Hands-on experience conducting vendor reviews, supplier due diligence, and third-party risk assessments

  • Previous experience within a financial institution, banking, financial services, or fintech environment

  • Experience performing information security or cybersecurity reviews of vendors

  • Strong understanding of risk assessment methodologies and security controls

  • Excellent analytical and problem-solving skills

  • Ability to assess risks and provide practical, risk-based recommendations

  • Strong communication and stakeholder management skills

  • Ability to work effectively in a global environment


Nice to Have:


Relevant certifications such as:

  • CTPRP (Certified Third Party Risk Professional)

  • Other Risk Assessment certifications

  • Familiarity with frameworks and standards such as NIST, ISO 27001, SOC 2, DORA, or similar


What We Offer:

  • Participation in a global Third-Party Risk Management function

  • Exposure to a high-volume and mature vendor risk environment

  • Multisport card

  • Private healthcare (Medicover)

  • Access to an e-learning platform

  • Group life insurance

  • Hybrid working model with occasional meetings aligned to US time zones

  • Opportunity to work with international stakeholders and teams worldwide