Third Party Risk Manager
About the Role
We are looking for an experienced Third Party Risk & Governance Manager to support the development, implementation, and continuous improvement of cybersecurity risk management processes covering suppliers, service providers, partners, and other external parties.
The role combines third party cyber risk management, governance, stakeholder coordination, operational oversight, and process improvement. You will work with Cybersecurity, Procurement, Legal, IT, business teams, and external partners to ensure that third party risks are identified, assessed, monitored, and addressed consistently throughout the relationship lifecycle.
- Professional experience in Third Party Risk Management, cybersecurity risk, supplier risk, GRC, technology risk, or a related area.
- Good understanding of third party cybersecurity risks and their potential impact on business operations, data protection, resilience, and regulatory compliance.
- Knowledge of relevant cybersecurity frameworks, standards, and regulations, such as NIST CSF, ISO 27001, ISO 27036, DORA, NIS2, or equivalent.
- Experience coordinating risk assessments, remediation activities, issue tracking, or third party monitoring processes.
- Ability to work effectively with Procurement, Legal, Cybersecurity, IT, business stakeholders, and external partners.
- Strong stakeholder management and influencing skills in complex, international, or matrix-based environments.
- Experience with operational program coordination and cross-functional collaboration.
- Ability to work with KPIs, dashboards, service indicators, and management reporting.
- Strong analytical and problem-solving skills, with a focus on continuous process improvement.
- Ability to translate risk and governance requirements into clear, practical guidance.
- Structured, proactive, and independent working style.
- Strong written and verbal English communication skills.