
Senior Third-Party Risk Management Consultant
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Jordan.
• Evaluate and manage risks throughout the entire vendor lifecycle, starting from onboarding and due diligence to ongoing monitoring and offboarding.
• Analyze third-party risks related to cybersecurity, technology, operations, privacy, compliance, and resilience.
• Monitor findings and remediation efforts while enhancing TPRM frameworks and reporting mechanisms.
• Assist in the planning and execution of Third-Party Risk Management projects, ensuring alignment with objectives, methodologies, and delivery schedules.
• Conduct inherent and residual risk assessments for third parties, vendors, service providers, partners, and outsourced services.
• Carry out risk-based due diligence evaluations for both new and existing third-party relationships.
• Assess third-party security controls, governance practices, and compliance posture against customer demands, regulatory requirements, and industry standards.
• Review vendor assessment responses, supporting documentation, audit reports, certifications, and independent assurance reports.
• Facilitate vendor risk assessments during onboarding, periodic reassessments, contract renewals, significant changes, and offboarding processes.
• Identify and evaluate risks linked to cloud services, managed services, SaaS platforms, telecommunications providers, and strategic technology partners.
• Assess concentration, dependency, fourth-party, and critical supplier risks.
• Collaborate with procurement, legal, cybersecurity, compliance, privacy, and business stakeholders.
• Create and maintain third-party risk registers, assessment records, risk exceptions, remediation plans, and governance documentation.
• Track findings, remediation actions, and risk treatment strategies.
• Facilitate processes for third-party risk acceptance and exceptions.
• Conduct ongoing monitoring of critical and high-risk vendors.
• Evaluate third-party business continuity, disaster recovery, and operational resilience capabilities.
• Review contractual security and risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification requirements.
• Contribute to the development and enhancement of TPRM frameworks, methodologies, procedures, standards, and assessment templates.
• Analyze vendor risk trends, assessment results, and risk exposures.
• Prepare management reports, dashboards, risk metrics, and executive presentations.
• Foster awareness and adherence to TPRM requirements.
• Ensure compliance with customer policies, regulatory requirements, and industry standards concerning vendor risk management, cybersecurity, operational resilience, and supply chain security.
• Collaborate closely with procurement, legal, cybersecurity, compliance, and business teams to facilitate informed vendor decision-making.
• 8–10 years of relevant experience.
• Proficiency in both Arabic and English, with strong written and verbal communication skills.
• Extensive experience in third-party risk management (TPRM), including vendor due diligence, inherent and residual risk assessments, and risk-based reviews throughout the vendor lifecycle.
• Experience in evaluating cybersecurity, technology, operational, compliance, privacy, and business continuity risks associated with third parties.
• Ability to assess vendor security controls using evaluation responses, supporting documentation, audit reports, certifications, and independent assurance reports.
• Experience in managing vendor risk registers, findings, remediation plans, risk acceptance, and exceptions.
• Knowledge of risks related to cloud services, SaaS platforms, managed services, and other technology providers, including concentration and fourth-party risk.
• Experience in assessing third-party business continuity, disaster recovery, and operational resilience capabilities.
• Familiarity with contractual risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification.
• Experience in developing or refining TPRM frameworks, procedures, assessment methodologies, and reporting structures.
• Understanding of applicable NCA controls, privacy requirements, cybersecurity standards, and vendor risk regulations.
• 2-year project engagement.
• Access to the Global Consulting Bootcamp.
• Access to the MC Club.
Destinus
TruBridge
American Health Marketplace
Old Republic Title
Get handpicked remote jobs straight to your inbox weekly.