Third-Party Risk Management Analyst
⚲ Warszawa
13 440 - 14 952 PLN netto (B2B)
Wymagania
- Vendor Risk Management
- Vendor Cybersecurity Assessments
- IT Risk Management
- NIST/ISO 27001
- Due Diligence Reviews
- Third-party risk management
- Cybersecurity Risk Assessment
Opis stanowiska
Location: Hybrid work model - 2 days per week from the client’s office in Warsaw
Availability: ASAP / within 1 month
Contract Type: B2B via Experis
About the Role:
We are looking for a Third-Party Risk Management Analyst to support and enhance our Third-Party Risk Management (TPRM) program. In this role, you will be responsible for conducting risk-based due diligence, performing cybersecurity assessments, and monitoring supplier risk throughout the vendor lifecycle. You will work closely with cross-functional teams to identify, assess, and manage third-party risks while ensuring compliance with enterprise risk, security, and regulatory requirements.
Responsibilities:
Risk Assessment & Due Diligence
• Perform cybersecurity and risk assessments of third parties using standardized frameworks
• Evaluate suppliers' security posture, controls, and compliance with internal requirements
• Analyze risks across multiple domains, including information security, data privacy, and business continuity
• Assign risk ratings and document findings in accordance with TPRM standards
Risk Identification & Issue Management
• Identify control gaps, vulnerabilities, and areas of elevated risk
• Document and track remediation actions with suppliers and internal stakeholders
• Escalate high-risk findings in line with defined risk thresholds and procedures
Ongoing Monitoring
• Support continuous monitoring activities, including review of threat intelligence, security ratings, and supplier updates
• Track changes in vendor risk posture over time
• Assist in periodic reassessments based on risk tiering
Stakeholder Engagement
• Partner with Procurement, Information Security, Legal, and business stakeholders to support risk-based decision making
• Communicate assessment results clearly to both technical and non-technical audiences
Program Support & Documentation
• Maintain accurate records of assessments, decisions, and supporting evidence
• Ensure all activities align with TPRM policies, standards, and regulatory expectations, including DORA, NIST, and ISO frameworks
• Support audit and regulatory inquiries by providing required documentation
Requirements:
• 3–5 years of experience in Third-Party Risk Management, Cybersecurity Risk Management, or IT Risk
• Hands-on experience conducting vendor cybersecurity assessments or due diligence reviews
• Familiarity with industry frameworks and standards such as NIST, ISO 27001, and SOC 2
• Strong analytical and problem-solving skills
• Ability to assess risk and make recommendations based on incomplete or evolving information
• Excellent written and verbal communication skills
• Ability to effectively communicate with both technical and non-technical stakeholders
• Strong attention to detail and organizational skills
Offer:
• Multisport card
• Private healthcare (Medicover)
• Access to an e learning platform
• Group life insurance
Availability: ASAP / within 1 month
Contract Type: B2B via Experis
About the Role:
We are looking for a Third-Party Risk Management Analyst to support and enhance our Third-Party Risk Management (TPRM) program. In this role, you will be responsible for conducting risk-based due diligence, performing cybersecurity assessments, and monitoring supplier risk throughout the vendor lifecycle. You will work closely with cross-functional teams to identify, assess, and manage third-party risks while ensuring compliance with enterprise risk, security, and regulatory requirements.
Responsibilities:
Risk Assessment & Due Diligence
• Perform cybersecurity and risk assessments of third parties using standardized frameworks
• Evaluate suppliers' security posture, controls, and compliance with internal requirements
• Analyze risks across multiple domains, including information security, data privacy, and business continuity
• Assign risk ratings and document findings in accordance with TPRM standards
Risk Identification & Issue Management
• Identify control gaps, vulnerabilities, and areas of elevated risk
• Document and track remediation actions with suppliers and internal stakeholders
• Escalate high-risk findings in line with defined risk thresholds and procedures
Ongoing Monitoring
• Support continuous monitoring activities, including review of threat intelligence, security ratings, and supplier updates
• Track changes in vendor risk posture over time
• Assist in periodic reassessments based on risk tiering
Stakeholder Engagement
• Partner with Procurement, Information Security, Legal, and business stakeholders to support risk-based decision making
• Communicate assessment results clearly to both technical and non-technical audiences
Program Support & Documentation
• Maintain accurate records of assessments, decisions, and supporting evidence
• Ensure all activities align with TPRM policies, standards, and regulatory expectations, including DORA, NIST, and ISO frameworks
• Support audit and regulatory inquiries by providing required documentation
Requirements:
• 3–5 years of experience in Third-Party Risk Management, Cybersecurity Risk Management, or IT Risk
• Hands-on experience conducting vendor cybersecurity assessments or due diligence reviews
• Familiarity with industry frameworks and standards such as NIST, ISO 27001, and SOC 2
• Strong analytical and problem-solving skills
• Ability to assess risk and make recommendations based on incomplete or evolving information
• Excellent written and verbal communication skills
• Ability to effectively communicate with both technical and non-technical stakeholders
• Strong attention to detail and organizational skills
Offer:
• Multisport card
• Private healthcare (Medicover)
• Access to an e learning platform
• Group life insurance
🔍 Dekoder Ogłoszenia
🔴
support and enhance our Third-Party Risk Management (TPRM) program
Prawdopodobnie będziesz musiał wdrażać i usprawniać istniejące procesy, a nie tylko je wykonywać.
🟡
work closely with cross-functional teams
Spodziewaj się dużej liczby spotkań i konieczności koordynacji działań z wieloma różnymi działami.
🟡
ensuring compliance with enterprise risk, security, and regulatory requirements
Praca będzie wymagała ścisłego przestrzegania wewnętrznych polityk i zewnętrznych przepisów, co może oznaczać biurokrację.
🟡
Identify control gaps, vulnerabilities, and areas of elevated risk
Twoim głównym zadaniem będzie znajdowanie problemów, a niekoniecznie ich rozwiązywanie.
🟡
Escalate high-risk findings in line with defined risk thresholds and procedures
Będziesz odpowiedzialny za zgłaszanie problemów, ale faktyczne decyzje o ich rozwiązaniu mogą leżeć po stronie innych osób.