Senior Third-Party Risk Specialist

Mistral

Paris

Sur place

EUR 90 000 - 120 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Healthcare coverage
Parental leave
Retirement plans
Relocation support
Wellness programs
Meal and transportation allowances
Other location-specific perks

Résumé du poste

Mistral is seeking a Senior Third-Party Risk Specialist to identify, assess and mitigate risks from vendors, partners, and subcontractors. You will work with Legal, Procurement, Security and Operations to embed robust risk management across the business and ensure regulatory compliance.

You will lead due diligence, audits, and contractual reviews, and stay ahead of evolving standards like GDPR, NIS2, and the Cyber Resilience Act while maintaining thorough documentation and training for

Qualifications

  • 7+ years in third-party risk management, cybersecurity compliance, information security governance, or related field.
  • Experience supporting cybersecurity compliance programs, certification processes, or external audits.
  • Practical knowledge of standards and frameworks such as ISO 27001, SOC 2, NIST SP 800-53, or regulations like NIS2, DORA, GDPR.
  • Proficiency in risk assessment methodologies (e.g., EBIOS RM, ISO 27005).
  • Familiarity with regulations such as NIS2, Cyber Resilience Act, LPM, or DORA.
  • Strong organizational skills and attention to detail, with ability to manage documentation.
  • Excellent written and verbal communication skills.
  • Strong analytical and problem-solving abilities.
  • Ability to work collaboratively across technical, legal, commercial, and operational teams.
  • Professional proficiency in English; French proficiency is a plus.

Responsabilités

  • Identify, assess, and mitigate risks with third parties (vendors, partners, subcontractors).
  • Embed proactive third-party risk management into business processes with Legal, Procurement, Security, and Operations.
  • Digitally document assessments, decisions, and actions for audits and compliance.
  • Lead training and guidance on third-party risk issues for internal teams.
  • Monitor regulatory evolution (NIS2, Cyber Resilience Act, GDPR) and adjust the framework accordingly.

Connaissances

7+ years experience in TPRM
Cybersecurity compliance
ISO 27001 / SOC 2
NIS2 / DORA / GDPR
Risk assessment methods
English proficiency
Communication skills
Analytical skills
Collaborative work across teams
French proficiency (a plus)

Description du poste

About Mistral

Mistral provides full-stack AI solutions: from frontier models to developer tools, applications, and compute. We partner with enterprises tackling the hardest problems—across high-stakes industries like finance, manufacturing, defense, healthcare, and the public sector—co-creating customized AI systems that they can run on their terms.

About Mistral

Mistral provides full-stack AI solutions: from frontier models to developer tools, applications, and compute. We partner with enterprises tackling the hardest problems—across high-stakes industries like finance, manufacturing, defense, healthcare, and the public sector—co-creating customized AI systems that they can run on their terms. We are a dynamic, collaborative team passionate about AI and its potential to transform society. Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between Europe, North America, Asia and the Middle East. We are creative, low-ego and team-spirited.

Role summary

As a Senior Third-Party Risk Specialist, you will be responsible for identifying, assessing, and mitigating risks associated with third parties (vendors, partners, subcontractors, etc.) at Mistral. You will play a pivotal role in safeguarding our assets, data, and reputation by ensuring that our third-party relationships adhere to the highest standards of security, compliance, and resilience. You will work closely with Legal, Procurement, Security, and Operational teams to embed a proactive third-party risk management approach into our business processes.

What you will do
  • Develop and manage the third-party risk management program: Design, implement, and maintain a structured framework for identifying, assessing, and monitoring risks associated with third parties (vendors, partners, service providers, etc.).
  • Conduct third-party assessments and audits: Perform due diligence, compliance assessments, security audits, and contractual reviews to ensure third parties meet our requirements and regulatory obligations (e.g., GDPR, NIS2, DORA).
  • Collaborate with internal teams: Work with Procurement, Legal, Security, and Operations teams to integrate third-party risk requirements into vendor selection, negotiation, and monitoring processes.
  • Manage incidents and non-compliance: Identify and address gaps or incidents related to third parties, coordinating corrective actions and ensuring follow-up until resolution.
  • Raise awareness and train stakeholders: Develop and deliver training and guidance to educate internal teams on third-party risk issues and their responsibilities.
  • Maintain robust documentation: Document assessments, decisions, and actions related to third-party risk management, ensuring traceability for internal and external audits.
  • Monitor regulatory and standards evolution: Stay updated on changes in regulations (e.g., NIS2, Cyber Resilience Act, GDPR) and standards (e.g., ISO 27001, SOC 2, ISO 27036) impacting third-party risk management, and propose adjustments to the internal framework.
  • Optimize tools and processes: Contribute to the continuous improvement of tools (e.g., third-party risk management platforms) and methodologies to enhance the program's effectiveness.
  • Align with broader resilience strategy: Ensure the third-party risk management program supports the company's overall cybersecurity and compliance objectives.
  • Contract redlining and negotiation skills: Ability to review, edit, and negotiate contractual terms to align with security and compliance requirements.
About you
  • 7+ years in third-party risk management, cybersecurity compliance, information security governance, or a related field.
  • Experience supporting cybersecurity compliance programs, certification processes, or external audits.
  • Practical knowledge of standards and frameworks such as ISO 27001, SOC 2, NIST SP 800-53, or regulations like NIS2, DORA, GDPR.
  • Proficiency in risk assessment methodologies (e.g., EBIOS RM, ISO 27005).
  • Familiarity with cybersecurity regulations such as NIS2, the Cyber Resilience Act, LPM, or DORA.
  • Strong organizational skills and attention to detail, with the ability to manage documentation and coordinate multiple stakeholders.
  • Excellent written and verbal communication skills.
  • Strong analytical and problem-solving abilities.
  • Ability to work collaboratively across technical, legal, commercial, and operational teams.
  • Professional proficiency in English; French proficiency is a plus.
What we offer

We offer a comprehensive benefits package designed to support your well-being, growth, and work-life balance.

  • healthcare coverage
  • parental leave
  • retirement plans
  • relocation support
  • wellness programsmeal and transportation allowances
  • other location-specific perks

For the most up-to-date details on benefits available in your location, please refer to our Benefits page.

Privacy Policy

Your privacy matters to us. You can learn more about how we handle your personal data in our Applicant Privacy Policy.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Compliance Specialist
Security Compliance Specialist

Mistral • Paris

Sur place
EUR 80 000 - 110 000
Healthcare coverage
Parental leave
Relocation support
Security Compliance, GRC Engineer
Security Compliance, GRC Engineer

Mistral • Paris

Sur place
EUR 70 000 - 110 000
Security Compliance Specialist
Security Compliance Specialist

Mistral Ai • Paris

Sur place
EUR 75 000 - 100 000
Healthcare coverage
Parental leave
Relocation support
+2
Deputy Director, Safety & Security HQ
Deputy Director, Safety & Security HQ

Mistral AI • Paris

Sur place
EUR 120 000 - 190 000
Healthcare coverage
Relocation support
Wellness programs
Deputy Director, Safety & Security HQ
Deputy Director, Safety & Security HQ

Mistral • Paris

Sur place
EUR 1 000 000 - 3 000 000
Deputy Director, Safety & security HQ
Deputy Director, Safety & security HQ

Mistral • Paris

Sur place
EUR 75 000 - 100 000
Healthcare coverage
Parental leave
Relocation support
+1
Deputy Director, Safety & Security HQ
Deputy Director, Safety & Security HQ

jobr.pro • Paris

Sur place
EUR 60 000 - 80 000
Healthcare coverage
Parental leave
Retirement plans
+4
Director of Internal Control
Director of Internal Control

Mistral AI • Paris

Sur place
EUR 100 000 - 160 000
Privacy Legal Counsel
Privacy Legal Counsel

Mistral AI • Paris

Sur place
EUR 90 000 - 120 000
Healthcare coverage
Parental leave
Retirement plans
+1
Security Compliance, GRC Engineer
Security Compliance, GRC Engineer

Mistral • Paris

Hybride
EUR 70 000 - 100 000
Benefits package