Join to apply for the Third Party Risk & Assurance Specialist role at IOVENDO
3 weeks ago Be among the first 25 applicants
Get AI-powered advice on this job and more exclusive features.
Third Party Risk & Assurance Specialist London 3 month contract Excellent day rate
We are seeking a specialist in third party risk and assurance, with experience across various types of technology service providers. This is a multi-faceted role supporting both a Technology Transformation Programme as well as maintaining oversight over current operational technology and applications.
This role will suit someone who has managed vendors previously, or someone with equivalent practical experience in providing technology and security assurance for clients, who is looking to grow into a GRC role and potentially beyond third party risk.
Key Responsibilities
- Develop and maintain third party governance and risk management frameworks.
- Support the development and implementation of third party policies and governance controls with other functions, e.g., Finance, Legal, Procurement, Security, Architecture, Risk.
- Develop technology service and operational risk considerations for supplier tier classification definitions.
- Review existing technology supplier due diligence and work with SME functions to streamline the process.
- Create and maintain a risk taxonomy and reference library to support third party risk identification and assessment for technology.
- Ensure all Technology and Application change involving third parties follow policies, standards, and governance procedures, supporting various stage gate assessments including business case and design reviews, operational readiness, and service transition.
- Coordinate procurement due diligence and supplier risk assessments.
- Work with multiple functions to understand business use cases, and plan for timely third party due diligence and risk assessments.
- Review and support relevant architecture and integration plans, including internal operational process change.
- Manage inherent risk levels for prospective third-party relationships, coordinating with teams on tier classification.
- Oversee data protection compliance during due diligence, including privacy and security requirements.
- Evaluate third parties' compliance obligations and impact on overall compliance posture.
- Produce and review due diligence risk reports, capturing trends and KRIs for management.
- Support contractual negotiations and renewals, providing SME input.
- Assist in operational readiness and risk assessments for onboarding third parties.
- Conduct ongoing third-party risk management and monitoring, including vulnerability assessments and exit planning.
- Develop and implement asset management and control assurance strategies, maintaining a third-party risk register.
- Manage supplier control assurance programs, including rights-to-audit and action plan tracking.
- Support internal risk frameworks, including risk assessments and policy exception management.
- Oversee risk events and incident management involving third parties.
- Prepare and present reports on third-party governance, performance, and risk.
- Promote learning and awareness through training and research into new risk and assurance techniques.
Additional Details
- Seniority level: Mid-Senior level
- Employment type: Contract
- Job function: Accounting/Auditing and Finance
- Industry: Banking