Third-Party Risk Specialist

Schillings

Greater London

On-site

GBP 60,000 - 90,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Schillings seeks a Third-Party Risk Specialist to own the firm’s supplier risk management framework, including due diligence, risk assessments and governance. You will coordinate onboarding and oversight, working with Risk & Compliance, Information Security, Data Protection, IT, Finance and Operations.

You will collaborate with stakeholders to ensure risks are identified, assessed and managed, maintaining records, driving improvements and facilitating supplier reviews across the firm.

Qualifications

  • 3 - 5 years’ experience in governance, supplier management, procurement or operational risk.
  • Strong working knowledge of risk management, information security and data protection principles.
  • Experience supporting supplier onboarding or procurement processes, including contractual negotiation.

Responsibilities

  • Onboarding Process: Embed and maintain adherence to the supplier onboarding process across the business; drive continual improvement; identify opportunities to streamline onboarding and oversight using AI and workflow automation.
  • Supplier Due Diligence, Assessment and Approvals: Liaise with stakeholders and suppliers; issue due diligence questionnaires; apply risk classification and due diligence methodology; conduct risk assessments with SME input; review documentation and coordinate controls.
  • Governance and Reporting: Maintain records and schedules; prepare reports and approvals; contribute to management information and committee reporting; coordinate supplier reviews and risk trends.
  • Key Competencies: Attention to detail, analytical thinking, organizational skills, multi-tasking, communication, stakeholder relationships, pragmatic negotiation, confidence with senior stakeholders.
  • Essential Experience: 3-5 years in governance, supplier management, procurement or operational risk; knowledge of risk, information security and data protection; onboarding experience; ability to translate complex issues into business recommendations.
  • Desirable Experience: Experience in law firm or regulated environments; GDPR knowledge; familiarity with risk assessment and governance frameworks; exposure to AI or supplier governance tools.

Skills

Governance
Supplier management
Risk management
Stakeholder management
Project coordination
Attention to detail
Communication
Information security
Data protection
Negotiation
OneTrust

Tools

OneTrust

Job description

Schillings handles high stakes opportunities and threats for an international clientele: successful individuals, businesses and high-profile organisations across the world.

We support our clients to achieve their goals by developing winning strategies to protect their freedom to operate, and are the first port of call in a crisis, defending our clients from attacks on their reputations, privacy and security. Schillings’ offer is unique to the market, combining strategic communications with law, intelligence & investigations, digital resilience and security.

Schillings is a collaborative and welcoming place to work, with a positive culture, strong values and a developed service ethic. We require commitment, diligence, curiosity, agility and professionalism, and in return provide competitive packages, stimulating challenges and interesting work. We are committed to sharing learning and creating development opportunities so you can progress your career with us. Our people’s career trajectories and average longevity at Schillings underline this.

Join us and become part of our story.

Role Purpose

The Third-Party Risk Specialist will have day-to-day ownership of the firm's third-party risk management framework, including supplier due diligence, risk assessments, stakeholder reviews, governance processes and ongoing supplier oversight.

The role will act as the central point of coordination for supplier onboarding and oversight, ensuring that appropriate information is gathered, risks are assessed by relevant subject matter experts, approvals are obtained and records are maintained throughout the supplier lifecycle.

The role will work closely with Risk & Compliance, Information Security, Data Protection, IT, Finance, Operations and business stakeholders to ensure third-party risks are identified, assessed and managed appropriately.

Key Responsibilities
Onboarding Process
  • Embedding and maintaining adherence to the supplier onboarding process across the business.
  • Driving continual improvement of the supplier onboarding process, including identifying opportunities to enhance efficiency, controls and user experience, and supporting the development of appropriate systems, workflows and reporting tools.
  • Identifying opportunities to streamline supplier onboarding and oversight processes through appropriate use of AI, automation and workflow optimisation.
Supplier Due Diligence, Assessment and Approvals
  • Liaising with internal stakeholders and with suppliers, advising on onboarding requirements and documentation required
  • Sending out due diligence questionnaires using the firm’s third-party due diligence software
  • Maintaining and applying the firm’s supplier risk classification and due diligence methodology, ensuring that the scope and frequency of assessments are proportionate to supplier criticality, data access, system connectivity and wider risk exposure.
  • Conducting risk assessments with input from subject matter experts including Information Security and Data Protection.
  • Reviewing due diligence and contractual documentation, identifying risk areas, coordinating specialist review where required and supporting the implementation of appropriate controls.
  • Tracking and recording the progress of supplier assessments and approvals.
  • Acting as a key user and administrator of supplier onboarding and due diligence platforms, including supporting process improvements, reporting and workflow automation.
Governance and Reporting
  • Maintaining accurate and up-to-date records, including:
  • Supplier Risk Register
  • CRM and third-party due diligence software
  • Renewal and review schedules
  • Assessment outcomes, approvals and key correspondence
  • Supplier risk findings, remediation actions, approval conditions, exceptions and risk acceptance, including owners and target dates
  • Initiating, managing and tracking periodic supplier reviews in line with agreed schedules and risk-based requirements.
  • Coordinating reassessment where there are material changes to the supplier, service, approved use case, data processing or changes impacting wider risk profile.
  • Identifying, assessing and escalating supplier incidents, concerns and changes in risk profile, ensuring appropriate follow-up action is taken.
  • Prepare reports, summaries and approval papers.
  • Contributing to management information and committee reporting, including supplier risk trends and emerging issues.
  • Contributing to the continued development of risk-based supplier management practices across the firm.
  • Coordinating and challenging stakeholders to ensure onboarding requests progress in a timely manner and required information is provided.
Key Competencies
  • Excellent attention to detail.
  • Strong analytical and problem-solving skills.
  • Strong organisational and project coordination skills.
  • Ability to manage multiple workstreams and competing priorities simultaneously.
  • Strong written and verbal communication skills.
  • Ability to build effective relationships across the business and with external suppliers.
  • Pragmatic and risk-aware negotiation and decision-making skills.
  • Confidence engaging with senior stakeholders.
Essential Experience
  • 3 - 5 years’ experience in a governance, supplier management, procurement or operational risk role.
  • Strong working knowledge of risk management, information security and data protection principles.
  • Experience supporting supplier onboarding or procurement processes, including contractual negotiation.
  • Experience gathering and analysing information from multiple sources.
  • Experience coordinating activities across different business teams.
  • Experience maintaining records, registers or governance documentation.
  • Strong organisational and administrative skills.
  • Ability to translate technical, legal, and operational issues into clear business recommendations.
Desirable Experience
  • Experience within a law firm, professional services or regulated environment.
  • Good working knowledge of UK and EU GDPR data protection principles.
  • Familiarity with risk assessment and governance approval frameworks.
  • Exposure to technology, AI or supplier governance and risk assessments.
  • Experience using OneTrust or similar third-party risk management, GRC or supplier onboarding platforms.
Life at Schillings

Given our bold and innovative business strategy, it is not surprising that Schillings has a very strong culture. The atmosphere is highly collaborative and focused on excellence. We have worked hard over the years to develop a coaching culture. Schillings has adopted a set of values to put at the heart of this and they reflect the intention and tenor of our ambitious plans. They are: ‘Innovative; Bold; United; and Excellent’. Our client list speaks for the outstanding results that have been delivered over many years and the task now is to grow without losing any of the commitment to delivering for clients or our service ethos. Finding people who share our values and can thrive in this environment is key to our success.

It takes a unique mix of people to create something truly great. We appreciate that diversity of thought, background and culture creates the best environment to truly innovate, solve problems and achieve our goals. We welcome candidates from all backgrounds – if you are driven and want to achieve your best then we will give you the platform and support to succeed.

Please let us know if there are any extenuating circumstances we should consider, or any adjustments we may need to make to our selection process, when making your application.

Find our candidate privacy notice here, Candidate Privacy Notice (schillingspartners.com)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk and Compliance Executive
Risk and Compliance Executive

Schillings • Greater London

On-site
GBP 35,000 - 40,000
Risk and Compliance Executive
Risk and Compliance Executive

Schillings • City Of London

On-site
GBP 50,000 - 70,000
Competitive packages
Coaching culture
Risk and Compliance Executive
Risk and Compliance Executive

Jobless • Greater London

Hybrid
GBP 35,000 - 40,000
Legal Senior Associate
Legal Senior Associate

Schillings • City Of London

On-site
GBP 60,000 - 80,000
Competitive salary
Career development opportunities
Collaborative working environment
Head of Digital Resilience (Acting)
Head of Digital Resilience (Acting)

Schillings • Greater London

On-site
GBP 90,000 - 150,000
Vendor Risk & Onboarding Specialist
Vendor Risk & Onboarding Specialist

Schillings • Greater London

On-site
GBP 60,000 - 90,000
Third Party Risk Analyst
Third Party Risk Analyst

Domestic & General • Wimbledon

Hybrid
GBP 45,000 - 65,000
Bonus potential
25 days annual leave
Pension scheme
+1
Third Party Risk Analyst
Third Party Risk Analyst

Domestic & General • Greater London

Hybrid
GBP 42,000 - 64,000
25 days annual leave
Health cash plan
Company pension
+3
Information Security Specialist
Information Security Specialist

Whereby • Glasgow

On-site
GBP 55,000 - 85,000
Third Party Security Due Diligence Lead
Third Party Security Due Diligence Lead

Swift Transportation • Greater London

On-site
GBP 90,000 - 120,000
Accessibility accommodations
Inclusive environment
Support for professional development