As a Senior Third-Party Risk Management Specialist, you will join the Global Resilience Risk (GRR) sub-function within Group Risk & Compliance. You will be responsible for active risk stewardship and oversight of third-party risk across the enterprise.
Acting as a key advisor to First Line of Defense (1LOD) teams and Business & Function leads, you will ensure third-party risks—including vendor, supplier, outsourcing, and concentration risks—are identified, assessed, monitored, and kept within defined risk appetites.
Key Responsibilities
- Active Risk Management & Governance: Provide technical advice and oversight to ensure global business units understand and operate within the bank's defined Third-Party Risk Appetite.
- Control Environment Support: Partner with 1LOD control and risk owners to evaluate the effectiveness of key controls, driving continuous improvements in control design and execution.
- Emerging Risk Horizon Scanning: Monitor global macro and local regulatory environments to detect emerging third-party risks early and formulate practical control mitigants.
- Technical Guidance & Risk Translation: Translate complex third-party risk topics, risk assessments, and incident root-cause analyses into clear, non-technical language for senior business partners.
- Regulatory & Board Reporting: Deliver expert technical input for key regulatory, risk profile, and governance reports (e.g., Risk Appetite Statements, Risk Management Meetings, and Board reporting).
- Audit & Regulatory Engagement: Support audit and regulatory examinations pertaining to third-party risk management; oversee timely remediation of audit findings and regulatory recommendations.
- Risk Culture & Capability Uplift: Facilitate training and knowledge-sharing initiatives across Business & Function teams to strengthen third-party risk culture and awareness.
- Issue Escalation & Material Change Oversight: Identify root causes of operational risk events and escalated key control gaps or vulnerabilities arising from material change programs.
Key Qualifications & Skills
Experience & Knowledge:
- Financial Services Experience: Prior experience in Risk Management at a Globally Systemically Important Bank (GSIB) or Globally Significant Financial Institution (GSFI).
- Domain Technical Expertise: Deep technical understanding of end-to-end Third-Party Risk Management (TPRM), Vendor Management, Outsourcing Risk, and Operational Resilience.
- Regulatory Landscape: Strong familiarity with global financial regulations governing vendor management, operational resilience, and third-party risk oversight (e.g., PRA, FCA, DORA, OCC/Fed guidelines).
- Risk Frameworks: Thorough understanding of operational risk taxonomies, key control frameworks, and risk appetite mechanisms in complex matrix organizations.
Skills & Education:
- Technical Communication: Ability to articulate complex risk metrics and control frameworks clearly and persuasively to non-technical stakeholders.
- Stakeholder Influence: Strong diplomatic and influencing skills to challenge the status quo, drive change, and operate effectively within a multi-locational matrix structure.
- Education: Bachelor’s degree (BA/BS) required; Master’s Degree (MBA/MSc) or relevant professional certificates (e.g., CRISC, CTPRP, CISSP) highly preferred.