Third-Party Risk Manager

mthree

Kraków

On-site

PLN 180,000 - 260,000

Full time

8 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

mthree is seeking a Senior Third-Party Risk Management Specialist to join the Global Resilience Risk (GRR) sub-function within Group Risk & Compliance. You will be responsible for active risk stewardship and oversight of third-party risk across the enterprise.

You will advise 1LOD teams and business leads to ensure vendor, supplier, outsourcing, and concentration risks are identified, assessed, monitored, and kept within defined risk appetites.

Qualifications

  • Experience in risk management at a GSIB/GSFI level.
  • End-to-end Third-Party Risk Management, Vendor Management, Outsourcing Risk, and Operational Resilience.
  • Familiarity with PRA, FCA, DORA, OCC/Fed guidelines.
  • Understanding of operational risk taxonomies and risk appetite in matrix organizations.

Responsibilities

  • Provide risk governance and oversight of third-party risk across the enterprise.
  • Advise 1LOD teams and business leads on risk appetite and risk governance.
  • Identify, assess, monitor, and report third-party risks (vendor, supplier, outsourcing, concentration).
  • Support regulatory reporting and governance meetings (Risk Appetite Statements, Board reporting).
  • Assist audit and regulatory engagements and remediation of findings.
  • Foster risk culture and capability uplift across Business & Function teams.
  • Escalate issues and oversee material change risk arising from changes.

Skills

Technical Communication
Stakeholder Influence
Regulatory Knowledge

Education

Bachelor's degree
Master's degree / certificates

Job description

As a Senior Third-Party Risk Management Specialist, you will join the Global Resilience Risk (GRR) sub-function within Group Risk & Compliance. You will be responsible for active risk stewardship and oversight of third-party risk across the enterprise.

Acting as a key advisor to First Line of Defense (1LOD) teams and Business & Function leads, you will ensure third-party risks—including vendor, supplier, outsourcing, and concentration risks—are identified, assessed, monitored, and kept within defined risk appetites.

Key Responsibilities
  • Active Risk Management & Governance: Provide technical advice and oversight to ensure global business units understand and operate within the bank's defined Third-Party Risk Appetite.
  • Control Environment Support: Partner with 1LOD control and risk owners to evaluate the effectiveness of key controls, driving continuous improvements in control design and execution.
  • Emerging Risk Horizon Scanning: Monitor global macro and local regulatory environments to detect emerging third-party risks early and formulate practical control mitigants.
  • Technical Guidance & Risk Translation: Translate complex third-party risk topics, risk assessments, and incident root-cause analyses into clear, non-technical language for senior business partners.
  • Regulatory & Board Reporting: Deliver expert technical input for key regulatory, risk profile, and governance reports (e.g., Risk Appetite Statements, Risk Management Meetings, and Board reporting).
  • Audit & Regulatory Engagement: Support audit and regulatory examinations pertaining to third-party risk management; oversee timely remediation of audit findings and regulatory recommendations.
  • Risk Culture & Capability Uplift: Facilitate training and knowledge-sharing initiatives across Business & Function teams to strengthen third-party risk culture and awareness.
  • Issue Escalation & Material Change Oversight: Identify root causes of operational risk events and escalated key control gaps or vulnerabilities arising from material change programs.
Key Qualifications & Skills
Experience & Knowledge:
  • Financial Services Experience: Prior experience in Risk Management at a Globally Systemically Important Bank (GSIB) or Globally Significant Financial Institution (GSFI).
  • Domain Technical Expertise: Deep technical understanding of end-to-end Third-Party Risk Management (TPRM), Vendor Management, Outsourcing Risk, and Operational Resilience.
  • Regulatory Landscape: Strong familiarity with global financial regulations governing vendor management, operational resilience, and third-party risk oversight (e.g., PRA, FCA, DORA, OCC/Fed guidelines).
  • Risk Frameworks: Thorough understanding of operational risk taxonomies, key control frameworks, and risk appetite mechanisms in complex matrix organizations.
Skills & Education:
  • Technical Communication: Ability to articulate complex risk metrics and control frameworks clearly and persuasively to non-technical stakeholders.
  • Stakeholder Influence: Strong diplomatic and influencing skills to challenge the status quo, drive change, and operate effectively within a multi-locational matrix structure.
  • Education: Bachelor’s degree (BA/BS) required; Master’s Degree (MBA/MSc) or relevant professional certificates (e.g., CRISC, CTPRP, CISSP) highly preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Third-Party Risk Architect
Senior Third-Party Risk Architect

mthree • Kraków

On-site
PLN 180,000 - 260,000
Senior Analyst – Third Party Risk Management
Senior Analyst – Third Party Risk Management

Crisil Integral IQ • Kraków

Hybrid
PLN 180,000 - 320,000
Stable Employment
Secure Employment Contract
Medicover health insurance
+6
Third-Party Risk Manager: Build Controls & Strategy
Third-Party Risk Manager: Build Controls & Strategy

Revolut • Poland

On-site
PLN 180,000 - 300,000
Business Risk Manager (Third Party Risk)
Business Risk Manager (Third Party Risk)

Revolut • Poland

On-site
PLN 180,000 - 300,000
Third Party Security Risk Manager (m/f/d)
Third Party Security Risk Manager (m/f/d)

JT International S.A. • Poland

On-site
PLN 224,000 - 300,000
Continuous Monitoring Lead for OCRA( for RFP purposes)
Continuous Monitoring Lead for OCRA( for RFP purposes)

Luxoft • Kraków

On-site
PLN 180,000 - 280,000
Private medical insurance
Dental care
Life insurance
+1
Vendor Security & TPRM Lead
Vendor Security & TPRM Lead

Asana • Warszawa

Hybrid
Health insurance
Meals reimbursement
Career growth budget
+5
Senior Manager, Third Party Strategy and Oversight
Senior Manager, Third Party Strategy and Oversight

Bristol-Myers Squibb • Poland

On-site
PLN 120,000 - 170,000
Remote Risk & Vulnerability Management Lead – Delivery SME
Remote Risk & Vulnerability Management Lead – Delivery SME

Experis ManpowerGroup Sp. z o.o. • Katowice

Hybrid
PLN 180,000 - 260,000
Multisport card
Private healthcare (Medicover)
Access to an e learning platform
+1
ICT Risk Governance & Oversight - Assistant Vice President
ICT Risk Governance & Oversight - Assistant Vice President

State Street • Województwo pomorskie

On-site
PLN 180,000 - 240,000