Senior Third-Party Risk Management Consultant - 2-Year Engagement

MENA Consultant

United States

Remote

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

MENA Consultant is seeking a Senior Third-Party Risk Management Consultant to assess and manage vendor risks across the full lifecycle, from onboarding to offboarding. You will review cybersecurity, privacy, and continuity risks and coordinate with procurement, legal, and cybersecurity teams to support informed decisions.

Responsibilities include conducting risk assessments, evaluating controls, and maintaining risk registers with remediation plans.

Qualifications

  • Strong experience in third-party risk management (TPRM).
  • Experience assessing cybersecurity, technology, operational, compliance, privacy, and business continuity risks.
  • Ability to evaluate vendor security controls using responses, evidence, audits, and certifications.
  • Experience managing vendor risk registers, findings, remediation plans, risk acceptance, and exceptions.
  • Knowledge of risks with cloud services, SaaS, managed services, and fourth-party risk.
  • Experience assessing third-party business continuity and disaster recovery capabilities.
  • Familiarity with contractual risk requirements including security clauses, SLAs, data protection, audit rights, incident notification.
  • Experience developing or improving TPRM frameworks, procedures, assessment methodologies, and reporting.
  • Knowledge of applicable NCA controls, privacy requirements, cybersecurity standards, and vendor risk regulations.

Responsibilities

  • Plan and execute Third-Party Risk Management engagements in line with project objectives and timelines.
  • Perform inherent and residual risk assessments for third parties and outsourced services across business and tech landscapes.
  • Conduct risk-based due diligence reviews for new and existing engagements to identify cybersecurity, privacy, and operational risks.
  • Evaluate third-party security controls and governance against requirements and standards.
  • Review assessment responses, evidence, audits, and certifications to validate control effectiveness.
  • Track findings, remediation actions, and risk treatment plans to ensure timely closure.
  • Facilitate risk acceptance and exception processes with stakeholders and approval workflows.
  • Monitor critical/high-risk vendors through periodic reviews and security alerts.
  • Develop and maintain TPRM frameworks, templates, and governance documentation.
  • Provide management reports and executive dashboards on vendor risk posture and remediation progress.

Skills

TPRM
Vendor due diligence
Risk-based reviews
Regulatory compliance
Contractual risk requirements
Operational resilience
NCA controls

Job description

Location: remote.
Years of Experience: 8-10 years.
Project Duration: 2 years.
Language Requirements: Fluency in Arabic & English (written and spoken).

We are seeking a Senior Third-Party Risk Management Consultant to assess and manage risks across the full vendor lifecycle, from onboarding and due diligence through ongoing monitoring and offboarding. The consultant will evaluate third-party cybersecurity, technology, operational, privacy, compliance, and resilience risks; track findings and remediation; and help strengthen TPRM frameworks and reporting. The role involves working closely with procurement, legal, cybersecurity, compliance, and business teams to support informed vendor decisions.

Key Requirements
  • Strong experience in third-party risk management (TPRM), including vendor due diligence, inherent and residual risk assessments, and risk-based reviews throughout the vendor lifecycle.
  • Experience assessing cybersecurity, technology, operational, compliance, privacy, and business continuity risks associated with third parties.
  • Ability to evaluate vendor security controls using assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports.
  • Experience managing vendor risk registers, findings, remediation plans, risk acceptance, and exceptions.
  • Knowledge of risks associated with cloud services, SaaS platforms, managed services, and other technology providers, including concentration and fourth-party risk.
  • Experience assessing third-party business continuity, disaster recovery, and operational resilience capabilities.
  • Familiarity with contractual risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification.
  • Experience developing or improving TPRM frameworks, procedures, assessment methodologies, and reporting.
  • Knowledge of applicable NCA controls, privacy requirements, cybersecurity standards, and vendor risk regulations.
Key Responsibilities
  • Support the planning and execution of Third-Party Risk Management engagements in alignment with project objectives, methodologies, and delivery timelines.
  • Conduct inherent and residual risk assessments for third parties, vendors, service providers, partners, and outsourced services across customer's business and technology landscape.
  • Perform risk-based due diligence reviews for new and existing third-party engagements to identify cybersecurity, technology, operational, compliance, privacy, and business continuity risks.
  • Evaluate third-party security controls, governance practices, and compliance posture against customer requirements, regulatory obligations, and industry standards.
  • Review vendor assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports to validate control eUectiveness.
  • Assess third-party compliance with applicable requirements, including contractual obligations, information security requirements, NCA controls, privacy requirements, and internal policies.
  • Facilitate vendor risk assessments throughout the third-party lifecycle, including onboarding, periodic reassessments, contract renewals, significant changes, and oUboarding activities.
  • Identify, document, and assess third-party risks associated with cloud services, managed services, SaaS platforms, telecommunications providers, and strategic technology partners.
  • Evaluate concentration risk, dependency risk, fourth-party risk, and critical supplier exposure to support resilience and supply chain risk management objectives.
  • Collaborate with procurement, legal, cybersecurity, compliance, privacy, and business stakeholders to ensure comprehensive vendor risk evaluations.
  • Develop and maintain third-party risk registers, assessment records, risk exceptions, remediation plans, and supporting governance documentation.
  • Track identified findings, remediation actions, and risk treatment plans, ensuring timely closure of vendor-related risks and control gaps.
  • Facilitate third-party risk acceptance and exception processes, including risk impact analysis, compensating control reviews, stakeholder coordination, and approval workflows.
  • Perform ongoing monitoring of critical and high-risk vendors through periodic reviews, risk indicators, security alerts, performance metrics, and emerging threat assessments.
  • Assess third-party business continuity, disaster recovery, and operational resilience capabilities to ensure alignment with customer recovery requirements and service expectations.
  • Review contractual security and risk requirements, including security clauses, service level agreements (SLAs), data protection obligations, audit rights, and incident notification requirements.
  • Support the development, maintenance, and enhancement of Third-Party Risk Management frameworks, methodologies, procedures, standards, and assessment templates.
  • Analyze vendor risk trends, assessment outcomes, and risk exposures to provide actionable insights and recommendations for management decision-making.
  • Prepare management reports, dashboards, risk metrics, and executive presentations highlighting vendor risk posture, assessment status, critical findings, and remediation progress.
  • Promote awareness and adoption of Third-Party Risk Management requirements across business units and relevant stakeholder groups.
  • Ensure alignment with customer policies, regulatory requirements, and industry frameworks related to vendor risk management, cybersecurity, operational resilience, and supply chain security.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Third-Party Risk Management Consultant - 2-Year Engagement (Fully Remote)
Senior Third-Party Risk Management Consultant - 2-Year Engagement (Fully Remote)

MENA Consultant • United States

Remote
USD 120,000 - 180,000
Senior Third-Party Risk & Resilience Consultant
Senior Third-Party Risk & Resilience Consultant

MENA Consultant • United States

Remote
USD 120,000 - 180,000
Senior Analyst TPRM
Senior Analyst TPRM

Altisource • United States

Remote
USD 95,000 - 140,000
Senior Third-Party Risk Management Analyst
Senior Third-Party Risk Management Analyst

Phyton Talent Advisors • Red Bank (NJ)

On-site
USD 90,000 - 150,000
Senior TPRM Lead - Vendor Risk & Compliance (Arabic/English)
Senior TPRM Lead - Vendor Risk & Compliance (Arabic/English)

MENA Consultant • United States

Remote
USD 120,000 - 180,000
Contracts Manager - Junior/ Third-Party Risk Management (TPRM)
Contracts Manager - Junior/ Third-Party Risk Management (TPRM)

Spectraforce Technologies • Westlake (TX)

On-site
USD 120,000 - 150,000
Third Party Cyber Risk Analyst
Third Party Cyber Risk Analyst

Selby Jennings • New York (NY)

On-site
USD 90,000 - 140,000
Advisor – Third-Party Risk Management (TPRM)
Advisor – Third-Party Risk Management (TPRM)

CGS CyberDefense • West Palm Beach (FL)

On-site
USD 90,000 - 120,000
Access to cutting-edge cybersecurity tools
Ongoing professional development
A culture that values curiosity and innovation
Information Technology Security Manager
Information Technology Security Manager

Meet Life Sciences • Princeton (NJ)

Hybrid
USD 124,000 - 165,000
Senior - Third-Party Cybersecurity & Risk Management
Senior - Third-Party Cybersecurity & Risk Management

TechDigital Group • Mount Laurel Township (NJ)

On-site
USD 90,000 - 120,000