Third-Party Risk Management Analyst

Security

Third-Party Risk Management Analyst

Security
Al. Jerozolimskie, Warszawa

Experis Manpower Group

Full-time
B2B
Mid
Hybrid
2 onsite / 3 remote
21,20 - 23,59 USDNet per hour - B2B

Job description

Location: Hybrid work model - 2 days per week from the Warsaw office or 1 day per month for Candidates based outside Warsaw
Availability: ASAP / within 1 month
Contract Type: B2B via Experis

About the Role:

We are looking for a Third-Party Risk Management Analyst to join a global team responsible for conducting vendor risk assessments and security reviews as part of the organization's Third-Party Risk Management (TPRM) program. You will support the onboarding and ongoing monitoring of vendors by performing risk-based due diligence, evaluating security controls, and identifying potential risks across the supplier ecosystem.
This role is ideal for professionals with experience in vendor reviews, information security assessments, and third-party risk management, preferably within a financial services environment.

Responsibilities:

Vendor Risk Assessments & Due Diligence

  • Conduct risk-based due diligence and security reviews of prospective and existing vendors

  • Perform cybersecurity and information security assessments using established frameworks and methodologies

  • Evaluate suppliers’ security controls, policies, governance practices, and overall risk posture

  • Assess risks across multiple domains, including information security, data privacy, operational resilience, and business continuity

  • Assign and document risk ratings, findings, and recommendations in accordance with TPRM standards


Risk Identification & Remediation

  • Identify control gaps, vulnerabilities, and areas of elevated risk

  • Review vendor responses and supporting documentation

  • Track remediation activities and collaborate with suppliers to address identified issues

  • Escalate high-risk findings in line with established governance processes


Ongoing Monitoring

  • Support ongoing monitoring of third-party risk throughout the vendor lifecycle

  • Participate in periodic reassessments of vendors based on risk tiering and business requirements

  • Monitor changes in vendor risk profiles and emerging security threats


Stakeholder Collaboration

  • Partner with Procurement, Information Security, Legal, Compliance, and business stakeholders

  • Provide risk-based recommendations to support onboarding and vendor management decisions

  • Present assessment outcomes clearly to both technical and non-technical audiences


Documentation & Governance

  • Maintain accurate assessment records and supporting evidence

  • Ensure compliance with internal policies, regulatory requirements, and industry standards

  • Support audits and reviews by providing relevant risk and assessment documentation


Requirements:

  • 3–5 years of experience in Third-Party Risk Management, Vendor Risk Management, Information Security, Cybersecurity, IT Risk, or a related field

  • Hands-on experience conducting vendor reviews, supplier due diligence, and third-party risk assessments

  • Previous experience within a financial institution, banking, financial services, or fintech environment

  • Experience performing information security or cybersecurity reviews of vendors

  • Strong understanding of risk assessment methodologies and security controls

  • Excellent analytical and problem-solving skills

  • Ability to assess risks and provide practical, risk-based recommendations

  • Strong communication and stakeholder management skills

  • Ability to work effectively in a global environment


Nice to Have:


Relevant certifications such as: 

  • CTPRP (Certified Third Party Risk Professional)

  • Other Risk Assessment certifications

  • Familiarity with frameworks and standards such as NIST, ISO 27001, SOC 2, DORA, or similar


What We Offer:

  • Participation in a global Third-Party Risk Management function

  • Exposure to a high-volume and mature vendor risk environment

  • Multisport card

  • Private healthcare (Medicover)

  • Access to an e-learning platform

  • Group life insurance

  • Hybrid working model with occasional meetings aligned to US time zones

  • Opportunity to work with international stakeholders and teams worldwide

Tech stack

    English

    C1

    Third-party risk management

    regular

    risk assessment

    regular

    Due Diligence Reviews

    regular

    IT Risk Management

    regular

    Financial institution experience

    regular

    Vendor Risk Management

    regular

    Cybersecurity Risk Assessment

    nice to have

    NIST/ISO 27001

    nice to have

    Vendor Cybersecurity Assessments

    nice to have

Office location

Similar offers
Link Group

Link Group

Remote

Remote

44,93 - 55,50USD/h
Security
Cybersecurity
Risk Management
Team Leader / ManagerManagerB2BB2BFull-timeFull-time
New
ADVERTISEMENT: Recommended by Just Join IT
Similar offers
Link Group

Link Group

Remote

Remote

44,93 - 55,50USD/h
Security
Cybersecurity
Risk Management
Team Leader / ManagerManagerB2BB2BFull-timeFull-time
New
Procter & Gamble

Procter & Gamble

Warszawa

Hybrid

Hybrid

Undisclosed Salary
vulnerabilities
vulnerability scanning
Vulnerability Management
MITRE ATT&CK
CVEs
CVSS
Python
MidMidPermanentPermanentFull-timeFull-time
New
HelloFresh

HelloFresh

Warszawa

Hybrid

Hybrid

3 215,43 - 4 474,81USD/month
Microsoft Entra ID
SSO
SCIM
Identity Lifecycle
Scripting
MidMidB2BB2BFull-timeFull-time
New
emagine Polska

emagine Polska

Hybrid

Hybrid

31,62 - 35,58USD/h
CMDB
IT Security
Asset AND Configuration Management
MidMidB2BB2BFull-timeFull-time
New
Fabrity S.A.

Fabrity S.A.

Warszawa

Hybrid

Hybrid

5 323,68 - 7 985,52USD/month
Monitoring&Audit
Cybersecurity
Vulnerability & Risk Scanners
Identity & Access Management
MidMidB2BB2BFull-timeFull-time
New
ADVERTISEMENT: Recommended by Just Join IT