About this role
Location: remote.
Years of Experience: 8-10 years.
Project Duration: 2 years.
Language Requirements: Fluency in Arabic & English (written and spoken).
We are seeking a Senior Third-Party Risk Management Consultant to assess and manage risks across the full vendor lifecycle, from onboarding and due diligence through ongoing monitoring and offboarding. The consultant will evaluate third-party cybersecurity, technology, operational, privacy, compliance, and resilience risks; track findings and remediation; and help strengthen TPRM frameworks and reporting. The role involves working closely with procurement, legal, cybersecurity, compliance, and business teams to support informed vendor decisions.
Key Requirements
- Strong experience in third-party risk management (TPRM) , including vendor due diligence, inherent and residual risk assessments, and risk-based reviews throughout the vendor lifecycle.
- Experience assessing cybersecurity, technology, operational, compliance, privacy, and business continuity risks associated with third parties.
- Ability to evaluate vendor security controls using assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports.
- Experience managing vendor risk registers, findings, remediation plans, risk acceptance, and exceptions .
- Knowledge of risks associated with cloud services, SaaS platforms, managed services, and other technology providers , including concentration and fourth-party risk.
- Experience assessing third-party business continuity, disaster recovery, and operational resilience capabilities.
- Familiarity with contractual risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification.
- Experience developing or improving TPRM frameworks, procedures, assessment methodologies, and reporting .
- Knowledge of applicable NCA controls, privacy requirements, cybersecurity standards, and vendor risk regulations .
Key Responsibilities
- Support the planning and execution of Third-Party Risk Management engagements in alignment with project objectives, methodologies, and delivery timelines.
- Conduct inherent and residual risk assessments for third parties, vendors, service providers, partners, and outsourced services across customer's business and technology landscape.
- Perform risk-based due diligence reviews for new and existing third-party engagements to identify cybersecurity, technology, operational, compliance, privacy, and business continuity risks.
- Evaluate third-party security controls, governance practices, and compliance posture against customer requirements, regulatory obligations, and industry standards.
- Review vendor assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports to validate control eUectiveness.
- Assess third-party compliance with applicable requirements, including contractual obligations, information security requirements, NCA controls, privacy requirements, and internal policies.
- Facilitate vendor risk assessments throughout the third-party lifecycle, including onboarding, periodic reassessments, contract renewals, significant changes, and oUboarding activities.
- Identify, document, and assess third-party risks associated with cloud services, managed services, SaaS platforms, telecommunications providers, and strategic technology partners.
- Evaluate concentration risk, dependency risk, fourth-party risk, and critical supplier exposure to support resilience and supply chain risk management objectives.
- Collaborate with procurement, legal, cybersecurity, compliance, privacy, and business stakeholders to ensure comprehensive vendor risk evaluations.
- Develop and maintain third-party risk registers, assessment records, risk exceptions, remediation plans, and supporting governance documentation.
- Track identified findings, remediation actions, and risk treatment plans, ensuring timely closure of vendor-related risks and control gaps.
- Facilitate third-party risk acceptance and exception processes, including risk impact analysis, compensating control reviews, stakeholder coordination, and approval workflows.
- Perform ongoing monitoring of critical and high-risk vendors through periodic reviews, risk indicators, security alerts, performance metrics, and emerging threat assessments.
- Assess third-party business continuity, disaster recovery, and operational resilience capabilities to ensure alignment with customer recovery requirements and service expectations.
- Review contractual security and risk requirements, including security clauses, service level agreements (SLAs), data protection obligations, audit rights, and incident notification requirements.
- Support the development, maintenance, and enhancement of Third-Party Risk Management frameworks, methodologies, procedures, standards, and assessment templates.
- Analyze vendor risk trends, assessment outcomes, and risk exposures to provide actionable insights and recommendations for management decision-making.
- Prepare management reports, dashboards, risk metrics, and executive presentations highlighting vendor risk posture, assessment status, critical findings, and remediation progress.
- Promote awareness and adoption of Third-Party Risk Management requirements across business units and relevant stakeholder groups.
- Ensure alignment with customer policies, regulatory requirements, and industry frameworks related to vendor risk management, cybersecurity, operational resilience, and supply chain security.
---
If you would like to know more about the Global Consulting Bootcamp Visit: https://caseinpointco.com/global-consultant-bootcamp/
If you would like to know more about the MC Club Visit: https://menaconsultant.com/mc-club/