Senior Third-Party Risk Management Consultant - 2-Year Engagement

MENA ConsultantAmman, AmmanRemoteContractSenior, 5–8 yearsListed 2 days ago

Apply now

About this role

Location: remote.
Years of Experience: 8-10 years.
Project Duration: 2 years.
Language Requirements: Fluency in Arabic & English (written and spoken).

We are seeking a Senior Third-Party Risk Management Consultant to assess and manage risks across the full vendor lifecycle, from onboarding and due diligence through ongoing monitoring and offboarding. The consultant will evaluate third-party cybersecurity, technology, operational, privacy, compliance, and resilience risks; track findings and remediation; and help strengthen TPRM frameworks and reporting. The role involves working closely with procurement, legal, cybersecurity, compliance, and business teams to support informed vendor decisions.

Key Requirements

- Strong experience in third-party risk management (TPRM) , including vendor due diligence, inherent and residual risk assessments, and risk-based reviews throughout the vendor lifecycle.

- Experience assessing cybersecurity, technology, operational, compliance, privacy, and business continuity risks associated with third parties.

- Ability to evaluate vendor security controls using assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports.

- Experience managing vendor risk registers, findings, remediation plans, risk acceptance, and exceptions .

- Knowledge of risks associated with cloud services, SaaS platforms, managed services, and other technology providers , including concentration and fourth-party risk.

- Experience assessing third-party business continuity, disaster recovery, and operational resilience capabilities.

- Familiarity with contractual risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification.

- Experience developing or improving TPRM frameworks, procedures, assessment methodologies, and reporting .

- Knowledge of applicable NCA controls, privacy requirements, cybersecurity standards, and vendor risk regulations .

Key Responsibilities

- Support the planning and execution of Third-Party Risk Management engagements in alignment with project objectives, methodologies, and delivery timelines.

- Conduct inherent and residual risk assessments for third parties, vendors, service providers, partners, and outsourced services across customer's business and technology landscape.

- Perform risk-based due diligence reviews for new and existing third-party engagements to identify cybersecurity, technology, operational, compliance, privacy, and business continuity risks.

- Evaluate third-party security controls, governance practices, and compliance posture against customer requirements, regulatory obligations, and industry standards.

- Review vendor assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports to validate control eUectiveness.

- Assess third-party compliance with applicable requirements, including contractual obligations, information security requirements, NCA controls, privacy requirements, and internal policies.

- Facilitate vendor risk assessments throughout the third-party lifecycle, including onboarding, periodic reassessments, contract renewals, significant changes, and oUboarding activities.

- Identify, document, and assess third-party risks associated with cloud services, managed services, SaaS platforms, telecommunications providers, and strategic technology partners.

- Evaluate concentration risk, dependency risk, fourth-party risk, and critical supplier exposure to support resilience and supply chain risk management objectives.

- Collaborate with procurement, legal, cybersecurity, compliance, privacy, and business stakeholders to ensure comprehensive vendor risk evaluations.

- Develop and maintain third-party risk registers, assessment records, risk exceptions, remediation plans, and supporting governance documentation.

- Track identified findings, remediation actions, and risk treatment plans, ensuring timely closure of vendor-related risks and control gaps.

- Facilitate third-party risk acceptance and exception processes, including risk impact analysis, compensating control reviews, stakeholder coordination, and approval workflows.

- Perform ongoing monitoring of critical and high-risk vendors through periodic reviews, risk indicators, security alerts, performance metrics, and emerging threat assessments.

- Assess third-party business continuity, disaster recovery, and operational resilience capabilities to ensure alignment with customer recovery requirements and service expectations.

- Review contractual security and risk requirements, including security clauses, service level agreements (SLAs), data protection obligations, audit rights, and incident notification requirements.

- Support the development, maintenance, and enhancement of Third-Party Risk Management frameworks, methodologies, procedures, standards, and assessment templates.

- Analyze vendor risk trends, assessment outcomes, and risk exposures to provide actionable insights and recommendations for management decision-making.

- Prepare management reports, dashboards, risk metrics, and executive presentations highlighting vendor risk posture, assessment status, critical findings, and remediation progress.

- Promote awareness and adoption of Third-Party Risk Management requirements across business units and relevant stakeholder groups.

- Ensure alignment with customer policies, regulatory requirements, and industry frameworks related to vendor risk management, cybersecurity, operational resilience, and supply chain security.

---

If you would like to know more about the Global Consulting Bootcamp Visit: https://caseinpointco.com/global-consultant-bootcamp/
If you would like to know more about the MC Club Visit: https://menaconsultant.com/mc-club/