JustJoin.IT Hybrydowo Mid

Third-Party Risk Management Analyst

Experis Manpower Group

⚲ Warszawa

13 440 - 14 952 PLN netto (B2B)

Wymagania

  • Vendor Risk Management
  • Vendor Cybersecurity Assessments
  • IT Risk Management
  • NIST/ISO 27001
  • Due Diligence Reviews
  • Third-party risk management
  • Cybersecurity Risk Assessment

Opis stanowiska

Location: Hybrid work model - 2 days per week from the client’s office in Warsaw
Availability: ASAP / within 1 month 
Contract Type: B2B via Experis

About the Role:

We are looking for a Third-Party Risk Management Analyst to support and enhance our Third-Party Risk Management (TPRM) program. In this role, you will be responsible for conducting risk-based due diligence, performing cybersecurity assessments, and monitoring supplier risk throughout the vendor lifecycle. You will work closely with cross-functional teams to identify, assess, and manage third-party risks while ensuring compliance with enterprise risk, security, and regulatory requirements.

Responsibilities:

Risk Assessment & Due Diligence
• Perform cybersecurity and risk assessments of third parties using standardized frameworks
• Evaluate suppliers' security posture, controls, and compliance with internal requirements
• Analyze risks across multiple domains, including information security, data privacy, and business continuity
• Assign risk ratings and document findings in accordance with TPRM standards

Risk Identification & Issue Management
• Identify control gaps, vulnerabilities, and areas of elevated risk
• Document and track remediation actions with suppliers and internal stakeholders
• Escalate high-risk findings in line with defined risk thresholds and procedures

Ongoing Monitoring
• Support continuous monitoring activities, including review of threat intelligence, security ratings, and supplier updates
• Track changes in vendor risk posture over time
• Assist in periodic reassessments based on risk tiering

Stakeholder Engagement
• Partner with Procurement, Information Security, Legal, and business stakeholders to support risk-based decision making
• Communicate assessment results clearly to both technical and non-technical audiences

Program Support & Documentation
• Maintain accurate records of assessments, decisions, and supporting evidence
• Ensure all activities align with TPRM policies, standards, and regulatory expectations, including DORA, NIST, and ISO frameworks
• Support audit and regulatory inquiries by providing required documentation

Requirements:

• 3–5 years of experience in Third-Party Risk Management, Cybersecurity Risk Management, or IT Risk
• Hands-on experience conducting vendor cybersecurity assessments or due diligence reviews
• Familiarity with industry frameworks and standards such as NIST, ISO 27001, and SOC 2
• Strong analytical and problem-solving skills
• Ability to assess risk and make recommendations based on incomplete or evolving information
• Excellent written and verbal communication skills
• Ability to effectively communicate with both technical and non-technical stakeholders
• Strong attention to detail and organizational skills

Offer:

• Multisport card
• Private healthcare (Medicover)
• Access to an e learning platform
• Group life insurance

🔍 Dekoder Ogłoszenia

🔴
support and enhance our Third-Party Risk Management (TPRM) program
Prawdopodobnie będziesz musiał wdrażać i usprawniać istniejące procesy, a nie tylko je wykonywać.
🟡
work closely with cross-functional teams
Spodziewaj się dużej liczby spotkań i konieczności koordynacji działań z wieloma różnymi działami.
🟡
ensuring compliance with enterprise risk, security, and regulatory requirements
Praca będzie wymagała ścisłego przestrzegania wewnętrznych polityk i zewnętrznych przepisów, co może oznaczać biurokrację.
🟡
Identify control gaps, vulnerabilities, and areas of elevated risk
Twoim głównym zadaniem będzie znajdowanie problemów, a niekoniecznie ich rozwiązywanie.
🟡
Escalate high-risk findings in line with defined risk thresholds and procedures
Będziesz odpowiedzialny za zgłaszanie problemów, ale faktyczne decyzje o ich rozwiązaniu mogą leżeć po stronie innych osób.