Senior Third-Party Risk Specialist
- Location
- United Arab Emirates
- Country
- UAE
- Category
- Other
- Employment type
- Full-time
- Application
- External application
- Posted
- 6 Oct 2026
- Closes
- 26 Oct 2026
CV Match Score
Loading match details…
About this role
We're Hiring: Senior Third-Party Risk Specialist
Location: United Arab Emirates (Remote)
Employment Type: Full-Time
Experience Level: Senior
Work Arrangement: Fully Remote
About Us
We are a globally focused organization committed to strengthening operational resilience, responsible sourcing, risk management, and effective governance across diverse markets.
Our teams collaborate across Risk, Procurement, Information Security, Compliance, Legal, Finance, Technology, Operations, Privacy, Business Continuity, and business functions to identify and manage risks arising from suppliers, vendors, contractors, service providers, strategic partners, and other external relationships.
The Role
We are seeking an experienced Senior Third-Party Risk Specialist to lead third-party risk management activities across the organization, including risk assessments, due diligence, onboarding, ongoing monitoring, control reviews, issue management, contract requirements, and third-party governance.
The ideal candidate will combine strong risk-management expertise with practical knowledge of vendor governance, information security, privacy, compliance, operational resilience, procurement, and contractual risk. The role will help ensure third parties are appropriately assessed, monitored, and managed throughout their lifecycle according to their criticality, risk profile, services, data access, and potential business impact.
Key Responsibilities
* Develop and maintain third-party risk management frameworks, policies, standards, procedures, and governance requirements.
* Establish risk-based third-party governance processes covering onboarding, assessment, approval, monitoring, remediation, renewal, and termination.
* Maintain a comprehensive third-party risk inventory covering suppliers, vendors, contractors, service providers, strategic partners, and other external parties.
* Establish third-party segmentation and risk-tiering methodologies based on criticality, service type, data access, geographic exposure, regulatory requirements, and business impact.
* Define inherent-risk assessment methodologies for third-party relationships.
* Conduct comprehensive third-party risk assessments and due-diligence reviews.
* Evaluate third-party risks across operational, financial, cyber, information-security, privacy, compliance, legal, regulatory, concentration, resilience, and reputational dimensions.
* Review third-party business activities, services, processes, systems, locations, subcontractors, and dependencies.
* Assess the criticality of third-party services and identify relationships that support important or essential business processes.
* Coordinate enhanced due diligence for high-risk and critical third parties.
* Review third-party ownership structures, financial condition, corporate governance, regulatory history, litigation, sanctions exposure, and other relevant risk indicators.
* Evaluate third-party control environments using questionnaires, certifications, independent assessments, audit reports, and supporting evidence.
* Review security certifications and assurance reports such as SOC reports, ISO certifications, penetration-testing summaries, and other relevant evidence.
* Assess third-party information-security controls covering access management, encryption, vulnerability management, incident response, security monitoring, and data protection.
* Evaluate third-party privacy and data-protection practices where personal or sensitive information is processed.
* Assess third-party business continuity, disaster recovery, crisis management, and operational resilience capabilities.
* Review recovery objectives, resilience testing, contingency arrangements, and dependency management for critical providers.
* Evaluate third-party financial and business viability risks.
* Monitor third-party financial indicators, credit concerns, ownership changes, restructuring, and other events that may affect service continuity.
* Assess geographic, geopolitical, country, and concentration risks associated with third-party relationships.
* Identify single points of failure and excessive dependency on individual vendors, regions, technologies, or service providers.
* Assess fourth-party and subcontractor risks and ensure material subcontractors are appropriately identified and governed.
* Review third-party supply-chain dependencies and assess potential cascading risks.
* Coordinate with Procurement and business owners during third-party onboarding and selection processes.
* Establish minimum risk requirements before third-party engagement or contract execution.
* Review risk assessments for new suppliers and provide risk-based recommendations for approval, rejection, or additional controls.
* Establish risk acceptance and exception-management processes for third-party relationships.
* Ensure material third-party risks are appropriately documented, approved, and tracked.
* Review contracts and contractual provisions from a third-party risk perspective.
* Work with Legal and Procurement to ensure contracts include appropriate risk, security, privacy, audit, resilience, insurance, compliance, and termination provisions.
* Define minimum contractual requirements for critical and high-risk third parties.
* Review service-level agreements, performance obligations, escalation procedures, notification requirements, and remediation provisions.
* Ensure contracts provide appropriate rights to audit, obtain assurance evidence, and monitor third-party controls.
* Monitor third-party compliance with contractual risk requirements.
* Establish ongoing third-party monitoring programs based on risk tier and service criticality.
* Monitor changes in third-party risk profiles, control environments, ownership, financial condition, certifications, incidents, and regulatory status.
* Conduct periodic reassessments of high-risk and critical third parties.
* Track third-party security incidents, privacy incidents, operational disruptions, regulatory events, and other material risk events.
* Coordinate third-party incident response and escalation activities with relevant internal teams.
* Assess the impact of third-party incidents and ensure appropriate corrective actions are implemented.
* Track third-party risk issues, control deficiencies, remediation plans, exceptions, and overdue actions.
* Challenge third-party remediation plans and validate evidence of corrective action.
* Escalate material or unresolved third-party risks to appropriate risk committees and senior management.
Key Performance Indicators
* Third-party risk assessment completion rate
* Third-party assessment timeliness
* High-risk third-party assessment coverage
* Critical third-party assessment coverage
* Third-party inventory completeness
* Third-party inventory accuracy
* Third-party risk-tiering accuracy
* Inherent-risk assessment completion
* Enhanced due-diligence completion
* Third-party onboarding compliance
* Third-party approval compliance
* Third-party reassessment completion
* Overdue third-party assessment rate
* Third-party risk issue identification rate
* Third-party remediation completion rate
* Overdue remediation rate
* High-risk issue closure time
* Third-party risk exception rate
* Risk acceptance compliance
* Third-party control deficiency rate
* Third-party security assessment completion
* Third-party privacy assessment completion
* Business continuity assessment coverage
* Critical supplier resilience coverage
* Third-party incident frequency
* Third-party incident response time
* Third-party incident resolution time
* Third-party contractual compliance
* Contractual risk-control coverage
* Audit-right coverage for critical third parties
* Subcontractor and fourth-party visibility
* Concentration-risk exposure
* Single-point-of-failure exposure
* Third-party financial-risk monitoring coverage
* Third-party regulatory compliance
* Third-party certification and assurance coverage
* Third-party monitoring effectiveness
* Key risk indicator reporting timeliness
* Third-party risk dashboard accuracy
* Audit finding resolution
* Regulatory finding resolution
* Third-party risk training completion
* Third-party risk policy compliance
* Vendor governance stakeholder satisfaction
* Third-party risk process efficiency
* Third-party risk automation adoption
* Overall reduction in material third-party risk exposure
Ideal Candidate
The successful candidate should have strong experience in third-party risk management, vendor risk management, supplier risk, operational risk, outsourcing risk, information-security risk, procurement risk, or enterprise risk management, preferably within financial services, technology, telecommunications, professional services, regulated industries, or complex multinational organizations.
The candidate should demonstrate:
* Strong understanding of third-party and vendor risk management principles.
* Proven experience developing or operating third-party risk management programs.
* Experience conducting third-party risk assessments and due-diligence reviews.
* Strong understanding of third-party lifecycle management from onboarding through termination.
* Experience assessing operational, financial, cyber, privacy, compliance, legal, resilience, and reputational risks.