- Company Name
- Copper.co
- Job Title
- Third-Party Risk Management Lead
- Job Description
-
**Job Title:**
Third‑Party Risk Management Lead
**Role Summary:**
Design, implement, and maintain a comprehensive Third‑Party Risk Management (TPRM) framework that governs all vendor, outsourcing, and critical ICT engagements, ensuring regulatory compliance, operational resilience, and effective risk treatment across the organization.
**Expectations:**
- Lead end‑to‑end vendor lifecycle risk oversight – intake, due diligence, monitoring, remediation, and exit.
- Demonstrate mastery of regulated financial services risk standards (e.g., FCA, EBA, DORA).
- Provide actionable risk insights to senior leadership and governance bodies.
- Champion continuous improvement of TPRM policies, tools, and processes.
**Key Responsibilities:**
- Develop and refine TPRM policies, procedures, and risk registers.
- Conduct risk assessments and due diligence on new and existing vendors.
- Monitor third‑party exposure, prepare and present risk reports, and flag material issues.
- Collaborate with Procurement, Legal, Technology, and Business units to embed risk controls throughout the vendor lifecycle.
- Manage contract risk clauses, SLA performance, and exit planning.
- Drive automation and modernization of TPRM processes and reporting.
- Liaise with entity risk managers to maintain accurate outsourcing profiles and risk registers.
**Required Skills:**
- Proven experience in third‑party risk management within regulated financial or fintech environments.
- Deep knowledge of vendor lifecycle management, outsourcing regulations, and operational resilience requirements.
- Ability to interpret and apply regulatory frameworks (FCA, EBA, DORA, etc.) to TPRM practices.
- Strong stakeholder‑management and influencing capabilities across technical and non‑technical teams.
- Experience leading risk assessments, assurance reviews, and remediation for critical vendors.
- Familiarity with contract risk clauses, SLA management, and exit planning.
- Proficiency with TPRM technology platforms, automation tools, and reporting dashboards.
- Understanding of information security and data protection requirements in vendor relationships.
**Required Education & Certifications:**
- Bachelor’s degree in Finance, Risk Management, Law, or related field.
- Professional certifications (e.g., CRISC, CISSP, ISO 27001 Lead Implementer, FRM) preferred.