CrawlJobs Logo

Senior Risk Manager - Third Party Risk

United Kingdom, London · Job Posted June 04, 2026
Apply Position
Job Link Share

Job Description

The role supports the Head of Operational Risk in the oversight and management of operational risk matters across the group, with a particular focus on third party risk activities. It is also responsible for providing independent second-line oversight, challenge, and assurance over the organisation's management of risks, including those arising from third parties, outsourced services, and strategic suppliers. The role has primary responsibility for the management of operational risks across a number of business areas, including Delegated Authority, Facilities Management and Talent Management. It also has a particular focus on the design, maintenance, and oversight of the group's third party risk management framework, ensuring that third party risks are identified, assessed, monitored, and managed in line with the firm's risk appetite, regulatory requirements, and operational resilience objectives.

Job Responsibility

  • Provide independent oversight and effective challenge to first-line operational risk activities
  • Review, challenge and contribute to the Third Party Risk Management (TPRM) framework, policies and standards
  • Support the Head of Operational Risk in facilitating regular Risk & Control Self Assessments (RCSAs) with first line risk owners and stakeholders, ensuring the assessments are performed and documented accordingly
  • Oversee the management of delegated authority risk within Underwriting, Claims and Operations as part of the TPRM framework
  • Ensure consistent risk tiering and materiality assessments for all third parties
  • Review and challenge residual risk assessments, risk acceptances, and exceptions related to Operational Risk
  • Oversee integration of Third Party Risk into operational resilience, technology, cyber, and data frameworks
  • Support the implementation and maintenance of a robust control environment with clear ownership and accountability within the business, ensuring control documentation remains accurate and current
  • Develop and monitor key risk indicators (KRIs) and support risk appetite monitoring and management
  • Work collaboratively with 1st Line and Risk domain teams, supporting the embedding of the Operational Risk and TPRM framework into the organisation and across the 3 Lines of Defence model
  • Act as the appropriate liaison across the 3 Lines of Defence model, including 1st Line colleagues, Risk Owners, Compliance and Internal Audit functions, Operational Resilience, and risk domains including Information Security and Sustainability
  • Provide review, credible challenge and 2nd Line insights over 1st Line decision-focused risk reporting, dashboards, and actively participate in any thematic deep dives, with particular focus on Third Party and broader risk areas
  • Provide independent risk opinions on emerging operational risk themes
  • Investigate and report operational risk incidents, ensuring lessons learned are captured and implemented
  • Support ORSA, scenario testing, and stress testing, in particular where Third Party dependencies are classed as material
  • Identify systemic risks and concentration vulnerabilities related to TPRM
  • Challenge the quality, completeness, and relevance of first-line reporting and MI, ensuring they support effective risk management and align with risk appetite
  • Support compliance with regulatory expectations relating to third party, outsourcing and broader operational risks
  • Act as a second-line point of contact for regulators and Internal Audit
  • Ensure clear governance, escalation, and documentation of third-party risk decisions
  • Promote clear ownership and accountability across the first line
  • Promote a culture of good conduct within the Operational Risk team by demonstrating and communicating the expected levels of behaviour and integrity

Requirements

  • Degree level educated or an equivalent combination of education training and experience with third-party frameworks and industry standards
  • and/or relevant professional qualification (e.g., IRM International Certificate in Operational Risk, Practitioner Certificate in Information Management, etc.)
  • Proven third party risk expertise, preferably with knowledge of relevant standards such as ISO 27001, ISO 22301, NIST, and COBIT
  • A strong understanding of the Lloyd's or wider company insurance market and frameworks is preferable
  • Knowledge and experience of risk management frameworks and tools
  • Demonstrate effective understanding of relevant TPRM regulations for a global organisation operating across the UK, EU, US and Asia
  • Understanding of the commercial drivers and dynamics affecting risk decisions in the insurance sector, as well as operational and risk processes found within an international insurance group
  • Ability to build strong partnering relationships with a wide range of stakeholders, in particular the 1st Line TPRM team
  • Ability to interact professionally and with credibility and manage expectations of management and key stakeholders
  • Ability to manage time, meet deadlines and prioritise
  • Able to communicate effectively with others
  • Ability to build and track remediation plans where deficiencies are identified
  • Proficiency in Microsoft 365 apps
  • Experience of working in a global and fast paced business environment is essential
  • Experience of Committee and Board reporting
  • Application of risk-based judgement
  • Influencing and trusted advisor
  • Flexible
  • Energetic, enthusiastic and positive
  • Team player
  • Self-motivated with the ability to work autonomously
  • Proactive
  • Strong prioritisation skills
  • ability to meet deadlines and manage stakeholders' expectations
  • Highest degree of integrity / discretion
  • Strong written and verbal communication skills
  • Analytical
  • Attention to detail, with ability to see bigger picture
  • Ability to challenge, negotiate with, influence and persuade both internal and external parties

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

Senior Risk Manager - Third Party Risk

8 matching positions

Third Party Risk Senior Lead

This is a pivotal role where you’ll act as the key liaison between the central T...
Location
Location
United States , Austin
Salary
Salary:
Not provided
weareorbis.com Logo
Orbis Consultants
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven experience representing central risk or compliance functions across the Americas
  • Strong background in third-party risk management, including localisation, governance, and oversight
  • Hands-on experience supporting audits, exams, and IntraGroup risk activities
  • Exceptional communication skills, with the ability to engage senior stakeholders and influence outcomes
  • Highly organised, detail-oriented, and able to manage multiple priorities independently in a fast-paced environment
  • A strategic thinker with a process improvement mindset and long-term vision
Job Responsibility
Job Responsibility
  • Lead TPRM in your region – oversee localisation, regulatory mapping, outsourcing registers, and ensure compliance with group policies
  • Strengthen risk oversight – support risk assessments, monitor local controls, and escalate deviations with corrective actions
  • Represent Third Party Risk – act as the primary TPRM contact in local committees, governance forums, and syncs
  • Support audits & exams – ensure documentation and responses align with group frameworks, driving consistent global standards
  • Guide IntraGroup activity – coordinate materiality assessments and exit strategies, ensuring alignment with group-wide policies
What we offer
What we offer
  • relocation package included
  • Fulltime
Read More
Arrow Right

Third Party Risk Senior Lead

This is a pivotal role where you’ll act as the key liaison between the central T...
Location
Location
United States , Austin
Salary
Salary:
Not provided
weareorbis.com Logo
Orbis Consultants
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven experience representing central risk or compliance functions across the Americas
  • Strong background in third-party risk management, including localisation, governance, and oversight
  • Hands-on experience supporting audits, exams, and IntraGroup risk activities
  • Exceptional communication skills, with the ability to engage senior stakeholders and influence outcomes
  • Highly organised, detail-oriented, and able to manage multiple priorities independently in a fast-paced environment
  • A strategic thinker with a process improvement mindset and long-term vision
Job Responsibility
Job Responsibility
  • Lead TPRM in your region – oversee localisation, regulatory mapping, outsourcing registers, and ensure compliance with group policies
  • Strengthen risk oversight – support risk assessments, monitor local controls, and escalate deviations with corrective actions
  • Represent Third Party Risk – act as the primary TPRM contact in local committees, governance forums, and syncs
  • Support audits & exams – ensure documentation and responses align with group frameworks, driving consistent global standards
  • Guide IntraGroup activity – coordinate materiality assessments and exit strategies, ensuring alignment with group-wide policies
What we offer
What we offer
  • relocation package included
  • Fulltime
Read More
Arrow Right

Third Party Risk Senior Lead

This is a pivotal role where you’ll act as the key liaison between the central T...
Location
Location
United States , Austin
Salary
Salary:
Not provided
weareorbis.com Logo
Orbis Consultants
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven experience representing central risk or compliance functions across the Americas
  • Strong background in third-party risk management, including localisation, governance, and oversight
  • Hands-on experience supporting audits, exams, and IntraGroup risk activities
  • Exceptional communication skills, with the ability to engage senior stakeholders and influence outcomes
  • Highly organised, detail-oriented, and able to manage multiple priorities independently in a fast-paced environment
  • A strategic thinker with a process improvement mindset and long-term vision
Job Responsibility
Job Responsibility
  • Lead TPRM in your region – oversee localisation, regulatory mapping, outsourcing registers, and ensure compliance with group policies
  • Strengthen risk oversight – support risk assessments, monitor local controls, and escalate deviations with corrective actions
  • Represent Third Party Risk – act as the primary TPRM contact in local committees, governance forums, and syncs
  • Support audits & exams – ensure documentation and responses align with group frameworks, driving consistent global standards
  • Guide IntraGroup activity – coordinate materiality assessments and exit strategies, ensuring alignment with group-wide policies
  • Fulltime
Read More
Arrow Right

Third Party Risk Analyst

Our team members are at the heart of everything we do. At Cencora, we are united...
Location
Location
Colombia , Bogota
Salary
Salary:
Not provided
cencora.com Logo
Cencora
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s Degree – required
  • 3-5 years of work experience in similar position
  • Strong understanding of risk management principles and practices, particularly as they relate to third party relationships
  • Familiarity with contract negotiation, invoice processing or legal terms review preferred
  • Proficiency in data analysis and the ability to assess and interpret contracts, compliance documentation, and financial statements
  • Excellent written and verbal communication skills required for reporting findings, communicating with vendors and collaborating with internal stakeholders
  • The ability to identify and mitigate risks, as well as to develop effective risk mitigation strategies
  • Self-motivated, ability to work independently, strong organizational skills
  • Ability to multitask and work in a fast paced environment
  • Consistently delivers results and meets deadlines
Job Responsibility
Job Responsibility
  • Identify, measure, and report operational and Third-Party Risk Management risks
  • Support management of third-party risk onboarding and due diligence by ensuring appropriate risk assessments are completed
  • Assist Business Owners with due diligence documentation and evaluation of third-party relationships
  • Execute issue management end-to-end activities (issue identification, prioritization, assignment, remediation, closure) for matters pertaining to third parties
  • Ensure adequate, appropriate, and current third-party risk documentation is maintained in the Third Party Risk Management Software System
  • Leverage the Third-Party Risk Management Software System as the system of record and as a reporting tool to analyze vendors for risk analysis
  • Consult with business leaders to effectively manage change when required
  • Provide risk oversight for process improvement projects, as needed
  • Liaise with senior management and Third-Party Risk Management stakeholders
  • Oversee and / or develop ongoing monitoring activities in alignment with TPRM policy
  • Fulltime
Read More
Arrow Right

Third Party Vendor Management Senior Analyst

Individuals in Operational Risk establish and manage operational risk policies, ...
Location
Location
Costa Rica , Heredia
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5-8 years of experience
  • Knowledge in risk management, particularly Resilience and Third-Party Risk Management
  • Understanding of Third-Party Management policy and procedures
  • Familiarity with risk governance structures and risk appetite parameters
  • Ability to create, apply, and analyze MIS of reports
  • Background in the implementation of third-party and resilience risk processes across various sectors and regions
  • Experience in conducting comprehensive third-party and resilience risk management reviews
  • Knowledge of relevant regulations and standards related to risk management, and ability to ensure compliance
  • Adapt to work across a diverse organization, managing various sectors and regions
  • Utilize strong analytical skills to interpret complex data and present it in a clear and understandable manner
Job Responsibility
Job Responsibility
  • Represent business leadership in Third-Party Risk Management activities coordination and facilitation
  • Evaluate market conditions and provide insight into trends that could impact the business
  • Advise on third-party risk assessments and reassessments
  • Verify third-party compliance to required policies and controls
  • Partner with operations and tech teams for on-site visits of third parties when necessary
  • Maintain and update Exit Strategy Plans as required
  • Address escalations of non-performance and contractual issues with third parties when necessary
  • Monitor third-party performance and service level agreements
  • Ensure proper execution and upload of third-party contracts in Contract Management System
  • Review, prioritize, assess, and act on third-party risk management assessments results
  • Fulltime
Read More
Arrow Right

Resilience Risk 2nd LOD Lead Analyst, Vice President

Individuals in Operational Risk establish and manage operational risk policies, ...
Location
Location
Hungary , Budapest
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 6-10 years of experience
  • Understanding of Third Party Risk management lifecycle and risk assessment processes
  • Thought leadership and clarity in presenting ideas to senior management
  • Proven technical knowledge of resilience and Third-Party Risk principles and processes, to include up to date knowledge of current technology solutions, including Cloud
  • Experience in implementing risk processes across a large and diverse organization
  • Knowledge of regulatory requirements underpinning resilience and the Third-Party Risk Management and Outsourcing Lifecycle (OCC/FRB/EBA/PRA/MAS, etc.)
  • Excellent analytical skills to interpret and present complex data
  • Proficiency in the use of MIS and other risk management tools
  • Excellent project management skills to oversee risk reviews and mitigation efforts
  • Strong communication skills to provide counsel and collaborate with various stakeholders
Job Responsibility
Job Responsibility
  • Provide strategic support in the formulation and implementation of operational risk management policies and procedures, prioritizing resilience and third-party risk management
  • Drive the identification, measurement, monitoring, and management of residual and emerging risks, ensuring consistent practices across the organization
  • Champion continuous improvement initiatives, incorporating lessons learned from resilience tests, simulations, and third-party risk analysis
  • Act as a liaison with internal and external stakeholders, fostering effective collaboration in risk management
  • Oversee and challenge key risk indicators and material operational risks, ensuring resilience and third-party risks stay within defined Risk Appetite parameters
  • Lead oversight reviews, addressing root causes of unintended losses and ensuring policy and regulatory compliance in resilience and third-party risk management
  • Assess the effectiveness of business and technology capabilities and controls across the organization, promoting the implementation of sound risk management processes
  • Develop, implement, and analyze reports to identify excessive risk areas, ensuring the effectiveness of risk mitigation efforts involving third parties
  • Facilitate the dissemination of operational risk management best practices, raising awareness of resilience and third risk-party among all staff
  • Assist risk management team leaders in staff development, fostering a high level of competence and morale in operational risk management
What we offer
What we offer
  • Global Benefits
  • support your well-being, growth and work-life balance
  • Fulltime
Read More
Arrow Right

Third Party Vendor Management Lead Analyst

Individuals in Operational Risk establish and manage operational risk policies, ...
Location
Location
Costa Rica , Heredia
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 6-10 years of experience
  • Understanding of Third Party Risk management lifecycle and risk assessment processes
  • Thought leadership and clarity in presenting ideas to senior management
  • Proven technical knowledge of resilience and Third-Party Risk principles and processes, to include up to date knowledge of current technology solutions, including Cloud
  • Experience in implementing risk processes across a large and diverse organization
  • Knowledge of regulatory requirements underpinning resilience and the Third-Party Risk Management and Outsourcing Lifecycle (OCC/FRB/EBA/PRA/MAS, etc.)
  • Excellent analytical skills to interpret and present complex data
  • Proficiency in the use of MIS and other risk management tools
  • Excellent project management skills to oversee risk reviews and mitigation efforts
  • Strong communication skills to provide counsel and collaborate with various stakeholders
Job Responsibility
Job Responsibility
  • Represent business leadership to coordinate and facilitate Third-Party Risk Management activities
  • Evaluate current market conditions and provide insight on trends/issues that could impact the business by external third parties
  • Advise the BAO on risk assessment for third parties and reassess as required
  • identify significant relationship changes to trigger risk assessment updates
  • Verify compliance of third parties with required policies and controls
  • Partner with business operations, technology teams, and internal functions to conduct on-site visits of third parties, as required
  • Maintain and update Citi’s Exit Strategy Plans as required
  • collaborate with business contacts to establish risk mitigation activities when the exit strategy poses significant risk to Citi
  • Interact with third parties on escalations of non-performance and contractual issues to drive resolution when appropriate
  • Monitor third party performance and Service Level Agreements (SLAs) through Citi Performance Management Assessment (PMA) process
  • Fulltime
Read More
Arrow Right

Assistant Vice President – Third Party Risk Oversight specialist - TPRO - Consumer Credit Risk

The AVP – Third party risk oversight role is responsible for owning and enhancin...
Location
Location
India , Mumbai
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 8+ years of experience in Risk management, third-party risk, vendor risk/management or credit risk with a large financial institution
  • US banking regulatory expectations
  • Prior experience operating with consumer credit risk or closely related risk domains
  • Extensive background in managing critical suppliers and regulated third-party relationships
  • Experience active as a risk/process oversight owner or leading risk platforms, frameworks, or governance models
  • Bachelor’s degree in related fields
  • Working knowledge of Vendor relationship management / Vendor risk management/ TPRO
  • Growth mindset with ability to balance risk, compliance and business enablement
  • Excellent stakeholder management and executive communication skills
  • Ability to challenge vendors and internal partners constructively
Job Responsibility
Job Responsibility
  • Product ownership and strategy: Own the end-to-end product vision for third-party risk oversight tools, processes, and controls within consumer credit risk
  • Own the TPRO vision, roadmap, and backlog, ensuring alignment with Citi risk policies and enterprise standards
  • Translate regulatory guidance, Citi policies, and risk requirements into User stories, controls, and functional requirements into scalable risk oversight solutions
  • Prioritize initiatives based on risk severity, regulatory commitments and business impact
  • Third-party Risk oversight: Oversee risk assessment lifecycle for third-party vendors, including: Inherent risk assessments, Due diligence (financial, operations, cyber, data privacy, model risk), Ongoing monitoring and periodic reviews
  • Ensure critical and high- risk vendors undergo enhanced oversight and governance
  • Maintain a risk-tiered vendor inventory aligned with consumer credit risk exposure
  • Supplier and contract management: Ensure supplier contracts meet regulatory, risk and control standard, including: SLAs, KPI, audit and access rights, data protection, information security, confidentiality, BCP/DR (business continuity planning/ Disaster recover), subcontractor and fourth-party controls
  • Track contract milestones, renewals, terminations and renegotiations
  • Proactively identify contracts nearing expirations and drive timely renewals or exit strategies
  • Fulltime
Read More
Arrow Right