AML RightSource logo
AML RightSource

AML RightSource is committed to fostering a diverse work environment and is proud to be an equal opportunity employer. We provide equal employment opportunities to all qualified applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Third Party Risk Management (TPRM) Lead

RiskRiskFull TimeRemoteLeadTeam 5,001-10,000

Location

Poland

Posted

2 days ago

Salary

PLN14.2K / month

Seniority

Lead

No structured requirement data.

Job Description

Third Party Risk Management (TPRM) Lead

AML RightSource

Role Description The Third Party Risk Management (TPRM) Lead is responsible for designing, implementing, and operating an enterprise-wide Third Party Risk Management framework. This role leads the transformation of the current vendor onboarding and oversight process into a structured, scalable, and risk-based TPRM program aligned with regulatory expectations and organizational risk appetite. The TPRM Lead partners cross-functionally with Information Security, Privacy, Legal, IT, and Business stakeholders to ensure third-party risks are appropriately identified, assessed, monitored, and mitigated throughout the vendor lifecycle. - Lead and administer the global Third Party/vendor review program, including risk rating of new vendors, managing the end-to-end onboarding process, and conducting annual reviews of existing material and high-risk vendors. - Implement formal Third Party Risk Management framework aligned with industry standards and best practices. - Establish procedures covering: - Vendor onboarding - Ongoing monitoring - Vendor offboarding - Organize and maintain centralized repositories for relevant Third-Party Risk and metrics documents. - Establish and maintain a centralized vendor inventory with risk classification and ownership tracking. - Review and redesign vendor onboarding workflows and intake questionnaires. - Ensure onboarding requirements align with: - Information Security requirements - Privacy and data protection requirements - Regulatory and compliance expectations - Develop and implement standardized vendor risk assessment questionnaires. - Define minimum evidence and documentation requirements, including certifications, control attestations, and security documentation. - Establish review, escalation, and approval workflows for vendor assessments. - Perform specialized reviews with Information Security and Privacy teams, including technical assessments and Data Protection Impact Assessment (DPIA) where required. - Design and implement a structured vendor monitoring and annual review program. - Track vendor risk posture over time and ensure timely reassessments and remediation follow-up. - Support customer due diligence processes and reduce repetitive inbound security questionnaires through centralized documentation. - Assess and integrate evolving regulatory requirements impacting third-party risk management, including EU AI Act considerations where applicable. - Ensure AI-related vendor risks are identified and addressed within the TPRM framework. - Monitor emerging regulatory, technology, and operational risks relevant to vendor management practices. - Lead remediation and reduction of existing vendor review and alerts using a risk-based prioritization approach. - Serve as the primary point of contact for third-party risk management matters across the organization. - Develop and maintain TPRM metrics, dashboards, and reporting capabilities. - Provide regular reporting and program updates for Risk & Compliance leadership. - Partner with Legal to ensure that Non-Disclosure Agreements (NDAs) are properly executed where required. - Serve as the primary point of contact for Third Party adverse media escalations (Perform Level 2 disposition). - Support internal audits, external audits/certifications (i.e. SOC2, ISO27001), customer due diligence, and certification activities. - Help identify and lead initiatives to ensure that compliance activities throughout the organization are effective and in compliance with SOC2 and ISO27001. - Assist with generating responses to Client Due Diligence requests. - Assist with the execution of compliance related activities such as our Business Continuity/Disaster Recovery exercises, risk matrix reviews, incident response tabletops, etc. - Perform analysis of software to ensure compliance with IP rights. - Support broader compliance activities as needed. Qualifications - 3–5 years of experience in Third Party Risk Management, Vendor Management, Information Security, Compliance, Risk, Audit, Privacy, or related operational function. - Experience supporting vendor onboarding, risk assessments, compliance reviews, privacy reviews, or governance processes. - Ability to coordinate cross-functional activities involving Information Security, Privacy, Legal, and Business stakeholders. - Experience reviewing vendor documentation such as SOC 2 reports, security questionnaires, certifications, privacy documentation, or compliance evidence is preferred. - Familiarity with privacy and data protection requirements impacting third-party risk management, including GDPR concepts, DPIAs, and data processing considerations. - Strong analytical and problem-solving skills with attention to detail. - Effective written and verbal communication skills, including the ability to communicate risk, privacy, and process requirements clearly to stakeholders. - Experience working with governance, risk, compliance, procurement, ticketing, or vendor management tools (e.g., JIRA) is preferred. - Ability to support process improvement initiatives and help implement scalable governance practices. - Relevant certifications such as CIPP/E, Security+, ISO 27001 Foundations, CISA, CRISC, or similar are a plus. Benefits - Minimum salary: 14,166 PLN gross/month - Comprehensive private medical healthcare - Remote work options subject to the type of position or project - The option to join a group private insurance plan (subject to a fee) - MyBenefit Cafeteria including Multisport - Annual discretionary bonus, subject to both company performance and individual contribution - Employee Assistance Program (EAP) - Access to goFLUENT language learning platform

Related Categories

Related Job Pages

More Risk Jobs

Wahed logo

Shariah Risk Associate

Wahed

Halal investing made simple

Risk2 days ago
Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

• Assist in reviewing internal documents, contracts, and product materials from a Shariah perspective. • Support Shariah compliance monitoring activities, including maintaining approval records, trackers, and audit documentation. • Conduct basic research on Shariah rulings, AAOIFI standards, and contemporary Islamic finance practices. • Help prepare summaries, internal reports, and presentations for Shariah reviews and training sessions. • Support the Shariah team in responding to internal queries, risk reviews, and audit requirements. • Maintain organized documentation, version control, and structured archives for Shariah-related materials.

India
Encompass Health logo

Regional Quality/Risk Director

Encompass Health

Encompass Health is a trusted leader in post-acute care with over 150 nationwide locations and a team of 36,000 exceptional individuals and growing! We proudly set the standard in care by leading with empathy. We do what's right, focus on the positive, and stand stronger together. We provide equal employment opportunities regardless of race, ethnicity, gender, sexual orientation, gender identity or expression, religion, national origin, color, creed, age, mental or physical disability, or any other protected classification.

Risk3 days ago
Full TimeRemoteTeam 10,001

Role Description The Regional Quality/Risk Director is responsible for helping to create an environment and culture that enables the region to fulfill its mission by meeting or exceeding its goals, conveying the company's mission to all staff, facilitating hospital accountability for their performance, and motivating staff to improve their performance. - This position will support cultural diversity by ensuring that the delivery of quality, equitable and culturally competent patient-centered care is provided. - Promoting and maintaining an inclusive work environment and culture that is respectful and accepting of diversity. Qualifications - Experience in quality and risk management. - Strong leadership and motivational skills. - Ability to work in a remote environment. Requirements - Job Code: 100140 - #LI-KC1 Benefits - Competitive salary and benefits package. - Opportunities for professional development. - Inclusive culture that celebrates diversity. Company Description Encompass Health is a trusted leader in post-acute care with over 150 nationwide locations and a team of 36,000 exceptional individuals and growing! - We proudly set the standard in care by leading with empathy. - We do what's right, focus on the positive, and stand stronger together. - We provide equal employment opportunities regardless of race, ethnicity, gender, sexual orientation, gender identity or expression, religion, national origin, color, creed, age, mental or physical disability, or any other protected classification.

United States
Church Mutual Insurance Company, S.I. logo

Risk Control Consultant (Specialist)

Church Mutual Insurance Company, S.I.

Church Mutual is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. Exact compensation will vary based on consideration of a variety of factors including education, skills, experience, and location.

Risk3 days ago

Role Description Provide risk control services to Church Mutual customers and prospective accounts for a specific market segment. Represent Risk Control at service capability presentations and customer onboarding sessions. Analyze data to determine gaps in risk control services/materials to the specialized market and develop and implement solutions. Develop relevant and unique educational content pertinent to the specific market. On any given day, you'll: - Consult with customers, in the assigned market, both in-person and remotely for risk mitigation to reduce losses and strengthen their Risk Control Program. - Develop content and deliver presentations to assist internal and external customers to better understand the unique risk exposures of the assigned market. - Analyse data and identify gaps in existing service strategies, resources, and training programs. Develop, recommend, and implement needed changes. - Work with the Underwriting Department to develop risk reduction techniques for the specialty market. - Work with the Marketing Department to develop risk control materials for the specialty market. Qualifications - Bachelor's degree or equivalent experience is required. Bachelor's degree in a safety related field is preferred. - Evidence of continuing education in the insurance industry is desired. - A minimum of five years of experience within the specific market. - Extensive knowledge of specialized facility operations and related loss exposures and controls within the specific market. - Highly conversant with training materials and programs specific to the needs of the specialized market. - Experience in managing risk control services on large accounts is preferred. - Mastery in developing presentations and presenting to groups. - Excellent verbal and listening skills. - Excellent planning skills for service delivery and itinerary management. - Demonstrated consulting skills in risk control area. - Proven ability to analyze data, develop, and implement solutions. - Proven time management and detailed organizational skills. Requirements - Overnight travel is required 2-3 weeks a month. - Travels routinely via plane to customer locations. - Ability to operate a motor vehicle. - Works inside and may work outside in heat/cold, wet/humid, dry/arid, and varied lighting conditions. - May require occasional physical activities that include standing, walking (including extended periods on level and uneven walkways and surfaces that are wet, icy, snowy, or cluttered), bending, kneeling, stooping, crouching, crawling, and climbing (including ladders and stairs). Company Description Church Mutual is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. Exact compensation will vary based on consideration of a variety of factors including education, skills, experience, and location.

United States
Teleplan Globe logo

Fagansvarlig, UxS regulatorisk etterlevelse

Teleplan Globe

Software and Solutions for Decision Makers that Protects People, Assets and Institutions

Risk3 days ago
Full TimeRemoteTeam 51-200H1B No Sponsor

• Følge opp relevant regelverk og standarder knyttet til UxS-operasjoner • Omsette regulatoriske krav til interne føringer, prosesser og dokumentasjon • Sikre at compliance-hensyn ivaretas i krav, backlog, test og leveranser • Bygge opp og vedlikeholde styrende dokumentasjon og etterlevelsesrammeverk • Bidra til regulatoriske vurderinger i forbindelse med test, demonstrasjon og operativ bruk • Støtte organisasjonen med faglige vurderinger og beslutningsunderlag ved regulatorisk usikkerhet

Norway