Senior Third-Party Risk Management Consultant (2-year remote)
MENA Consultant · Amman
Job description
About the role
We are looking for a Senior Third-Party Risk Management Consultant to lead a two‑year remote engagement. The consultant will assess and manage risks throughout the vendor lifecycle, from onboarding and due diligence to ongoing monitoring and off‑boarding, working closely with procurement, legal, cybersecurity, compliance and business teams.
Key responsibilities
- Plan and execute TPRM engagements, delivering risk assessments and due‑diligence reviews for new and existing third‑party relationships.
- Evaluate cybersecurity, technology, operational, privacy, compliance and business‑continuity risks using vendor responses, audit reports, certifications and independent assurance evidence.
- Maintain and update third‑party risk registers, remediation plans, risk exceptions and governance documentation.
- Monitor high‑risk vendors through periodic reviews, security alerts, performance metrics and emerging‑threat assessments.
- Analyze concentration, dependency and fourth‑party risks to support supply‑chain resilience objectives.
- Collaborate with cross‑functional stakeholders to ensure comprehensive risk evaluations and alignment with contractual security clauses, SLAs and data‑protection obligations.
- Provide management reports, dashboards and executive presentations highlighting risk posture, critical findings and remediation progress.
Required profile
- 8‑10 years of experience in third‑party risk management, including vendor due diligence, inherent and residual risk assessments, and risk‑based reviews.
- Strong knowledge of cloud services, SaaS platforms, managed services and related fourth‑party risk considerations.
- Familiarity with contractual risk requirements such as security clauses, audit rights, incident‑notification obligations and data‑protection standards.
- Fluency in Arabic and English, both written and spoken.
Required skills
- Third‑Party Risk Management (TPRM) methodology and frameworks.
- Vendor due‑diligence and risk‑assessment techniques.
- Cybersecurity and cloud services risk evaluation.
- Business continuity and operational resilience assessment.
- Risk register management and remediation tracking.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Jordan.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 4 days ago
Expires 1 month from now
17 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
MENA Consultant
Amman