Manager ICT Third Party Risk
Meet Our Recruiter
Josh Mooney
About the Role
Manager ICT & Information Security Third Party Risk – 2nd Line of Defence
The Opportunity
If your current role only lets you flag risk after the decision's already been made, this one is different.
Here, you sit in the second line of defence with a genuine mandate to challenge. You'll assess how external providers handle security and technology risk, then push back when what you see doesn't meet the bar, regardless of how senior the stakeholder is on the other side of the table.
You'll work across Information Security, IT, Procurement and Operational Risk, with direct visibility into risk committees and senior management reporting.
The Role
You'll independently review and challenge the first line's risk assessments for third-party providers, from critical suppliers to cloud vendors and outsourcing partners.
- Assess the security posture of critical suppliers, vendors, cloud providers and outsourcing partners
- Challenge the first line on identified risks, controls, remediation plans and risk acceptances
- Evaluate third-party controls across IAM, data protection, vulnerability management, incident response, cloud security and cyber resilience
- Support and help shape the TPRM and Information Security Risk frameworks
- Monitor third-party incidents, vulnerabilities and control weaknesses through to remediation
- Ensure alignment with DORA, NIS2, ISO 27001, EBA Guidelines and MaRisk
- Prepare risk reporting for senior management and risk committees
- Support internal audits and regulatory assessments
Your findings feed directly into how the organisation manages its third-party exposure, giving you visibility that's hard to get in a first-line role.
The Company
Our client is a well-established, regulated financial services organisation with a mature second-line risk function. Its size and regulatory footprint mean third-party risk is treated as a genuine priority, not a box-ticking exercise, and the frameworks you'll work within are built to hold up under real regulatory scrutiny.
What You'll Need
- Several years' experience in Information Security, ICT, Third Party or Cyber Risk
- Solid knowledge of TPRM processes and third-party security assessments
- Familiarity with ISO 27001, DORA, NIS2 and EBA requirements
- Knowledge of cloud security, IAM, vulnerability management, incident response and cyber resilience
- Confidence to independently challenge the first line and communicate risk to senior stakeholders
- Fluent German and English
How to Apply
Interested? Your CV doesn't need to be up to date. Send what you have, or just give us a call, and we'll talk you through the details.