Logo for MENA CONSULTANCY

Senior Third-Party Risk Management Consultant - 2-Year Engagement

Role overview

Qualifications

  • 8-10 years of experience in third-party risk management (TPRM)
  • Fluency in Arabic and English (written and spoken)
  • Experience assessing cybersecurity and operational risks
  • Knowledge of contractual risk requirements and compliance regulations

Responsibilities

  • Support the planning and execution of Third-Party Risk Management engagements
  • Conduct risk assessments for third parties and service providers
  • Evaluate third-party security controls and compliance posture
  • Develop and maintain third-party risk registers and remediation plans

Key facts

Hard skills

Other skills

  • Collaboration
  • Analytical Skills
  • Communication
  • Problem Solving

About the company

MENA CONSULTANCY logo

MENA CONSULTANCY

Business Consulting & Services

MENA Consultancy is a multi-jurisdictional corporate services firm headquartered in Dubai, UAE, with offices in Doha, Qatar and Nairobi, Kenya. Established in 2011 and with over 2,000 corporate and private client structures to our name, we advise entrepreneurs, family offices and corporations at every stage of their business lifecycle, from company formation and initial market entry through to ongoing operations and compliance. Our experienced team guides clients through every requirement their jurisdiction demands: incorporation, licensing, immigration, local labour law, accounting and tax filing. Our core services include: Bespoke Entity Formation, Licensing & Structuring - SPVs, holding companies, trusts, foundations and operational entities, across mainland, free zone, financial free zone and offshore jurisdictions; Regulatory, Compliance & Governance - corporate secretarial services, statutory filings, beneficial ownership registration, economic substance compliance, policy frameworks and corporate records maintenance; Corporate Legal Advisory - legal counsel supporting business operations and corporate matters; Residency & Visa Solutions - immigration and labour services support and residency planning for individuals and corporate personnel; Business Support Services - HR administration, payroll processing, corporate tax registration and filing, VAT registration and compliance, bookkeeping and accounting support; Company Liquidation - end-to-end support for the voluntary liquidation and dissolution of entities, managing the full process from regulatory notifications through to the cancellation of licences and final deregistration; Twice recognised at the MEA Markets UAE Business Awards 2025 - Most Client-Focused Business Set-Up Consultancy and Client Service Excellence Award, we combine regional insight with international standards to deliver results that are cost-effective, practical, compliant and built for long-term success.

Company details

Company typeTPE
IndustryBusiness Consulting & Services
Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Location: remote.
Years of Experience: 8-10 years.
Project Duration: 2 years.
Language Requirements: Fluency in Arabic & English (written and spoken).

 

We are seeking a Senior Third-Party Risk Management Consultant to assess and manage risks across the full vendor lifecycle, from onboarding and due diligence through ongoing monitoring and offboarding. The consultant will evaluate third-party cybersecurity, technology, operational, privacy, compliance, and resilience risks; track findings and remediation; and help strengthen TPRM frameworks and reporting. The role involves working closely with procurement, legal, cybersecurity, compliance, and business teams to support informed vendor decisions.

Key Requirements

  • Strong experience in third-party risk management (TPRM), including vendor due diligence, inherent and residual risk assessments, and risk-based reviews throughout the vendor lifecycle.
  • Experience assessing cybersecurity, technology, operational, compliance, privacy, and business continuity risks associated with third parties.
  • Ability to evaluate vendor security controls using assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports.
  • Experience managing vendor risk registers, findings, remediation plans, risk acceptance, and exceptions.
  • Knowledge of risks associated with cloud services, SaaS platforms, managed services, and other technology providers, including concentration and fourth-party risk.
  • Experience assessing third-party business continuity, disaster recovery, and operational resilience capabilities.
  • Familiarity with contractual risk requirements, including security clauses, SLAs, data protection obligations, audit rights, and incident notification.
  • Experience developing or improving TPRM frameworks, procedures, assessment methodologies, and reporting.
  • Knowledge of applicable NCA controls, privacy requirements, cybersecurity standards, and vendor risk regulations.

Key Responsibilities

  • Support the planning and execution of Third-Party Risk Management engagements in alignment with project objectives, methodologies, and delivery timelines.
  • Conduct inherent and residual risk assessments for third parties, vendors, service providers, partners, and outsourced services across customer's business and technology landscape.
  • Perform risk-based due diligence reviews for new and existing third-party engagements to identify cybersecurity, technology, operational, compliance, privacy, and business continuity risks.
  • Evaluate third-party security controls, governance practices, and compliance posture against customer requirements, regulatory obligations, and industry standards.
  • Review vendor assessment responses, supporting evidence, audit reports, certifications, and independent assurance reports to validate control eUectiveness.
  • Assess third-party compliance with applicable requirements, including contractual obligations, information security requirements, NCA controls, privacy requirements, and internal policies.
  • Facilitate vendor risk assessments throughout the third-party lifecycle, including onboarding, periodic reassessments, contract renewals, significant changes, and oUboarding activities.
  • Identify, document, and assess third-party risks associated with cloud services, managed services, SaaS platforms, telecommunications providers, and strategic technology partners.
  • Evaluate concentration risk, dependency risk, fourth-party risk, and critical supplier exposure to support resilience and supply chain risk management objectives.
  • Collaborate with procurement, legal, cybersecurity, compliance, privacy, and business stakeholders to ensure comprehensive vendor risk evaluations.
  • Develop and maintain third-party risk registers, assessment records, risk exceptions, remediation plans, and supporting governance documentation.
  • Track identified findings, remediation actions, and risk treatment plans, ensuring timely closure of vendor-related risks and control gaps.
  • Facilitate third-party risk acceptance and exception processes, including risk impact analysis, compensating control reviews, stakeholder coordination, and approval workflows.
  • Perform ongoing monitoring of critical and high-risk vendors through periodic reviews, risk indicators, security alerts, performance metrics, and emerging threat assessments.
  • Assess third-party business continuity, disaster recovery, and operational resilience capabilities to ensure alignment with customer recovery requirements and service expectations.
  • Review contractual security and risk requirements, including security clauses, service level agreements (SLAs), data protection obligations, audit rights, and incident notification requirements.
  • Support the development, maintenance, and enhancement of Third-Party Risk Management frameworks, methodologies, procedures, standards, and assessment templates.
  • Analyze vendor risk trends, assessment outcomes, and risk exposures to provide actionable insights and recommendations for management decision-making.
  • Prepare management reports, dashboards, risk metrics, and executive presentations highlighting vendor risk posture, assessment status, critical findings, and remediation progress.
  • Promote awareness and adoption of Third-Party Risk Management requirements across business units and relevant stakeholder groups.
  • Ensure alignment with customer policies, regulatory requirements, and industry frameworks related to vendor risk management, cybersecurity, operational resilience, and supply chain security.

If you would like to know more about the Global Consulting Bootcamp Visit: https://caseinpointco.com/global-consultant-bootcamp/
If you would like to know more about the MC Club Visit: https://menaconsultant.com/mc-club/

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk Management Specialist Related jobs

Other jobs at MENA CONSULTANCY

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.