MENA Consultant is seeking a highly experienced Senior Third-Party Risk Management Consultant for a 2-year remote engagement. You will play a pivotal role in assessing and managing risks across the entire vendor lifecycle, ensuring that our clients maintain robust cybersecurity, operational, and compliance standards.
Key responsibilities
- Conduct comprehensive inherent and residual risk assessments for third-party vendors and service providers.
- Perform risk-based due diligence to identify cybersecurity, technology, operational, and privacy risks.
- Evaluate vendor security controls, audit reports, and certifications to validate their effectiveness.
- Manage vendor risk registers, track remediation plans, and facilitate risk acceptance processes.
- Collaborate with procurement, legal, and cybersecurity teams to support informed vendor decision-making.
Requirements
- 8-10 years of professional experience in Third-Party Risk Management (TPRM).
- Fluency in both Arabic and English, both written and spoken.
- Strong knowledge of cloud service risks, SaaS platforms, and fourth-party risk management.
- Familiarity with NCA controls, privacy regulations, and industry cybersecurity standards.
- Proven ability to develop and improve TPRM frameworks, methodologies, and reporting procedures.
What we offer
- A long-term, 2-year project engagement in a professional consulting environment.
- Full flexibility to work remotely from any location.
- Opportunity to work with diverse stakeholders across business, legal, and technical departments.
- Exposure to complex risk management challenges within the MENA region.