Senior Third-Party Risk Management (TPRM) Analyst / Lead
Location: Ireland (Hybrid - Dublin / Cork options)
Contract Duration: 6 Months Initial (Strong likelihood of extension)
Start Date: Immediate / ASAP
My client in Cork is seeking an experienced Third-Party Risk Management (TPRM) Analyst.
Key Responsibilities
- Framework & Operating Model Design: Define the TPRM vision, governance, risk principles, team structure, and cross-functional ownership across Procurement and Enterprise Risk (3 Lines of Defence).
- Critical Service & Supplier Mapping: Work with Resilience teams to link critical services/assets to supporting third and fourth parties; establish a robust, criticality-based supplier identification methodology.
- Risk Assessment & Tiering: Develop comprehensive risk assessment methodologies (covering cyber, operational continuity, financial, regulatory, fourth-party, physical security, and ESG) and establish supplier oversight tiering models.
- Procurement Integration: Build TPRM checkpoints into all stages of procurement-from tender and award through onboarding, ongoing monitoring, and exit.
- Legal & Contract Remediation: Collaborate with Legal to establish a tiered library of compliant contract clauses (audit rights, incident reporting, BCDR, cyber flow-downs) and lead high-priority contract remediations.
- Monitoring & Technology: Define review frequencies, Key Risk Indicators (KRIs), and external intelligence triggers (e.g., BitSight, SecurityScorecard). Assess options and build business cases for TPRM tech platforms and managed services.
- Senior Stakeholder Engagement: Deliver executive-ready reporting and board papers, uniting historically siloed teams across Risk, CISO, Legal, Finance, and Procurement.
Essential Requirements
- 5-10 years' experience in TPRM, supplier risk, or operational risk, with a proven track record of designing and deploying TPRM frameworks from scratch in regulated environments.
- Strong working knowledge of NIS2 and CER directives (or similar regulatory regimes such as DORA).
- Understanding of public or utilities procurement rules, specifically integrating risk requirements into formal tenders, frameworks, and contract call-offs.
- Demonstrated experience building risk assessment and tiering models built to withstand audit and regulatory scrutiny.
- Strong executive presence, cross-functional facilitation skills, and a pragmatic, delivery-focused mindset.
