Senior Third-Party Risk Specialist
About the role
As a Senior Third-Party Risk Specialist, you will be responsible for identifying, assessing, and mitigating risks associated with third parties (vendors, partners, subcontractors, etc.) at Mistral. You will play a pivotal role in safeguarding our assets, data, and reputation by ensuring that our third-party relationships adhere to the highest standards of security, compliance, and resilience. You will work closely with Legal, Procurement, Security, and Operational teams to embed a proactive third-party risk management approach into our business processes.
Responsibilities
- Develop and manage the third-party risk management program: Design, implement, and maintain a structured framework for identifying, assessing, and monitoring risks associated with third parties (vendors, partners, service providers, etc.).
- Conduct third-party assessments and audits: Perform due diligence, compliance assessments, security audits, and contractual reviews to ensure third parties meet our requirements and regulatory obligations (e.g., GDPR, NIS2, DORA).
- Collaborate with internal teams: Work with Procurement, Legal, Security, and Operations teams to integrate third-party risk requirements into vendor selection, negotiation, and monitoring processes.
- Manage incidents and non-compliance: Identify and address gaps or incidents related to third parties, coordinating corrective actions and ensuring follow-up until resolution.
- Raise awareness and train stakeholders: Develop and deliver training and guidance to educate internal teams on third-party risk issues and their responsibilities.
- Maintain robust documentation: Document assessments, decisions, and actions related to third-party risk management, ensuring traceability for internal and external audits.
- Monitor regulatory and standards evolution: Stay updated on changes in regulations (e.g., NIS2, Cyber Resilience Act, GDPR) and standards (e.g., ISO 27001, SOC 2, ISO 27036) impacting third-party risk management, and propose adjustments to the internal framework.
- Optimize tools and processes: Contribute to the continuous improvement of tools (e.g., third-party risk management platforms) and methodologies to enhance the program's effectiveness.
- Align with broader resilience strategy: Ensure the third-party risk management program supports the company's overall cybersecurity and compliance objectives.
- Contract redlining and negotiation skills: Ability to review, edit, and negotiate contractual terms to align with security and compliance requirements.
Requirements
- 7+ years in third-party risk management, cybersecurity compliance, information security governance, or a related field.
- Experience supporting cybersecurity compliance programs, certification processes, or external audits.
- Practical knowledge of standards and frameworks such as ISO 27001, SOC 2, NIST SP 800-53, or regulations like NIS2, DORA, GDPR.
- Proficiency in risk assessment methodologies (e.g., EBIOS RM, ISO 27005).
- Familiarity with cybersecurity regulations such as NIS2, the Cyber Resilience Act, LPM, or DORA.
- Strong organizational skills and attention to detail, with the ability to manage documentation and coordinate multiple stakeholders.
- Excellent written and verbal communication skills.
- Strong analytical and problem-solving abilities.
- Ability to work collaboratively across technical, legal, commercial, and operational teams.
- Professional proficiency in English; French proficiency is a plus.
Benefits
We offer a comprehensive benefits package designed to support your well-being, growth, and work-life balance. Benefits vary by country and may include healthcare coverage, parental leave, retirement plans, relocation support, wellness programs, meal and transportation allowances, and other location-specific perks.