The role involves leading the identification, assessment, and monitoring of risk exposure from outsourced services and critical ICT vendors within the Apex Group
Job Summary
The role involves leading the identification, assessment, and monitoring of risk exposure from outsourced services and critical ICT vendors within the Apex Group.
Candidates will design and operate a comprehensive risk-based Third-Party Assurance programme covering due diligence, onboarding, continuous monitoring, and exit strategies.
The position requires providing decision-ready inputs to the Technology Risk Forum while partnering with procurement, legal, and security engineering teams globally.
Matching Summary
The role involves leading the identification, assessment, and monitoring of risk exposure from outsourced services and critical ICT vendors within the Apex Group.
Skills & Requirements
Must-have
Third-party technical risk assurance experience
DORA ICT contractual clauses expertise
ISO/IEC 27001:2022 compliance knowledge
NIST CSF 2.0 outcomes implementation
Cloud provider security assessment skills
Nice-to-have
Exceptional stakeholder influence skills
Experience with EU AI Act responsibilities
Strong executive reporting capabilities
Regional enablement and harmonization experience
Key Requirements
10–15+ years in third-party technical risk assurance
Experience within financial services sector
Hands-on experience embedding DORA contractual clauses