Client: US enterprise client (insurance & financial services), empowering its in-house Cyber Security & Technology Risk organization
Location: Bucharest or Cluj
Work Model: Hybrid - 1 day/week onsite
Contract Type: Contract-to-Hire / B2B - initial 12-month contract, with strong potential for internalization into a permanent role
Schedule: Monday – Friday, 10:00 – 19:00 Romanian time (with 1 hour lunch break)
About the Role
We're looking for a Third-Party Risk Consultant to join our client's Cyber Security & Technology Risk team, supporting its leading US financial services and insurance organization. You'll play a key role in executing third-party risk assessments and due diligence activities across the organization's vendor ecosystem, covering new vendor onboarding and annual reassessments for vendors based in the US, Romania, and India.
This work sits at the intersection of vendor risk, cybersecurity controls, regulatory expectations, and technology operations. You'll evaluate services, data flows, system integrations, controls, and evidence to identify and document risk exposure, helping the organization strengthen its third-party risk framework.
You'll join a global, cross-functional team working alongside business stakeholders based in the US, and risk and QA/audit colleagues based in India, collaborating closely with issue management, procurement, compliance, legal, and audit partners.
Why Join Us
- Join a growing Cyber Security & Technology Risk function within a large, global financial services organization.
- Work directly on third-party risk assessments for vendors across the US, Romania, and India - high-visibility, high-impact work.
- Contract-to-Hire arrangement with real potential for internalization after the initial 12-month period.
- Collaborate cross-functionally with a global team spanning the US, Romania, and India.
- Build hands-on expertise across GRC platforms, security control frameworks (SOC 2, ISO 27001), and vendor risk methodology.
What You'll Do
- Execute third-party entity risk assessments for new vendor contracts and annual reassessments, covering vendors across the US, Romania, and India.
- Analyze third-party services, data flows, and system integrations to identify inherent and residual risk exposure.
- Review and interpret security controls and audit reports (e.g., SOC 2, ISO 27001) to assess control adequacy relative to risk.
- Collaborate with issue management teams to ensure identified risks and vulnerabilities are appropriately tracked, communicated, and remediated.
- Evaluate, document, and support breach event and incident response activities.
- Identify control gaps, weaknesses, or non-compliance issues and clearly document findings for further review.
- Partner with senior practitioners to support risk rating determinations and escalation decisions.
- Contribute to status reporting and metrics tracking for ongoing third-party risk activities, using GRC platforms (e.g., Archer, RiskRecon), ServiceNow, Jira, and Confluence.
- Research and consult with internal subject matter experts to understand and document risk identified through assessments and due diligence.
- Collaborate across Romania, US, and India working hours to ensure timely resolution of asks and escalations.
What We're Looking For
- 3+ years of experience in third-party/vendor risk management, technology risk, cybersecurity, audit, or controls testing.
- Hands-on experience conducting third-party entity assessments (new vendor onboarding) and annual reassessments.
- Solid understanding of risk assessment, vulnerability management, security controls, and regulatory expectations.
- Ability to read and interpret security control frameworks such as SOC 2 and ISO 27001.
- Experience with GRC platforms (e.g., Archer, RiskRecon) and ticketing/collaboration tools such as ServiceNow, Jira, and Confluence.
- Foundational understanding of third-party risk domains: cybersecurity & data protection, cloud/SaaS risk, identity and access management, business continuity & resiliency.
- Familiarity with industry frameworks such as NIST, ISO 27001, or SOC 2.
- Strong written and verbal communication skills, comfortable interacting with internal stakeholders, third parties, and globally distributed teams.
- Experience working in a contract, consulting, managed services, or globally distributed team environment, with the ability to ramp up quickly and build trust with remote stakeholders across the US and India.
- Strong attention to detail and documentation discipline; comfortable executing with limited guidance in a structured, process-driven environment.
Recruitment Process
- Round 1: Technical Screening - with the US Manager and RO Manager.
- Round 2: Technical / Panel Interview - with 2 US-based team members.