# Supplier Risk Lead

**Company**: FCE Bank
**Location**: Dunton, Essex
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Category**: Finance
**Industry**: Finance

**Apply**: https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/63154?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_35b3e418-dc2

## Description

Operating within the Second Line of Defence, the Supplier Risk Lead provides independent oversight, challenge, and assurance over FCE Bank's third-party and supplier risk profile.

Responsibilities:

- Independently review and challenge supplier risk assessments and classifications completed by the First Line

- Conduct quality assurance reviews on supplier due diligence and risk mitigation plans

- Lead the design and enhancement of the global Third-Party Risk Management (TPRM) framework and policy

- Maintain supplier risk classification tools and support optimisation of the GRC/TPRM system

- Produce consolidated risk reporting, dashboards, and MI for senior leadership and Risk Committees

- Monitor Key Risk Indicators (KRIs), policy exceptions, and risk acceptances against risk appetite

- Oversee monitoring of third and fourth-party incidents, ensuring robust root-cause analysis and remediation

- Provide advisory support and guidance to business owners, contract managers, and Vendor Management

- Develop and deliver training to strengthen risk culture and assessment quality

- Facilitate risk-profiling workshops for high-risk or complex supplier projects

- Ensure TPRM compliance with regulatory standards (e.g., DORA, PRA SS2/21, BCBS/BIS)

- Support internal audits and regulatory inspections, evidencing 2LoD oversight

- Maintain the ICT Third-Party Register of Information under DORA

- Assess third and fourth-party concentration risk to safeguard operational resilience

Qualifications:

- Professional Qualifications: Relevant professional risk or security certifications (e.g., CRISC, CISA, or IRM credentials).

## Skills

### Required
- risk management
- supplier risk
- GRC/TPRM
- regulatory compliance
- risk assessment

### Nice to have
- CRISC
- CISA
- IRM credentials

---

Source: [Apply at efds.fa.em5.oraclecloud.com](https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/63154?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
