Outsourcing and Third Party Risk Management Lead

Company: Teya Solutions
Apply for the Outsourcing and Third Party Risk Management Lead
Location: London
Job Description:

Overview

In this role you lead Teya’s day-to-day outsourcing and third party risk activities within the first line of defence. You own the TPRM framework across the business, coordinating due diligence, monitoring, and contract risk reviews. You’ll partner with Procurement, Legal, Information Security, Compliance, and Operational Risk to maintain registers and produce insight for governance. The role combines fast-paced delivery with risk-based decision making to enable rapid yet safe business growth. You will shape how we manage external providers in a mission-driven fintech environment.

Responsibilities

  • Own and maintain outsourcing and ICT third party registers in line with EBA Guidelines on Outsourcing, DORA, and FCA/PRA expectations
  • Coordinate due diligence across information security, data protection, financial crime, business continuity, and concentration risk
  • Manage ongoing monitoring: performance reviews, control attestations, incident tracking, and re-assessments of material third parties
  • Serve as first point of contact for business owners on third party risk, guiding onboarding, risk assessment, and contract review
  • Produce management information and reporting for senior governance forums highlighting risks and remediation progress
  • Collaborate with Compliance and Operational Risk (2LOD) to translate regulatory updates into operational practice
  • Support regulatory submissions, audits, and supervisory engagements on outsourcing and ICT third party matters
  • Drive continuous improvement of TPRM processes, controls, and tooling with risk-based prioritisation

Key requirements

  • A minimum of 3 years of experience in outsourcing or third party risk management within a regulated financial services environment (payments, e-money, banking, or similar)
  • Working knowledge of the EBA Guidelines on Outsourcing Arrangements and DORA
  • Experience running due diligence and ongoing monitoring across material third parties, including critical or important outsourcing arrangements and ICT services
  • Highly organised, with strong attention to detail and the ability to manage a large portfolio of third parties simultaneously
  • Pragmatic, risk-based mindset prioritising speed and safety in decision making
  • Comfortable building with AI and using AI tooling for due diligence summarisation, drafting, evidence review, data extraction
  • Bias to action and ability to ship initial processes or templates quickly
  • Commercial awareness with ability to discuss trade-offs with engineers, product owners, and commercial leads
  • Desirable: experience with TPRM tooling (Aravo, Prevalent, OneTrust, ProcessUnity) and DORA implementation across a financial services firm
  • Desirable: familiarity with operational resilience frameworks and identifying important business services
  • highly organised
  • pragmatic risk-based mindset
  • bias to action
  • EBA Guidelines on Outsourcing
  • DORA
  • TPRM tooling (Aravo, Prevalent, OneTrust, ProcessUnity)

Posted: September 20th, 2026