Data Risk Officer; Third-Party Risk
Listed on 2026-06-14
-
IT/Tech
Data Security, Cybersecurity, Information Security
Kennedys is looking for a Data Risk Officer (Third-Part Risk) to join the Risk & Compliance team, supporting the firm's third-party risk management (TPRM) framework, ensuring that risks arising from suppliers and external partners are identified, assessed, and controlled.
The role focuses on supplier due diligence, risk assessment, and ongoing monitoring to ensure compliance with regulatory, client, and internal obligations.
TeamKennedys Risk & Compliance team handles a wide range of partnership and risk and compliance issues for the firm and acts as an in-house legal department assisting with regulatory and professional conduct enquiries. Within this the Data Risk Team specialises in risk to data, privacy and information as well as compliance with associated regulations and best practise globally. This includes keeping abreast of new and emerging risks associated with ever developing technology such as AI.
Key Responsibilities- Support end-to-end third-party risk lifecycle including onboarding, assessment, and review
- Maintain third-party records within Sure Cloud and ensure documentation completeness and regular review
- Conduct supplier due diligence across data protection, security, and compliance
- Support risk tiering based on business impact and data sensitivity
- Assist with GDPR compliance and contract/data processing reviews
- Support DPIAs involving third parties
- Work with Procurement, IT, and Legal to apply governance into onboarding and offboarding of suppliers
- Monitor supplier risk posture and support reporting activities
- Support audits and client assurance processes
- Assist with third-party incident investigations and remediation tracking
- Understanding of GDPR and data protection principles
- Understanding of supply chain risk in technology
- Exposure to third-party risk or supplier due diligence and awareness of EU DORA
- Strong stakeholder management and organisational skills
- Ability to analyse and communicate risk clearly
Please let us know if you require any additional support or adjustments to be made in order to submit your application to Kennedys.
* where a level of experience is indicated, this is a guideline only and represents the amount of time we would usually expect a candidate to accumulate the requisite level of experience. This does not preclude applications from candidates with more or less experience.
#J-18808-LjbffrTo Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: